Windows Privesc

Windows Privesc

Abusing Windows Backup and Restore Privileges

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Print Spooler and PrintNightmare Local Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Named Pipe Impersonation for Local Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Insecure Registry Autoruns and Service ImagePath Writes

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Scheduled Task and Startup Folder Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Stored Credentials Hunting: DPAPI, Registry, and Files

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

DLL Hijacking and Search-Order Abuse on Windows

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Token Impersonation and Stealing on Windows

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

UAC Bypass Techniques via Auto-Elevating Binaries

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

AlwaysInstallElevated: MSI Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Weak Service Permissions and Binary Path Hijacking

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Unquoted Service Path Exploitation on Windows

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

SeImpersonatePrivilege Abuse: The Potato Family

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

PetitPotam and Coercion Attacks: Forcing Authentication and Relaying to AD CS

How PetitPotam coerces machine authentication via MS-EFSRPC and relays it to AD CS for domain compromise — with detection and defense.
Security

Abusing Windows Token Privileges: The Potato Attack Family

How service accounts with SeImpersonatePrivilege escalate to SYSTEM via JuicyPotato, PrintSpoofer, and RoguePotato, plus blue-team defenses.
Windows Privesc

Privilege Escalation via Unquoted Service Paths on Windows

How unquoted Windows service paths with spaces let low-privileged users plant a binary and escalate to SYSTEM, plus blue-team defenses.
Windows Privesc

Weak Service Permissions: Privilege Escalation via SERVICE_CHANGE_CONFIG on Windows

Abuse misconfigured Windows service DACLs to rewrite binPath and escalate to SYSTEM, plus detection and hardening.
Security

DLL Hijacking: Privilege Escalation and Persistence on Windows

How DLL search order hijacking and phantom DLLs lead to privilege escalation and persistence, plus Blue Team detection and defense.
Windows Privesc

Abusing AlwaysInstallElevated for Windows Privilege Escalation

How a misconfigured AlwaysInstallElevated policy lets a low-privileged user run a malicious MSI as SYSTEM, plus detection and defense.
Windows Privesc

UAC Bypass Techniques: A Practical Overview of Auto-Elevation Abuse

A practical tour of Windows UAC bypass techniques abusing auto-elevating binaries, registry hijacks, and UACME, plus blue-team defenses.