Monstersec Blog
search
⌘Ctrlk
LinkedinTwitterGRC Newsletter
Monstersec Blog
  • Monstersec Blog
  • Adversary Experience
    • Undetectable Phishing setup
    • How to Root any Android phone In A Just Few Hours
    • Red Team Plot
      • Red Team Simulation
      • AD Enumeration
      • Initial Access
      • Defense Evasion
      • Local Privilege Escalation
      • Credential Access
      • Lateral Movement
      • Local Persistence
      • Domain Privilege Escalation
      • Domain Persistence
      • Beyond Domain Admin
      • AD Certificate Service Attacks
      • Red Team Reference
    • Detection - Blue Team
    • Ransomware Plot
    • Pentesting Plot
    • OSINT Plot
    • Cloud Security Plot
    • Attack Surface Management Plot
    • DDoS Simulation
    • Automation
    • Cyber Security - Interview Questions
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Adversary Experiencechevron-right
  2. Red Team Plot

Local Privilege Escalation

Windows - https://github.com/carlospolop/PEASS-ng/tree/master/winPEASarrow-up-right

Linux - https://github.com/carlospolop/PEASS-ng/tree/master/linPEASarrow-up-right

hashtag
Way to escalate the privilege

  1. AlwaysInstallElevatedarrow-up-right

  2. SeBackupPrivilegearrow-up-right

  3. DnsAdmins to DomainAdminarrow-up-right

  4. SeImpersonatePrivilegearrow-up-right

  5. HiveNightmarearrow-up-right

  6. Logon Autostart Execution (Registry Run Keys)arrow-up-right

  7. Boot Logon Autostart Execution (Startup Folder)arrow-up-right

  8. Stored Credentials (Runas)arrow-up-right

  9. Weak Registry Permissionarrow-up-right

  10. Unquoted Service Patharrow-up-right

  11. Insecure GUI Applicationarrow-up-right

  12. Weak Service Permissionsarrow-up-right

  13. Scheduled Task/Job (T1573.005)arrow-up-right

  14. Kernel Exploitarrow-up-right

  15. SamAccountSpoofing (CVE-2021–42278)arrow-up-right

  16. SpoolFoolarrow-up-right

  17. PrintNightmarearrow-up-right

  18. Server Operator Grouparrow-up-right

PreviousDefense Evasionchevron-leftNextCredential Accesschevron-right

Last updated 3 years ago