githubEdit

9. Priv Esc

I. Initial Enumeration

RDP & Network

xfreerdp /v:<target ip> /u:htb-student
ipconfig /all
arp -a
route print
netstat -ano 

AppLocker & Defender

Get-MpComputerStatus
Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections
Get-AppLockerPolicy -Local | Test-AppLockerPolicy -path C:\Windows\System32\cmd.exe -User Everyone

System Info

set
systeminfo
wmic qfe
wmic product get name

Users & Processes

tasklist /svc
query user
echo %USERNAME%
whoami /priv
whoami /groups
net user
net localgroup
net localgroup administrators
net accounts

Named Pipes

II. Handy Commands

SQL Server

Privilege Escalation

LSASS Dumping & Mimikatz

File Ownership & ACLs

Hash Extraction & File Copy

Event Logs

DLLs, Users, & Services

Registry & DNS

File Transfer & Execution

Credential Theft - File Search

Last updated