Windows Access Token Manipulation for Privilege Escalation
Covers Windows access token manipulation techniques including token impersonation, theft, and creation to escalate privileges within Active Directory and local environments.
HackIndex
Language
Practical command-first pentest notes for Windows targets and Active Directory environments, grouped by attack phase. Use the tabs below to jump directly to the phase you need.
Windows privesc guides covering services, tokens, registry, and more
Covers Windows access token manipulation techniques including token impersonation, theft, and creation to escalate privileges within Active Directory and local environments.
Exploits misconfigured AlwaysInstallElevated registry keys to run malicious MSI packages with SYSTEM privileges on Windows hosts.
Exploits Windows DPAPI to decrypt stored credentials from browser vaults, credential manager, and user secrets for local privilege escalation.
Exploits NBNS spoofing, WPAD abuse & NTLM relay to DCOM for SYSTEM token impersonation via SeImpersonatePrivilege on legacy Windows systems.
Exploiting misconfigured Windows Registry autorun keys to execute malicious payloads with elevated privileges during system or user startup.
Exploit Windows `runas /savecred` stored credentials to execute commands as another user without knowing their password, achieving privilege escalation.
Windows post-exploitation enum, creds, loot, and file transfer guides
Covers techniques for moving files between attacker and Windows targets post-compromise, including common transfer methods like SMB, HTTP, and PowerShell.
Techniques for locating and extracting sensitive files, credentials, and user data from compromised Windows systems during post-exploitation reconnaissance.
Enumerate local Windows system info, users, groups, privileges, network config, and running processes to build situational awareness post-compromise.
Covers post-exploitation network reconnaissance on Windows systems, including enumeration of hosts, shares, active sessions, and domain topology using native tools.
Covers key Windows post-exploitation enumeration techniques using tools like WinPEAS, PowerView, and BloodHound to identify privilege escalation paths and lateral movement opportunities.
Covers techniques for extracting Windows access tokens and credentials post-compromise, including token impersonation, LSASS dumping, and privilege escalation.
Hash, ticket, SMB, WMI, WinRM, RDP, and token lateral moves
Covers PsExec-based lateral movement over SMB, including remote execution techniques, admin share abuse, and detection of suspicious PSEXESVC artifacts.
Exploits RDP sessions and reused credentials to move laterally across Windows environments, hijacking active sessions without requiring plaintext passwords.
Exploiting WinRM and PowerShell Remoting to move laterally across Windows environments using Enter-PSSession, Invoke-Command, and evil-winrm.
Leverages WMI to execute commands on remote Windows hosts for lateral movement, covering WMIC, PowerShell invoke methods, and evading common detections.
Registry, tasks, services, web shells, accounts, and ticket forging
Creates persistent backdoor access via Windows local accounts, net user commands, and administrator group manipulation to maintain long-term system compromise.
Covers Kerberos-based persistence via forged Golden (krbtgt) and Silver (service) tickets, enabling long-term domain access without valid credentials.
Covers Windows Registry-based persistence techniques, including Run keys, Winlogon hijacking, and COM hijacking to maintain attacker footholds.
Covers abusing Windows Task Scheduler (schtasks/COM) to establish persistent execution, including trigger types, privilege levels, and XML task configurations.
Establish persistent footholds by creating or hijacking Windows services, ensuring malicious payloads survive reboots and maintain long-term system access.
Covers detecting and mitigating web shell implants on Windows servers used by attackers to maintain persistent backdoor access via HTTP.
Guides on staging, and exfiltrating data over HTTP, SMB, FTP, and DNS
Techniques for identifying, collecting, and staging sensitive Windows data prior to exfiltration, covering file enumeration, compression, and archiving methods.
Explores DNS-based covert channel techniques on Windows to exfiltrate data, bypassing network controls by encoding payloads within DNS query traffic.
Covers techniques for exfiltrating data from Windows systems via HTTP/HTTPS, including tools, methods, and detection strategies for outbound data theft.
Covers techniques for exfiltrating data from Windows systems via SMB shares and FTP transfers, including tools, commands, and detection evasion methods.
Guides covering Windows and AD enumeration for privesc and pivoting
Techniques for enumerating AD objects, users, groups, GPOs, trusts, and misconfigurations using tools like BloodHound, ldapsearch, and PowerView.
Techniques for identifying installed AV and EDR solutions on Windows systems, including registry queries, process enumeration, and WMI-based detection methods.
Covers active Windows network enumeration techniques including host discovery, share mapping, SMB reconnaissance, and user/group extraction via native and third-party tools.
Enumerate Windows services and processes to identify running applications, privileges, and potential attack vectors using native tools and commands.
Covers techniques for enumerating Windows systems, including users, groups, privileges, network config, running processes, and installed software to identify attack paths.
Techniques for enumerating local and domain users, groups, and memberships on Windows systems using built-in tools and commands.
Get a shell via evil-winrm, web shells, and EternalBlue
Covers techniques for gaining initial footholds on Windows systems, including exploit execution, payload delivery, and leveraging common Windows vulnerabilities.
Find privesc paths via winPEAS, accesschk, tokens, and creds
Identifies misconfigurations and weaknesses in Windows environments to escalate privileges, covering token abuse, service exploits, and ACL flaws.
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.