Windows Service and Process Enumeration
Services and processes reveal what is running on the target, under which identity, and with what permissions. Misconfigured services are among the most common privilege escalation paths on Windows. Process enumeration tells you what security tools are active and which user contexts are available for token theft.
Running processes
Service enumeration
Enumerate all services with their binary paths, run-as accounts, and start types. Services running as SYSTEM with weak permissions are direct escalation paths.
Service permission checking
Services with overly permissive ACLs allow low-privilege users to modify the binary path and escalate to SYSTEM. Check permissions on both the service itself and its binary.
Writable service binaries lead to Service Binary Hijacking. Unquoted paths lead to Unquoted Service Path Privilege Escalation. Weak service permissions lead to Weak Service Permissions Privilege Escalation.
Scheduled tasks
Was this helpful?
Your feedback helps improve this page.