Windows Access Token Manipulation for Privilege Escalation
Covers Windows access token manipulation techniques including token impersonation, theft, and creation to escalate privileges within Active Directory and local environments.
HackIndex
Language
Windows:
Windows privesc guides covering services, tokens, registry, and more
Covers Windows access token manipulation techniques including token impersonation, theft, and creation to escalate privileges within Active Directory and local environments.
Exploits misconfigured AlwaysInstallElevated registry keys to run malicious MSI packages with SYSTEM privileges on Windows hosts.
Exploits Windows DPAPI to decrypt stored credentials from browser vaults, credential manager, and user secrets for local privilege escalation.
Exploits NBNS spoofing, WPAD abuse & NTLM relay to DCOM for SYSTEM token impersonation via SeImpersonatePrivilege on legacy Windows systems.
Exploiting misconfigured Windows Registry autorun keys to execute malicious payloads with elevated privileges during system or user startup.
Exploit Windows `runas /savecred` stored credentials to execute commands as another user without knowing their password, achieving privilege escalation.
Exploiting misconfigured Windows Scheduled Tasks to escalate privileges by hijacking task binaries, weak permissions, and DLL sideloading techniques.
Exploits SeImpersonatePrivilege to impersonate high-privilege tokens via named pipes or API abuse, escalating from service accounts to SYSTEM on Windows.
Techniques to bypass User Account Control (UAC) mechanisms, escalating standard user privileges to administrator level on Windows systems.
Exploits Windows services with unquoted executable paths containing spaces, allowing malicious binary placement for SYSTEM-level code execution.
Techniques for locating stored credentials in Windows registries, files, memory, and configs to escalate privileges on compromised systems.
Exploits Windows DLL search order to load malicious libraries, escalating privileges by hijacking vulnerable application or service executable paths.
Covers key tools for enumerating Windows privilege escalation vectors, including misconfigured services, weak permissions, unpatched vulnerabilities, and token abuse opportunities.
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.