| Priority | Technique | Reliability |
|---|---|---|
| 1 | whoami /priv → SeImpersonatePrivilege (Potato) | Very High · extremely common on service accounts |
| 2 | Unquoted service paths | High · frequent misconfiguration |
| 3 | Service weak permissions / writable binary | High |
| 4 | AlwaysInstallElevated | Medium · check registry first |
| 5 | Stored credentials (cmdkey, registry) | Medium · often overlooked |
| 6 | Unattend.xml / sysprep credentials | Medium |
| 7 | DLL hijacking | Moderate · needs writable path |
| 8 | Token impersonation (Incognito) | Situational |
| 9 | WinPEAS full scan | Use to find anything missed above |
in playbooks