OPSECTLAS you are here: Windows
Windows

Windows PrivEsc & Post-Exploitation

domain 17 sections

Description
Windows PrivEsc and post-exploitation · from user shell to SYSTEM and beyond.
Best For
Any Windows target after initial foothold · CTF, OSCP exam, real engagements.
Strength
Complete coverage from Potato attacks through Mimikatz with exact commands and priority ordering.
in this domain 17 sections
  1. 01 Decision Tree: Shell on Windows → What First?
  2. 02 Windows Escalation Priorities
  3. 03 Immediate Situational Awareness
  4. 04 SeImpersonatePrivilege → Potato Attack Chain
  5. 05 Service Misconfigurations
  6. 06 Registry Password Hunting
  7. 07 Unattend.xml / Sysprep Credentials
  8. 08 AlwaysInstallElevated
  9. 09 Stored Credentials
  10. 10 Token Impersonation (Incognito)
  11. 11 WinPEAS
  12. 12 Mimikatz
  13. 13 File Transfer Methods
  14. 14 Windows Loot & Proof
  15. 15 UAC Bypass
  16. 16 LSASS Dumping (Offline)
  17. 17 DPAPI & Browser Credentials