- Description
- Windows PrivEsc and post-exploitation · from user shell to SYSTEM and beyond.
- Best For
- Any Windows target after initial foothold · CTF, OSCP exam, real engagements.
- Strength
- Complete coverage from Potato attacks through Mimikatz with exact commands and priority ordering.
in this domain 17 sections
- 01 Decision Tree: Shell on Windows → What First?
- 02 Windows Escalation Priorities
- 03 Immediate Situational Awareness
- 04 SeImpersonatePrivilege → Potato Attack Chain
- 05 Service Misconfigurations
- 06 Registry Password Hunting
- 07 Unattend.xml / Sysprep Credentials
- 08 AlwaysInstallElevated
- 09 Stored Credentials
- 10 Token Impersonation (Incognito)
- 11 WinPEAS
- 12 Mimikatz
- 13 File Transfer Methods
- 14 Windows Loot & Proof
- 15 UAC Bypass
- 16 LSASS Dumping (Offline)
- 17 DPAPI & Browser Credentials