Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
siem — Curated SIEM queries and techniques for offensive discovery of Windows privilege escalation, misconfigured ACLs, services, scheduled tasks, and vulnerable drivers. | Kitploit
Tools/GitHubGitHub/ekitji/siem
Defensive ToolsPrivilege EscalationVulnerability AnalysisInformation GatheringPenetration TestingMisconfigurationLearning & EducationRed TeamingCurated ResourcesLog Analysis
GitHubekitji/siem
5857620 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

siem

Curated SIEM queries and techniques for offensive discovery of Windows privilege escalation, misconfigured ACLs, services, scheduled tasks, and vulnerable drivers.

View Repository
Share

Offensive SIEM

Practical techniques for leveraging SIEM as an offensive discovery tool, helping defenders think like attackers to strengthen security from within.

Queries

See above - queries.md file.

Will keep getting updated when needed. The idea is to have layer on layer coverage using different event.codes/event.providers.

  • Released queries for environmental PATHS, Kernel Drivers and Logon/Startup scripts etc during february 2026!
  • Released queries for OpenSSL libraries and Schedule task / Services with missing binary paths during mars 2026!

Vulnerability Management

Queries for Vulnerability Management in file: vulnerabilitymanagement.md

Gives you an idea how you can enumerate

  • Windows OS version and build status
  • Attack Surface Reduction (ASR) Rules and find misconfigurations
  • Windows Defender exclusions and find misconfigurations
  • Windows Applocker rules and find misconfigurations

Ping us if/when you find something

We hope that you liked the presentation. Ping us if you (i would say when you) find vulnerabilities by using this method. A simple message like "one of your queries cathed good stuff".. is more then enough :) do it by commiting to the ping.md file or contact us in alternative ways! We would be happy to share your success!

General information

The repo will assist you in having offensive mindset. Repo is to share the material and queries that we talked about in our presentation:

Offensive SIEM - When The Blue Team Switches Perspective

SEC-T september 2025 ⭐ https://www.youtube.com/watch?v=5nfL_4ek4dY

x33fcon updated talk june 2026 covering some new areas ⭐ https://youtu.be/dD_7AdEoj0k?is=CMp22Q9evBcqZe7L

We have included the most interesting ACL related parts and have tips & tricks.

Check out the outstanding webinars about windows local privilege escalation and windows endpoint misconfigurations which will assist you further on. There are more areas to look into.. This is only the starting point. If you build good queries in other areas - please share it with us so more in the community can use them.

The queries with ⭐ mark is extra highly relevant. The topics down below with ⭐ is really good content.

Webinars

Oddvar Moes Windows Client Privilege Escalation ⭐

a must to watch, specially the ACL for binaries, services and schedule tasks.

  • https://www.youtube.com/watch?v=EG2Mbw2DVnU

Spencers Windows Endpoint Misconfigs ⭐

Topic 2 (Insecurely installed/conf Software) And Topic 5 (Insecure Services And Tasks)

  • https://go.spenceralessi.com/windowsmisconfigsreplay
password: P3yGQ+1y
  • https://www.youtube.com/watch?v=JWopwNVP_to

Other related to Windows Privilege Escalation.

  • https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Windows%20-%20Privilege%20Escalation.md
  • https://sushant747.gitbooks.io/total-oscp-guide/content/privilege_escalation_windows.html
  • https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/

DLL Hijacking

  • https://itm4n.github.io/windows-dll-hijacking-clarified/

PATH entries and User-writable directories in the system PATH --> DLL Hijacking

  • https://www.expressvpn.com/blog/cybersecurity-lessons-a-path-vulnerability-in-windows/
  • https://www.praetorian.com/blog/red-team-local-privilege-escalation-writable-system-path-privilege-escalation-part-1/

SCCM / Software Center ⭐

  • https://blog.nviso.eu/2022/05/31/cve-farming-through-software-center-a-group-effort-to-flush-out-zero-day-privilege-escalations/
Interesting read about how many misconfigured software where found and you will likely find same ratio using Offensive SIEM!

Arbitrary File deletion --> Local privilege escalation

  • https://cicada-8.medium.com/were-going-the-wrong-way-how-to-abuse-symlinks-and-get-lpe-in-windows-0c598b99125b
  • https://cloud.google.com/blog/topics/threat-intelligence/arbitrary-file-deletion-vulnerabilities/
  • https://github.com/ZeroMemoryEx/CVE-2025-68921
  • https://xmcyber.com/blog/jumpshot-xm-cyber-uncovers-critical-local-privilege-escalation-cve-2025-34352-in-jumpcloud-agent/
  • https://www.youtube.com/watch?v=EG2Mbw2DVnU from minute: 34.45 (Intel Trusted Connect Service client)
  • https://www.zerodayinitiative.com/blog/2022/3/16/abusing-arbitrary-file-deletes-to-escalate-privilege-and-other-great-tricks
  • https://www.mdsec.co.uk/2026/02/total-recall-retracing-your-steps-back-to-nt-authoritysystem/
Other file operations
  • https://troopers.de/downloads/troopers19/TROOPERS19_AD_Abusing_privileged_file_operations.pdf

Logon scripts

  • https://offsec.blog/hidden-menace-how-to-identify-misconfigured-and-dangerous-logon-scripts/
  • https://cyberthreatperspective.buzzsprout.com/1731753/episodes/13343207-episode-54-misconfigured-and-dangerous-logon-scripts
  • https://offsec.blog/wp-content/uploads/2024/06/How-to-Harden-Active-Directory-to-Prevent-Cyber-Attacks.pdf

Kernel drivers and privilege escalation

  • https://www.youtube.com/watch?v=U36hAneQeZM

OpenSSLs openssl.cnf and privilege escalation

  • https://labs.infoguard.ch/advisories/cve-2025-13176_eset-inspect_edr_local-privilege-escalation/
  • https://blog.mirch.io/2019/06/10/cve-2019-12572-pia-windows-privilege-escalation-malicious-openssl-engine/
  • https://blog.pentryx.ch/local-privilege-escalation-in-lenovo-udc-19dc86d72142?gi=0fe882ea2355
  • https://www.triskelelabs.com/blog/cve-2025-2272-forcepoint-endpoint-dlp-privilege-escalation
  • https://hackerone.com/reports/622170

NSIS installer/uninstaller vulnerability

  • https://blog.amberwolf.com/blog/2026/april/next-next-system/

DotLocal Redirection vulnerability

  • https://web.archive.org/web/20230721193548/https://research.nccgroup.com/2023/07/03/technical-advisory-nullsoft-scriptable-installer-system-nsis-insecure-temporary-directory-usage/
  • https://blog.amberwolf.com/blog/2026/april/next-next-system/
  • https://youtu.be/Ik1xpsQEVwI?si=P7G1kmnSKdFldCAG
  • https://heegong.github.io/posts/Advaned-Installer-Local-Privilege-Escalation-Vulnerability/
  • https://www.synaptics.com/sites/default/files/nr-154525-tc-synaptics_displaylink_windows_driver_security_brief_-_oct2023.pdf
  • https://github.com/wixtoolset/issues/security/advisories/GHSA-7wh2-wxc7-9ph5

Example of interesting areas to look into that we have not covered in presentation but we have queries for some of them.

  • weak passwords in command_line - that are not following best practices / policies
  • weak passwords or sensitive information in powershell admin scripts scriptblock event code: 4104. Search for strings: "SecureString","PSCredential","Password", "passwd"......
  • weak passwords in registry - that are not following best practices / policies
  • file creations/deletions of typical files holding sensitive information like passwords.txt, passwords.xslx, unattend.xml etc.
  • AlwaysInstallElevated in Registry, Autologons (look if passwords is set)
  • Windows Privileges - Look at 4672 (logon with special privileges) And 4704/4705 (assignment/removal of rights)
  • Event code 5136 and 5137, AD objects.. look in to the fields: description, info and adminComment, if they have any plaintext passwords.
  • Using process creation events and look for sc.exe setting services security descriptor using sdset or sysmons registry event code 13 and checking the ACL value (in binary format of SDDL) and converting it to readable ACL looking for weak ACL permissions set on the service it self.
  • Do not assume that Program Files and similar admin-protected directories always have correct ACLs (Access Control Lists). It does happen that applications set incorrect default permissions and are far too permissive. CWE-732, CWE-284, CWE-276
  • SeImpersonatePrivilege token on "Network Service or Local Service" accounts running processes in user writable paths --> Potato like attack to get SYSTEM
  • etc..
Download Tool