Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Priv2Admin — Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS. | Kitploit
Tools/GitHubGitHub/gtworek/priv2admin
Privilege EscalationExploitationPost-ExploitationPenetration Testing
GitHubgtworek/priv2admin

Priv2Admin

Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.

View Repository
2.5k306153 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

The idea is to "translate" Windows OS privileges to a path leading to:

  1. administrator,
  2. integrity and/or confidentiality threat,
  3. availability threat,
  4. just a mess.

Privileges are listed and explained at: https://learn.microsoft.com/en-us/windows/win32/secauthz/privilege-constants

If the goal can be achieved multiple ways, the priority is

  1. Using built-in commands
  2. Using PowerShell (only if a working script exists)
  3. Using non-OS tools
  4. Using any other method

You can check your own privileges with whoami /priv. Disabled privileges are as good as enabled ones. The only important thing is if you have the privilege on the list or not.

Note 1: Whenever the attack path ends with a token creation, you can assume the next step is to create new process using such token and then take control over OS.

Note 2:
a. For calling NtQuerySystemInformation()/ZwQuerySystemInformation() directly, you can find required privileges here.
b. For NtSetSystemInformation()/ZwSetSystemInformation() required privileges are listed here here.

Note 3: I am focusing on the OS only. If a privilege works in AD but not in the OS itself, I am describing it as not used in the OS. It would be nice if someone digs deeper into AD-oriented scenarios.

Feel free to contribute and/or discuss presented ideas.

PrivilegeImpactToolExecution pathRemarks
SeAssignPrimaryTokenAdmin3rd party tool"It would allow a user to impersonate tokens and privesc to nt system using tools such as potato.exe, rottenpotato.exe and juicypotato.exe"Thank you Aurélien Chalot for the update. I will try to re-phrase it to something more recipe-like soon.
SeAuditThreat3rd party toolWrite events to the Security event log to fool auditing or to overwrite old events.Writing own events is possible with Authz Report Security Event API.
- see PoC by @daem0nc0re
SeBackupAdmin3rd party tool1. Backup the HKLM\SAM and HKLM\SYSTEM registry hives
2. Extract the local accounts hashes from the SAM database
3. Pass-the-Hash as a member of the local Administrators group

Alternatively, can be used to read sensitive files.
For more information, refer to the SeBackupPrivilege file.
- see PoC by @daem0nc0re
SeChangeNotifyNone--Privilege held by everyone. Revoking it may make the OS (Windows Server 2019) unbootable.
SeCreateGlobal???
SeCreatePagefileNoneBuilt-in commandsCreate hiberfil.sys, read it offline, look for sensitive data.Requires offline access, which leads to admin rights anyway.
- See PoC by @daem0nc0re
SeCreatePermanent???
SeCreateSymbolicLink???
SeCreateTokenAdmin3rd party toolCreate arbitrary token including local admin rights with NtCreateToken.
- see PoC by @daem0nc0re
SeDebugAdminPowerShellDuplicate the lsass.exe token.Script to be found at FuzzySecurity.
- See PoC by @daem0nc0re
SeDelegateSession-
UserImpersonate
???Privilege name broken to make the column narrow.
SeEnableDelegationNone--The privilege is not used in the Windows OS.
SeImpersonateAdmin3rd party toolTools from the Potato family (potato.exe, RottenPotato, RottenPotatoNG, Juicy Potato, SweetPotato, RemotePotato0), RogueWinRM, PrintSpoofer, etc.Similarly to SeAssignPrimaryToken, allows by design to create a process under the security context of another user (using a handle to a token of said user).

Multiple tools and techniques may be used to obtain the required token.
SeIncreaseBasePriorityAvailabilityBuilt-in commandsstart /realtime SomeCpuIntensiveApp.exeMay be more interesting on servers.
SeIncreaseQuotaAvailability3rd party toolChange cpu, memory, and cache limits to some values making the OS unbootable.- Quotas are not checked in the safe mode, which makes repair relatively easy.
- The same privilege is used for managing registry quotas.
SeIncreaseWorkingSetNone--Privilege held by everyone. Checked when calling fine-tuning memory management functions.
SeLoadDriverAdmin3rd party tool1. Load buggy kernel driver such as szkg64.sys
2. Exploit the driver vulnerability

Alternatively, the privilege may be used to unload security-related drivers with fltMC builtin command. i.e.: fltMC sysmondrv
1. The szkg64 vulnerability is listed as CVE-2018-15732
2. The szkg64 exploit code was created by Parvez Anwar
SeLockMemoryAvailability3rd party toolStarve System memory partition by moving pages.PoC published by Walied Assar (@waleedassar)
SeMachineAccountNone--The privilege is not used in the Windows OS.
SeManageVolumeAdmin3rd party tool1. Enable the privilege in the token
2. Create handle to \.\C: with SYNCHRONIZE | FILE_TRAVERSE
3. Send the FSCTL_SD_GLOBAL_CHANGE to replace S-1-5-32-544 with S-1-5-32-545
4. Overwrite utilman.exe etc.
FSCTL_SD_GLOBAL_CHANGE can be made with this piece of code.
SeProfileSingleProcessNone--The privilege is checked before changing (and in very limited set of commands, before querying) parameters of Prefetch, SuperFetch, and ReadyBoost. The impact may be adjusted, as the real effect is not known.
SeRelabelThreat3rd party toolModification of system files by a legitimate administratorSee: MIC documentation

Integrity labels provide additional protection, on top of well-known ACLs. Two main scenarios include:
- protection against attacks using exploitable applications such as browsers, PDF readers etc.
- protection of OS files.

SeRelabel present in the token will allow to use WRITE_OWNER access to a resource, including files and folders. Unfortunately, the token with IL less than High will have SeRelabel privilege disabled, making it useless for anyone not being an admin already.

See great blog post by @tiraniddo for details.
SeRemoteShutdownAvailabilityBuilt-in commandsshutdown /s /f /m \\server1 /d P:5:19The privilege is verified when shutdown/restart request comes from the network. 127.0.0.1 scenario to be investigated.
Download Tool