Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Windows-Privilege-Escalation-Notes — My handbook for Windows Privilege Escalation concepts. Do Check out my Playlist, link: https://www.youtube.com/playlist?list=PLlrnAg4kKF3puXLI0JyltbNJOC2R2HVFk | Kitploit
Tools/GitHubGitHub/saisathvik1/windows-privilege-escalation-notes
Privilege EscalationPassword AttacksExploitationInformation GatheringPost-ExploitationCTFPenetration TestingLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
saisathvik1/windows-privilege-escalation-notes

Windows-Privilege-Escalation-Notes

My handbook for Windows Privilege Escalation concepts. Do Check out my Playlist, link: https://www.youtube.com/playlist?list=PLlrnAg4kKF3puXLI0JyltbNJOC2R2HVFk

View Repository
5914344 years agoReviewed by Kitploit

Windows Privilege Escalation

  • Preferable room is https://tryhackme.com/room/windows10privesc, but u can use anything of your choice.
  • Some resources,
    • https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/
    • https://sushant747.gitbooks.io/total-oscp-guide/content/privilege_escalation_windows.html
    • https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Windows%20-%20Privilege%20Escalation.md
    • https://www.fuzzysecurity.com/tutorials/16.html

Types of accounts in windows machines:

  • Administrator (local): This is the user with the most privileges.
  • Standard (local): These users can access the computer but can only perform limited tasks. Typically these users can not make permanent or essential changes to the system.
  • Guest: This account gives access to the system but is not defined as a user.
  • Standard (domain): Active Directory allows organizations to manage user accounts. A standard domain account may have local administrator privileges.
  • Administrator (domain): Could be considered as the most privileged user. It can edit, create, and delete other users throughout the organization's domain.
  • SYSTEM : This not particularly an account but windows services utilize this account to do its task, but even this account has higher privileges

An Important point worth noting is Groups, any user of Group Administrator helps us to escalate!


Information Gathering:

  • One of the best Resource: https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Windows%20-%20Privilege%20Escalation.md
  1. whoami /priv - current user's privileges
  2. net users - lists all users
  3. net user <username> - lists details of a specific user
  4. qwinsta - Other users logged in simultaneously
  5. net localgroup - Groups available in system
  6. net localgroup <group-name> - list members of a specific group
  7. systeminfo - gives all the info info about OS
  8. hostname - hostname of system
  9. findstr /si password *.txt - we're looking for the files which consist 'password' that too in text files
  10. wmic qfe get Caption,Description,HotFixID,InstalledOn - this tells about the security patches and related information
  11. netstat -ano - connections associated with the machine
  12. schtasks /query /fo LIST /v - to look for any taks that are scheduled
  13. driverquery - lists the driver related information
  14. sc query windefend - looks for Antivirus service

Windows Exploit Suggester:

  • This is a legendary tool that most people use
  • We can solve 60% boxes out there on internet using this tool
  • Link: https://github.com/AonCyberLabs/Windows-Exploit-Suggester
  • Just have a copy of output of systeminfo tool in your machine and this is the only requirement for this tool
  • Pro Tip: Make sure all dependancies are fulfilled!

Vulnerable Software:

  • Here we'll try to find the software version thats installed and look for whether its vulnerable or not
  • wmic product get name,version,vendor - this gives product name, version, and the vendor. This particular command gives a proper visualisation of what we need.
  • Sometimes the above command might not work so use wmic service list brief | findstr "Running" and in order to obtain more information regarding the service use sc qc <ServiceName>


Privilege Escalation thru Metasploit:

  • After getting session in metasploit, run a module named post/multi/recon/local_exploit_suggester, make sure that ur session is in background so that this tool works properly or u can simply load it from meterpreter.
  • Then It'll suggest some modules which can be exploited so try them and some of them might work(optional).


WinPEAS:

  • This is an automated enumeration script which is quite helpful.
  • For best usage look for all the options by running winpeas.exe --help
  • Run the options that are only required and tune the output.


Kernel Exploit:

  • Use this particular tool called Windows Exploit Suggester
  • Firstly get the info of system by running systeminfo command and copy that to any file and name it with extension .txt
  • Now run the tool using the database
  • Here look for the kernel releated exploits.
  • Happy hacking!!


Service Exploits:

Insecure service permissions:

  • Here we'll try to identify services with some insecure permissions and then we can try to exploit them.
  • Here we can make use of winpeas.exe servicesinfo command and we can see the services which are quite helpful
  • One interesting part of output is like this,

    daclsvc(DACL Service)["C:\Program Files\DACL Service\daclservice.exe"] - Manual - Stopped
    YOU CAN MODIFY THIS SERVICE: ChangeConfig

  • But to obtain more information we can use a tool called accesschk which is by Microsoft, run it as follows accesschk.exe /accepteula -uwcqv <current-user> <service>, output is,
C:\PrivEsc>accesschk.exe /accepteula -uwcqv user daclsvc
daclsvc
        SERVICE_QUERY_STATUS
        SERVICE_QUERY_CONFIG
        SERVICE_CHANGE_CONFIG
        SERVICE_INTERROGATE
        SERVICE_ENUMERATE_DEPENDENTS
        SERVICE_START
        SERVICE_STOP
        READ_CONTROL

  • But the main part is service_change_config where we can change configuration of the service.
  • Run sc qc <service> and then note the Binary_path_name(this can be also called as binpath), which we're going to change(evil smile)
  • No create a playload which is of shell type and transfer it to the target machine
  • Syntax to change the config, sc config <service> <option>="<value>"
  • Now sc config daclsvc binpath="<path>" and now start the service sc start daclsvc

Unquoted Service Path:(USP)

  • For services the path needs to be in quotes, if its not enclosed like that then we can exploit that loophole and get high privilege.
Vulnerability Insight: 
The Windows API must assume where to find the referenced application if the path contains spaces and is not enclosed by quotation marks. If, for example, a service uses the unquoted path:

Vulnerable Service: C:\Program Files\Ignite Data\Vuln Service\file.exe

The system will read this path in the following sequence from 1 to 4 to trigger malicous.exe through a writeable directory.

C:\Program.exe
C:\Program Files\Ignite.exe
C:\Program Files\Ignite Data\Vuln.exe
C:\Program Files\Ignite Data\Vuln Service\file.exe
  • To get more information just use WinPEAS script with option servicesinfo, here we can see info if we can exploit any Unquoted Service Path, Here I ran the tool and the interesting part of output is like this,
unquotedsvc(Unquoted Path Service)[C:\Program Files\Unquoted Path Service\Common Files\unquotedpathservice.exe] - Manual - Stopped - No quotes and Space detected  
  • The output here clearly specifies that No quotes and Space Detected so we can conclude that we can exploit this particular service using USP
  • And to gather more information regarding service use sc qc <service>
  • Now let's check the permission for this particular location C:\Program Files\Unquoted Path Service using accesschk, so run accesschk.exe /accepteula -uwdq "C:\Program Files\Unquoted Path Service". Output:
accesschk.exe /accepteula -uwdq "C:\Program Files\Unquoted Path Service"
C:\Program Files\Unquoted Path Service
  Medium Mandatory Level (Default) [No-Write-Up]
  RW BUILTIN\Users
  RW NT SERVICE\TrustedInstaller
  RW NT AUTHORITY\SYSTEM
  RW BUILTIN\Administrators
Download Tool