Windows Privesc

Situational Awareness

Important information that should be obtained shortly after landing

  • Username / host name

  • Group memberships

  • Existing users and groups

  • OS

  • Network information / Ports / Connections

  • Installed applications

  • Running processes

cmd

whoami
whoami /groups
systeminfo
ipconfig /all
route print # Display all the routing information
netstat -ano # Display all active connections and show the processes ID
net user timothy

powershell

PrivEsc Scripts

Using powerup.ps1

WinPEAS

Last updated