Windows Privilege Escalation
Warn
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous command-line instructions for exploiting Windows system configurations, including modifying service binary paths (
sc config), executing malicious MSI packages (msiexec), and establishing reverse shells using Netcat (nc.exe). It also details the use of advanced exploitation tools like JuicyPotato, PrintSpoofer, and GodPotato for token impersonation. - [CREDENTIALS_UNSAFE]: The skill includes procedures for harvesting sensitive credentials from the SAM and SYSTEM registry hives, Windows Autologin settings, PuTTY sessions, and cleartext WiFi profiles. It also instructs on extracting passwords from
Unattend.xmland PowerShell history files. - [DATA_EXFILTRATION]: Provides payload examples for
msfvenomspecifically designed to create reverse shells directed to an external IP address, facilitating the exfiltration of harvested credentials and system data. - [COMMAND_EXECUTION]: Includes instructions for identifying and exploiting kernel vulnerabilities (e.g., MS17-010, CVE-2021-1732) and service misconfigurations like unquoted service paths and weak folder permissions.
Audit Metadata