privesc-windows
Warn
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions for escalating privileges to SYSTEM using various exploit tools such as PrintSpoofer, GodPotato, and JuicyPotatoNG, and techniques like UAC bypass via Fodhelper and Eventvwr.
- [COMMAND_EXECUTION]: Includes commands for establishing persistence by creating scheduled tasks that run malicious binaries with SYSTEM privileges on user logon.
- [COMMAND_EXECUTION]: Instructs on exploiting service misconfigurations, such as unquoted service paths and weak permissions, to replace legitimate service binaries with malicious ones.
- [CREDENTIALS_UNSAFE]: Contains detailed procedures for stealing system-wide credentials, including dumping SAM/SYSTEM registry hives, searching for plaintext passwords in the registry, and using Mimikatz to harvest logon passwords, DPAPI keys, and Kerberos tickets.
Audit Metadata