privesc-windows

Warn

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: Provides instructions for escalating privileges to SYSTEM using various exploit tools such as PrintSpoofer, GodPotato, and JuicyPotatoNG, and techniques like UAC bypass via Fodhelper and Eventvwr.
  • [COMMAND_EXECUTION]: Includes commands for establishing persistence by creating scheduled tasks that run malicious binaries with SYSTEM privileges on user logon.
  • [COMMAND_EXECUTION]: Instructs on exploiting service misconfigurations, such as unquoted service paths and weak permissions, to replace legitimate service binaries with malicious ones.
  • [CREDENTIALS_UNSAFE]: Contains detailed procedures for stealing system-wide credentials, including dumping SAM/SYSTEM registry hives, searching for plaintext passwords in the registry, and using Mimikatz to harvest logon passwords, DPAPI keys, and Kerberos tickets.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 26, 2026, 08:57 AM
Security Audit — agent-trust-hub — privesc-windows