Checklist - Local Windows Privilege Escalation
Tip
AWS Hacking์ ๋ฐฐ์ฐ๊ณ ์ฐ์ตํ์ธ์:
HackTricks Training AWS Red Team Expert (ARTE)
GCP Hacking์ ๋ฐฐ์ฐ๊ณ ์ฐ์ตํ์ธ์:HackTricks Training GCP Red Team Expert (GRTE)
Az Hacking์ ๋ฐฐ์ฐ๊ณ ์ฐ์ตํ์ธ์:HackTricks Training Azure Red Team Expert (AzRTE)
ํ๊ฐ ํธ๋ (ARTA/GRTA/AzRTA)๊ณผ Linux Hacking Expert (LHE)๋ฅผ ๋ณด๋ ค๋ฉด ์ ์ฒด HackTricks Training ์นดํ๋ก๊ทธ๋ฅผ ๋๋ฌ๋ณด์ธ์.
HackTricks ์ง์ํ๊ธฐ
- subscription plans๋ฅผ ํ์ธํ์ธ์!
- ๐ฌ Discord group, telegram group์ ์ฐธ์ฌํ๊ณ , X/Twitter์์ @hacktricks_live๋ฅผ ํ๋ก์ฐํ๊ฑฐ๋, LinkedIn page์ YouTube channel์ ํ์ธํ์ธ์.
- HackTricks ๋ฐ HackTricks Cloud github repos์ PR์ ์ ์ถํด hacking tricks๋ฅผ ๊ณต์ ํ์ธ์.
Windows local privilege escalation vectors๋ฅผ ์ฐพ๋ ๋ฐ ๊ฐ์ฅ ์ข์ tool: WinPEAS
System Info
- System information ํ๋
- ์คํฌ๋ฆฝํธ๋ฅผ ์ฌ์ฉํด kernel exploits ๊ฒ์
- Google์ ์ฌ์ฉํด kernel exploits ๊ฒ์
- searchsploit๋ฅผ ์ฌ์ฉํด kernel exploits ๊ฒ์
- env vars์ ํฅ๋ฏธ๋ก์ด ์ ๋ณด๊ฐ ์๋๊ฐ?
- PowerShell history์ Passwords๊ฐ ์๋๊ฐ?
- Internet settings์ ํฅ๋ฏธ๋ก์ด ์ ๋ณด๊ฐ ์๋๊ฐ?
- Drives?
- WSUS exploit?
- Third-party agent auto-updaters / IPC abuse
- AlwaysInstallElevated?
Logging/AV enumeration
- Audit ์ WEF ์ค์ ํ์ธ
- LAPS ํ์ธ
- WDigest ๊ฐ ํ์ฑํ๋์ด ์๋์ง ํ์ธ
- LSA Protection?
- Credentials Guard?
- Cached Credentials?
- ์ด๋ค AV๊ฐ ์๋์ง ํ์ธ
- AppLocker Policy?
- UAC
- Admin Protection / UIAccess silent elevation?
- Secure Desktop accessibility registry propagation (RegPwn)?
- User Privileges
- ํ์ฌ user์ privileges ํ์ธ
- member of any privileged group์ ์ํด ์๋๊ฐ?
- ์ด๋ฌํ ํ ํฐ๋ค ์ค ํ์ฑํ๋ ๊ฒ์ด ์๋์ง ํ์ธ: SeImpersonatePrivilege, SeAssignPrimaryPrivilege, SeTcbPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeCreateTokenPrivilege, SeLoadDriverPrivilege, SeTakeOwnershipPrivilege, SeDebugPrivilege ?
- SeManageVolumePrivilege(SeManageVolumePrivilege)๊ฐ ์๋์ง ํ์ธํ์ฌ raw volumes๋ฅผ ์ฝ๊ณ file ACLs๋ฅผ ์ฐํ
- Users Sessions?
- users homes ํ์ธ (access?)
- Password Policy ํ์ธ
- inside the Clipboard ์์ ๋ฌด์์ด ์๋๊ฐ?
Network
- ํ์ฌ network information ํ์ธ
- ์ธ๋ถ์์๋ง ์ ํ๋ hidden local services ํ์ธ
Running Processes
- Processes binaries์ file and folders permissions
- Memory Password mining
- Insecure GUI apps
-
ProcDump.exe๋ฅผ ํตํด interesting processes์์ credentials ํ์ทจ ? (firefox, chrome, etc โฆ)
Services
- modify any serviceํ ์ ์๋๊ฐ?
- ์ด๋ค service๊ฐ ์คํํ๋ binary๋ฅผ modifyํ ์ ์๋๊ฐ?
- ์ด๋ค service์ registry๋ฅผ modifyํ ์ ์๋๊ฐ?
- unquoted service binary path๋ฅผ ํ์ฉํ ์ ์๋๊ฐ?
- Service Triggers: enumerate and trigger privileged services
Applications
- ์ค์น๋ applications์ ๋ํ Write ๊ถํ
- Startup Applications
- ์ทจ์ฝํ Drivers
DLL Hijacking
- PATH ๋ด๋ถ์ ์ด๋ค folder์๋ writeํ ์ ์๋๊ฐ?
- ์๋ ค์ง service binary ์ค non-existant DLL์ loadํ๋ ค๊ณ ์๋ํ๋ ๊ฒ์ด ์๋๊ฐ?
- ์ด๋ค binaries folder์๋ writeํ ์ ์๋๊ฐ?
Network
- network๋ฅผ ์ด๊ฑฐ (shares, interfaces, routes, neighbours, โฆ)
- localhost (127.0.0.1)์์ listen ์ค์ธ network services๋ฅผ ํน๋ณํ ์ดํด๋ณผ ๊ฒ
Windows Credentials
- Winlogon credentials
- ์ฌ์ฉํ ์ ์๋ Windows Vault credentials?
- ํฅ๋ฏธ๋ก์ด DPAPI credentials?
- ์ ์ฅ๋ Wifi networks์ Passwords?
- saved RDP Connections์ ํฅ๋ฏธ๋ก์ด ์ ๋ณด๊ฐ ์๋๊ฐ?
- recently run commands์ Passwords๊ฐ ์๋๊ฐ?
- Remote Desktop Credentials Manager passwords?
- AppCmd.exe exists? Credentials?
- SCClient.exe? DLL Side Loading?
Files and Registry (Credentials)
- Putty: Creds and SSH host keys
- SSH keys in registry?
- unattended files์ Passwords๊ฐ ์๋๊ฐ?
- SAM & SYSTEM backup์ด ์๋๊ฐ?
- SeManageVolumePrivilege๊ฐ ์์ผ๋ฉด
SAM,SYSTEM, DPAPI material,MachineKeys์ ๋ํด raw-volume reads๋ฅผ ์๋ - Cloud credentials?
- McAfee SiteList.xml file?
- Cached GPP Password?
- IIS Web config file์ Password๊ฐ ์๋๊ฐ?
- web logs์ ํฅ๋ฏธ๋ก์ด ์ ๋ณด๊ฐ ์๋๊ฐ?
- ์ฌ์ฉ์์๊ฒ ask for credentialsํ ๊ฒ์ธ๊ฐ?
- Recycle Bin ์์ ํฅ๋ฏธ๋ก์ด file๋ค?
- credentials๋ฅผ ํฌํจํ๋ ๋ค๋ฅธ registry?
- Browser data ์์ (dbs, history, bookmarks, โฆ)?
- ํ์ผ๊ณผ registry์์์ Generic password search
- Passwords๋ฅผ ์๋์ผ๋ก ์ฐพ๋ Tools
Leaked Handlers
- administrator๊ฐ ์คํํ process์ handler์ ์ ๊ทผํ ์ ์๋๊ฐ?
Pipe Client Impersonation
- ์ด๋ฅผ ์ ์ฉํ ์ ์๋์ง ํ์ธ
References
Tip
AWS Hacking์ ๋ฐฐ์ฐ๊ณ ์ฐ์ตํ์ธ์:
HackTricks Training AWS Red Team Expert (ARTE)
GCP Hacking์ ๋ฐฐ์ฐ๊ณ ์ฐ์ตํ์ธ์:HackTricks Training GCP Red Team Expert (GRTE)
Az Hacking์ ๋ฐฐ์ฐ๊ณ ์ฐ์ตํ์ธ์:HackTricks Training Azure Red Team Expert (AzRTE)
ํ๊ฐ ํธ๋ (ARTA/GRTA/AzRTA)๊ณผ Linux Hacking Expert (LHE)๋ฅผ ๋ณด๋ ค๋ฉด ์ ์ฒด HackTricks Training ์นดํ๋ก๊ทธ๋ฅผ ๋๋ฌ๋ณด์ธ์.
HackTricks ์ง์ํ๊ธฐ
- subscription plans๋ฅผ ํ์ธํ์ธ์!
- ๐ฌ Discord group, telegram group์ ์ฐธ์ฌํ๊ณ , X/Twitter์์ @hacktricks_live๋ฅผ ํ๋ก์ฐํ๊ฑฐ๋, LinkedIn page์ YouTube channel์ ํ์ธํ์ธ์.
- HackTricks ๋ฐ HackTricks Cloud github repos์ PR์ ์ ์ถํด hacking tricks๋ฅผ ๊ณต์ ํ์ธ์.


