Windows
Find Windows Kernel Vulnerabilities
systeminfowes /tmp/systeminfo.txt -c -e --definitions /opt/wesng/definitions.zip -i "Elevation Of Privilege" | egrep -i exploit-dbwes /tmp/systeminfo.txt -c -e --definitions /opt/wesng/definitions.zip -i 'Remote Code Execution' | egrep -i exploit-dbwindows-exploit-suggester.py --systeminfo /tmp/systeminfo.txt -d /opt/winreconpack/2022-10-09-mssb.xlsTest For Previously Used credentials
cmdkey /listrunas /savecred /user:someuser whoami.exeTest For abuseable privileges
whoami /privSeBackupPrivilege
reg.exe save hklm\sam sam.savereg.exe save hklm\system system.savesecretsdump.py -sam sam.save -system system.save localSeRestorePrivilege
SeImpersonatePrivilege OR SeAssignPrimaryToken
RoguePotato
JuicyPotato
PrintSpoofer
HotPotato
SeDebugPrivilege
SeShutdownPrivilege
SeManageVolumePrivilege
SeTakeOwnershipPrivilege
Test For alwayselevated
Find Insecure Sam System backups
Non-default Programs Discovery
Test For Plaintext passwords
In Unattended Files
In Registries
In WinLogon
In SNMP Paraemeters
In Sticky Notes
Or with PowerShell
In Clipboard
In VNC
In Putty
Or With PowerShell
In Powershell History
In IIS WebServer configs
In WebServer Directories
Test For AutoRuns
Unmount Disks/Drives
Test Services
Insecure Service Executables
Or
Unquoted Service Paths
Insecure Service Permissions
Weak Registry Permissions
Test For Scheduled Tasks
Test For StartUp Apps
Test For Insecure GUI Apps
Find Vulnerable Driver
Last updated