https://github.com/gtworek/Priv2Admin
When you get a shell on a remote windows machine or any machine using evil-winrm, then after getting access, issue the following command:
whoami /all or whoami /priv
Based on you permission on the remote box, the above link will help you to figure out what you can do in the remote box.
if you see you have got sebackupprivilege and serestoreprivilege then you can do so many things. these 2 are very dangerous privileges.
Avi
Comments
Post a Comment