Simple and accurate guide to elevate permission to NT AUTHORITY\SYSTEM
- Basic System Enumeration
- Finding clear text credentials
- GPP (Group Policy Preference)
- Secrets dump via SAM (VHD Mounted Share)
- Kernel Expliots
- AlwaysInstallElevated
- DNSAdmin DLL Injection
- RunAs with Saved Credentials
- BinPATH Service Re-Direct - Weak Permissions
- USP (Unquoted Service Path)
- SeImpersonate / SeAssignPrimaryToken - Service Accounts
- MSSQL via UDF User Defined Function