7. Windows Privilege Escalation Flashcards

1
Q

Windows Privilege Types

A
Local: Guest User
Local: Regular User
Local: Admin
Local: NT Authority
Domain: Regular User
Domain; Delegated Admin
Domain: Domain Admin
Domain: Enterprise Admin
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what is Privilege Escalation

A

elevate user’s privilege level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

WinLogon

A
  1. choose OS
  2. Mount OS
  3. override sethc.exe with cmd.exe
  4. Execute cmd.exe with high-level privilege
  5. Add user and password
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Offline Mitigation

A
  1. BIOS Password
  2. Encrypt Drive
  3. Limit Physical Access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Online Mitigation

A
  1. Least privilege
  2. remove Local Admin rights
  3. Account Audits
  4. User Account Controls
  5. Applocker
  6. Software
  7. Code
    8 Tokens
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Hide user

A

add $

regedit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly