7. Windows Privilege Escalation Flashcards
1
Q
Windows Privilege Types
A
Local: Guest User Local: Regular User Local: Admin Local: NT Authority Domain: Regular User Domain; Delegated Admin Domain: Domain Admin Domain: Enterprise Admin
2
Q
what is Privilege Escalation
A
elevate user’s privilege level
3
Q
WinLogon
A
- choose OS
- Mount OS
- override sethc.exe with cmd.exe
- Execute cmd.exe with high-level privilege
- Add user and password
4
Q
Offline Mitigation
A
- BIOS Password
- Encrypt Drive
- Limit Physical Access
5
Q
Online Mitigation
A
- Least privilege
- remove Local Admin rights
- Account Audits
- User Account Controls
- Applocker
- Software
- Code
8 Tokens
6
Q
Hide user
A
add $
regedit