offensive-windows-privesc
Comprehensive Windows privilege escalation methodology for offensive security engagements. Covers the full attack surface from a standard user shell to NT AUTHORITY\SYSTEM: token impersonation via SeImpersonate and SeAssignPrimaryToken privileges using JuicyPotato, PrintSpoofer, GodPotato, SweetPotato, and RoguePotato; service misconfigurations including unquoted service paths, weak service DACLs, writable service binaries, and insecure service creation permissions; AlwaysInstallElevated MSI exploitation; DLL hijacking through search order abuse, phantom DLL loading, and writable PATH directory injection; UAC bypass techniques via fodhelper.exe, eventvwr.exe, CMSTP, and environment variable manipulation; scheduled task abuse for writable task actions and new task creation; registry autorun exploitation for persistence and escalation; PrintNightmare (CVE-2021-34527) for remote and local priv. . Use when performing authorized red-team, pentest, or research work involving windows privesc.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-windows-privesc/SKILL.md
- skills/offensive-windows-privesc/LICENSE
- skills/offensive-windows-privesc/README.md
- skills/offensive-windows-privesc/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.