Windows Privilege Escalation Flashcards
6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Windows Privilege Escalation flashcards as text
What is a 'scheduled task' privilege escalation in Windows and what must be true for it to work?
Answer: The task runs under a higher-privileged account and the current user can modify the task's action or its script/binary
Scheduled task escalation works when a task runs as a privileged user (e.g., SYSTEM) and the current user can overwrite the script or binary that the task executes.
What command in Windows lists all scheduled tasks with their run-as users?
Answer: schtasks /query /fo LIST /v
The 'schtasks /query /fo LIST /v' command lists all scheduled tasks in verbose list format, showing the task name, run-as user, schedule, and the program being executed.
What is User Account Control (UAC) bypass and why is it important during OSCP?
Answer: Elevating from a medium-integrity admin account to a high-integrity process without triggering UAC prompts
UAC bypass techniques allow an already-administrative but medium-integrity process to elevate to high integrity without displaying a UAC consent prompt, completing the privilege escalation.
Which Windows registry key stores hashed credentials for locally cached domain accounts?
Answer: HKLM\SECURITY\Cache
The HKLM\SECURITY\Cache registry key stores NL$Cache entries, which are MS-Cache v2 hashes of domain user credentials cached for offline login.
What is the significance of finding 'SeBackupPrivilege' on a Windows account during OSCP?
Answer: It allows bypassing filesystem ACLs to read any file, including the SAM and SYSTEM hives
SeBackupPrivilege allows reading any file on the system regardless of ACLs, enabling an attacker to copy the SAM and SYSTEM registry hives and extract all local password hashes offline.
When a Windows service runs as LocalSystem and you can restart it, what privilege escalation outcome is possible?
Answer: You can execute arbitrary code as SYSTEM if you can modify the service binary or configuration
If you can modify a service binary or its configuration and the service runs as LocalSystem (SYSTEM), restarting the service executes your payload with full SYSTEM privileges.