Windows Privilege Escalation Flashcards
6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Windows Privilege Escalation flashcards as text
What Windows command displays all locally stored credentials and cached tokens?
Answer: cmdkey /list
The 'cmdkey /list' command displays all credentials stored in the Windows Credential Manager, which may include domain accounts, RDP credentials, or service account passwords.
What does the 'whoami /priv' command reveal that is useful for Windows privilege escalation?
Answer: The user's group memberships and enabled/disabled token privileges
The 'whoami /priv' command lists all privilege tokens assigned to the current user, revealing potentially exploitable privileges like SeImpersonatePrivilege or SeDebugPrivilege.
Which tool is used during OSCP to enumerate misconfigured Windows services for privilege escalation?
Answer: WinPEAS
WinPEAS (Windows Privilege Escalation Awesome Script) automatically enumerates potential privilege escalation vectors including misconfigured services, DLL hijacking paths, and unquoted service paths.
What is an 'unquoted service path' vulnerability in Windows?
Answer: A service with its binary path not enclosed in quotes, allowing path hijacking if the path contains spaces
When a Windows service's binary path contains spaces and is not enclosed in quotes, Windows tries multiple path interpretations, allowing an attacker to place a malicious executable in an intermediate path.
What Windows command lists all services and their start types, useful for identifying auto-start services to target?
Answer: wmic service list brief
The 'wmic service list brief' command provides a concise list of all Windows services including their name, process ID, start mode, and status.
Which registry hive contains Windows auto-run entries that execute programs at system startup, useful for persistence?
Answer: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry key contains entries that execute programs at system startup for all users, making it a common persistence and privilege escalation target.