EOP Windows Tools and Resources

Hacktricks Checklistarrow-up-right.

Best tool to look for privilege escalation WinPEASSarrow-up-right.

PayloadAllTheThingsarrow-up-right EOP.

Compiled binariesarrow-up-right

Useful Tools :

  • Seatbeltarrow-up-right is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.

  • PowerUparrow-up-right PowerShell script Windows privilege escalation vectors that rely on misconfigurations. It can also be used to exploit some of the issues found.

  • SharpUparrow-up-right SharpUp is a C# port of various PowerUp functionality

  • JAWSarrow-up-right Just Another Windows (Enum) Script.

  • SessionGopherarrow-up-right SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop.

  • Watsonarrow-up-right Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities.

  • LaZagnearrow-up-right Tool used for retrieving passwords stored on a local machine from web browsers, chat tools, databases, Git, email, memory dumps, PHP, sysadmin tools, wireless network configurations, internal Windows password storage mechanisms, and more.

  • Windows Exploit Suggester arrow-up-right- Next Generation : WES-NG is a tool based on the output of Windows' systeminfo utility which provides the list of vulnerabilities the OS is vulnerable to, including any exploits for these vulnerabilities.

  • enumeration script like Sherlockarrow-up-right to look for missing patches

  • SharpGPOAbusearrow-up-right is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.

Kernel exploits, end of life systems

Websites :

  • This pagearrow-up-right has a more detailed listing of the end-of-life dates for Microsoft Windows and other products

Last updated