Windows
Decision Tree: Shell on Windows → What First?
reference
- Recon
- Enumerate
- Foothold
- PrivEsc
- Lateral
- Post-Ex
reached from Foothold (Windows)
You have a shell on a Windows host (a user session, maybe a meterpreter session). Get your bearings, automate the sweep, then escalate.
start Shell on Windows, a user session (maybe a meterpreter session)
- 1Immediate Situational Awareness (whoami /priv, systeminfo, patch level)
- 2WinPEAS (automate the whole enumeration sweep)
- 3Check your token and services
- SeImpersonatePrivilege → Potato Attack Chain (a service account? Potato to SYSTEM)
- Service Misconfigurations (weak service perms, unquoted service paths)
- 4Hunt for credentials
- Registry Password Hunting (autologon, VNC, PuTTY secrets)
- Stored Credentials (cmdkey, Credential Manager, config files)
- 5Token Impersonation · Incognito (reuse a token you can already reach)
follows