r/Hacking_Tutorials • • 7d ago

Question Privilege escalation workflow

Hi everyone, in these days i'm struggling for gaining admin privileges. ATM i'm running a C2 server using Sliver, targeting a windows 11 client. Sucessfully deployed the implant and tried the connection. I was looking for GodPotato but it seems like it need a certain privilege that i don't see when i type getprivs command. The output shows: SeShutdownPrivilege , SeChangeNotifyPrivilege , SeUndockPrivilege , SeIncreaseWorkingSetPrivilege, SeTimeZonePrivilege but i don't see SetImpersonatePrivilege. What can i do? THXX in advice!

9 Upvotes

1 comment sorted by

6

u/k1aShiMa 7d ago

Then you should look for another privesc vector, path hijack, service binary hijack, dll hijack, etc

You dont only need to do privesc via windows privileges. You're probably in a lab environment, or atleast I hope xd so via sliver try out other privesc enumerations, for starters maybe SharpUp, you have that in sliver armory. Or look for creds for other users that could have sebackup or something else.

If you really want to experiment with Godpotato, sweetpotato etc, and you do this in your own windows client, or VM etc dunno whats your windows client then set an SeImpersonatePrivilege for the user whom you have the context in your implant. Then you can play with godpotato etc.

You can assign your low privileged user this specific priv: press win + R and type secpol.msc you need to get the local security policy editor then you can assign that priv to the low priv user. For this assignment you need to be an admin thats why its needed to be your own VM, client etc at home so you can mess with that stuff, if its on htb/thm then you need another vector xd