Windows
Windows host’ta düşük yetkili kullanıcıdan yüksek yetkiye (local admin / SYSTEM) çıkmak ve ardından kimlik bilgisi toplamak, iç ağ ve AD saldırı zincirinin omurgasıdır. Bu bölüm yerel PE, credential dumping ve UAC/token konularını Türkçe olarak ele alır. Domain dominasyonu için Active Directory bölümüne bakın.
Bağlam
Section titled “Bağlam”Dayanak: phishing / RCE / RDP / WinRM / VPN workstationHedef: local admin → SYSTEM → SAM/LSA/LSASS → yanalAraçlar: WinPEAS, PowerUp, Seatbelt, Mimikatz, Impacket, RubeusYerel yükseltme çoğu zaman zayıf servis ACL’si, unquoted path, AlwaysInstallElevated, otomatik logon ve token privilege’lerinden gelir. UAC bypass tek başına “tam admin” değildir; integrity level ve linked token ayrımını bilmek gerekir.
Metodoloji
Section titled “Metodoloji”-
Enumeration — whoami, gruplar, privs, servisler, kayıt defteri, scheduled task.
-
Hızlı PE — PowerUp / WinPEAS bulgularını doğrula ve sömür.
-
Token / UAC — SeImpersonate (potato), linked token, integrity.
-
Credential access — SAM, LSA secrets, DPAPI, LSASS (yetki sonrası).
-
Yanal — PtH, RDP, WinRM, AD teknikleri.
Tipik saldırı yüzeyi
Section titled “Tipik saldırı yüzeyi”| Vektör | Ne aranır |
|---|---|
| Servisler | Yazılabilir binPath, zayıf DACL, unquoted path |
| Registry | AlwaysInstallElevated, AutoLogon, Service ImagePath |
| Scheduled Tasks | Yüksek yetkili + yazılabilir action |
| Token privs | SeImpersonate, SeAssignPrimaryToken, SeDebug |
| UAC | Auto-elevate, registry hijack, fodhelper sınıfı |
| Potato ailesi | SYSTEM impersonation (print/RPC/DCOM) |
| Credential store | SAM, LSA, DPAPI, Credential Manager |
Araç çantası
Section titled “Araç çantası”WinPEAS / Seatbelt / SharpUp / PowerUp → enumaccesschk / icacls / sc.exe → ACL & servisJuicyPotato / PrintSpoofer / GodPotato → SeImpersonatemimikatz / secretsdump / lsassy → credentialRubeus / Impacket → ticket & remoteBölümler
Section titled “Bölümler”- Privilege Escalation — servisler, AlwaysInstallElevated, unquoted path, potato, WinPEAS
- Credential Dumping — SAM, LSA, DPAPI (AD sayfalarına köprü)
- UAC & Tokens — UAC, token, privilege’ler
İlgili: LSASS Dumping, DPAPI, Pass-the-Hash.
Zincir örnekleri
Section titled “Zincir örnekleri”lowpriv shell → WinPEAS → unquoted service path → admin → secretsdump SAM → PtHIIS apppool → SeImpersonatePrivilege → PrintSpoofer → SYSTEM → LSASS dump → HasSession DAmedium IL admin → UAC bypass → high IL → mimikatz / lateralTüm konu başlıkları
Section titled “Tüm konu başlıkları”- MSSQL AD Abuse
- BadSuccessor
- Abusing Active Directory ACLs/ACEs
- AD CS Account Persistence
- AD CS Certificate Theft
- AD CS Domain Escalation
- AD CS Domain Persistence
- AD Certificates
- AD DNS Records
- Ad Dynamic Objects Anti Forensics
- AD information in printers
- Adws Enumeration
- ASREPRoast
- Badsuccessor Dmsa Migration Abuse
- BloodHound & Other AD Enum Tools
- Constrained Delegation
- Custom SSP
- DCShadow
- Diamond Ticket
- DSRM Credentials
- External Forest Domain - One-Way (Outbound)
- External Forest Domain - OneWay (Inbound) or bidirectional
- Golden Dmsa Gmsa
- Active Directory Methodology
- Kerberoast
- Kerberos Authentication
- Kerberos Double Hop Problem
- Lansweeper Security
- LAPS
- Ldap Signing And Channel Binding
- Over Pass the Hash/Pass the Key
- Password Spraying / Brute Force
- Force NTLM Privileged Authentication
- PrintNightmare
- Privileged Groups
- RDP Sessions Abuse
- Resource-based Constrained Delegation
- Sccm Management Point Relay Sql Policy Secrets
- Security Descriptors
- SID-History Injection
- Skeleton Key
- Timeroasting
- Authentication Credentials Uac And Efs
- UAC - User Account Control
- Antivirus (AV) Bypass
- Basic Win CMD for Pentesters
- Basic PowerShell for Pentesters
- PowerView/SharpView
- Checklist - Local Windows Privilege Escalation
- Cobalt Strike
- AtExec / SchtasksExec
- DCOM Exec
- Lateral Movement
- PsExec/Winexec/ScExec
- RDPexec
- SCMexec
- WinRM
- WmiExec
- Mythic
- NTLM
- Places to steal NTLM creds
- Protocol Handler Shell Execute Abuse
- Mimikatz
- Windows Credentials Protections
- Stealing Windows Credentials
- WTS Impersonator
- Abusing Auto Updaters And Ipc
- Access Tokens
- ACLs - DACLs/SACLs/ACEs
- AppendData/AddSubdirectory permission over service registry
- Arbitrary Kernel Rw Token Theft
- COM Hijacking
- Create MSI with WIX
- Advanced Html Staged Dll Sideloading
- Dll Hijacking
- Writable Sys Path +Dll Hijacking Privesc
- DPAPI - Extracting Passwords
- From High Integrity to SYSTEM with Name Pipes
- Windows Local Privilege Escalation
- Integrity Levels
- JuicyPotato
- Kernel Race Condition Object Manager Slowdown
- Leaked Handle Exploitation
- Local NTLM Reflection via SMB Arbitrary Port
- MSI Wrapper
- Named Pipe Client Impersonation
- Notepad Plus Plus Plugin Autoload Persistence
- Abusing Tokens
- Privilege Escalation with Autoruns
- RoguePotato, PrintSpoofer, SharpEfsPotato, GodPotato
- Secure Desktop Accessibility Registry Propagation LPE (RegPwn)
- SeDebug + SeImpersonate copy token
- SeImpersonate from High To System
- Semanagevolume Perform Volume Maintenance Tasks
- Service Triggers
- Telephony Tapsrv Arbitrary Dword Write To Rce
- Uiaccess Admin Protection Bypass
- Windows C Payloads
- Windows Registry Hive Exploitation