{"enrichment":{"faq":[{"a":"privesc-windows is a comprehensive guide to Windows privilege escalation techniques. It covers multiple escalation paths including token-impersonation attacks (GodPotato, SigmaPotato, PrintNotifyPotato), UAC bypass methods, service and DLL hijacking, kernel exploits, and credential harvesting from LSASS, SAM, and DPAPI. The guide includes enumeration strategies, exploitation tactics, OPSEC guidance, and detection evasion for each method.","q":"What is privesc-windows and what does it cover?"},{"a":"privesc-windows details token-impersonation exploitation via the Potato family of tools. These techniques exploit the SeImpersonate privilege to escalate from low-privilege shell to SYSTEM/admin. Methods include GodPotato, SigmaPotato, and PrintNotifyPotato, which leverage COM elevation and token impersonation to bypass privilege restrictions. The guide explains the mechanics, prerequisites, and detection evasion for each variant.","q":"How to escalate privileges on windows using token impersonation?"},{"a":"privesc-windows covers enumeration of Windows privilege escalation vectors using tools like WinPEAS and Seatbelt. These tools identify misconfigurations, weak service permissions, unquoted paths, kernel vulnerabilities, and other escalation opportunities. The guide explains how to interpret enumeration output and prioritize exploitation targets based on reliability and OPSEC impact.","q":"What enumeration tools does privesc-windows recommend?"},{"a":"Yes. privesc-windows covers UAC bypass methods including fodhelper, icmluautil COM elevation, and other techniques. It also addresses kernel protections and BYOVD (Bring Your Own Vulnerable Driver) approaches for bypassing modern defenses. The guide explains each bypass mechanism, prerequisites, and how to combine them with other escalation vectors.","q":"Can privesc-windows help with UAC bypass techniques?"},{"a":"privesc-windows guides credential harvesting from multiple sources: LSASS dumps via Mimikatz, SAM registry extraction for offline cracking, and DPAPI vault extraction. The guide explains each harvesting method, lateral movement implications, and tactical considerations for maintaining access while evading detection.","q":"How does privesc-windows address credential harvesting?"},{"a":"privesc-windows covers service-based escalation including DLL hijacking, unquoted service path exploitation, and scheduled task privilege escalation. The guide explains how to identify vulnerable services, craft payloads, and maintain persistence while minimizing detection risk across different Windows versions and configurations.","q":"What service exploitation methods are covered?"}],"shadow_tags":["post-exploitation","token-abuse","kernel-exploit","credential-theft","evasion-technique","windows-hardening","lateral-movement","system-access","exploit-chain","red-team-tradecraft"],"summary_rewrite":"privesc-windows guides you through multiple privilege-escalation paths on Windows hosts, from token-impersonation attacks (GodPotato, SigmaPotato, PrintNotifyPotato) and UAC bypass techniques to service/DLL hijacking and kernel exploits. It covers enumeration, exploitation, and credential harvesting with tactical OPSEC guidance and detection evasion for each method."},"files":[{"bytes":10805,"path":"skills/privesc-windows/SKILL.md","sha256":"a11d2912b25792bc9a0bee49922447b8dfc844b8a3dbdc3f9962b89e0522c1b5","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/privesc-windows/3c25ce1f/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/privesc-windows","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/privesc-windows","md":"https://skillfed.io/hypnguyen1209/offensive-claude/privesc-windows.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"privesc-windows","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"yaklang/hack-skills/windows-privilege-escalation"},{"id":"hypnguyen1209/offensive-claude/windows-boundaries"},{"id":"blacklanternsecurity/red-run/windows-discovery"},{"id":"zebbern/claude-code-guide/windows-privilege-escalation"},{"id":"blacklanternsecurity/red-run/windows-token-impersonation"},{"id":"blacklanternsecurity/red-run/windows-credential-harvesting"},{"id":"hypnguyen1209/offensive-claude/windows-mitigations"},{"id":"blacklanternsecurity/red-run/adcs-persistence"},{"id":"blacklanternsecurity/red-run/windows-kernel-exploits"},{"id":"hypnguyen1209/offensive-claude/threat-hunting"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"privesc-windows"},"version":"3c25ce1f"}
