{"enrichment":{"faq":[{"a":"windows-privilege-escalation teaches systematic methods to move from low-privilege shell to SYSTEM or admin. It covers token manipulation, Potato family exploits (JuicyPotato, GodPotato, PrintSpoofer), weak service configurations, DLL hijacking, UAC bypass techniques, scheduled task abuse, and registry autorun abuse\u2014each with specific commands and tool recommendations for different OS versions.","q":"What windows privilege escalation techniques does this playbook cover?"},{"a":"windows-privilege-escalation identifies and exploits service misconfigurations for privilege gain. The playbook covers unquoted service paths, weak file permissions, and service binary hijacking. It includes enumeration techniques to find vulnerable services and step-by-step exploitation methods tailored to different Windows versions.","q":"How do I escalate privileges on windows using service misconfigurations?"},{"a":"windows-privilege-escalation leverages token manipulation through Potato family exploits including JuicyPotato, GodPotato, and PrintSpoofer. These techniques abuse token impersonation and named pipe interactions to escalate from service accounts to SYSTEM, with specific guidance on which variant works best for your target OS version.","q":"What are Potato exploits and how does windows-privilege-escalation use them?"},{"a":"Yes. windows-privilege-escalation covers UAC bypass techniques to achieve elevated code execution. The playbook details multiple bypass methods including registry manipulation, scheduled task abuse, and application whitelisting bypasses, with commands and tool recommendations for each approach.","q":"Can windows-privilege-escalation help me bypass UAC?"},{"a":"windows-privilege-escalation provides systematic enumeration methods to identify escalation paths. It includes guidance on using tools like WinPEAS and PowerUp to discover weak configurations, misconfigurations, and exploitable conditions across services, registry, scheduled tasks, and file permissions.","q":"How does windows-privilege-escalation enumerate Windows security posture?"},{"a":"windows-privilege-escalation covers DLL hijacking for privilege escalation by exploiting search path vulnerabilities and weak DLL loading. It also details token impersonation techniques including SeImpersonate privilege exploitation, named pipe impersonation, and credential dumping from LSASS for comprehensive privilege escalation paths.","q":"What about DLL hijacking and token impersonation in windows-privilege-escalation?"}],"shadow_tags":["post-exploitation","privilege-escalation","windows-security","exploit-techniques","system-hardening","vulnerability-assessment","lateral-movement","persistence-mechanisms"],"summary_rewrite":"This playbook teaches you how to move from low-privilege shell access to SYSTEM or admin on Windows through systematic enumeration and exploitation. It covers token manipulation, Potato family exploits, weak service configurations, DLL hijacking, UAC bypass techniques, scheduled task abuse, and registry autorun abuse\u2014each with specific commands and tool recommendations for different OS versions."},"files":[{"bytes":10789,"path":"skills/windows-privilege-escalation/SKILL.md","sha256":"f9a84405529a5921861e603c917dc079fa473af3ba113afbb6710c53d6b310ab","url":"https://skillfed.io/files/yaklang/hack-skills/windows-privilege-escalation/0a738492/SKILL.md"}],"id":"yaklang/hack-skills/windows-privilege-escalation","links":{"html":"https://skillfed.io/yaklang/hack-skills/windows-privilege-escalation","md":"https://skillfed.io/yaklang/hack-skills/windows-privilege-escalation.md","repo":"https://github.com/yaklang/hack-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":196,"language":"CSS","last_updated":"2026-06-16","license":"MIT","name":"windows-privilege-escalation","publisher":"yaklang","stars":1480},"relations":{"similar":[{"id":"zebbern/claude-code-guide/windows-privilege-escalation"},{"id":"blacklanternsecurity/red-run/windows-token-impersonation"},{"id":"blacklanternsecurity/red-run/windows-discovery"},{"id":"hypnguyen1209/offensive-claude/red-team-ops"},{"id":"hypnguyen1209/offensive-claude/privesc-windows"},{"id":"blacklanternsecurity/red-run/windows-uac-bypass"},{"id":"blacklanternsecurity/red-run/windows-service-dll-abuse"},{"id":"hypnguyen1209/offensive-claude/windows-boundaries"},{"id":"blacklanternsecurity/red-run/windows-kernel-exploits"},{"id":"blacklanternsecurity/red-run/gpo-abuse"}]},"slug":{"owner":"yaklang","repo":"hack-skills","skill":"windows-privilege-escalation"},"version":"0a738492"}
