Windows

# SID representation (RID = 1001)
S-R-X-Y
S-1-5-21-1336799502-1441772794-948155058-1001
# Well known SIDs
S-1-0-0                       Nobody        
S-1-1-0	                      Everybody
S-1-5-11                      Authenticated Users
S-1-5-18                      Local System
S-1-5-domainidentifier-500    Administrator
# Integrity Levels
- System integrity  Kernel-mode processes with SYSTEM privileges
- High integrity  Processes with administrative privileges
- Medium integrity  Processes running with standard user privileges
- Low integrity level  Restricted processes, often used for security [sandboxing], such as web browsers.
- Untrusted  The lowest integrity level, assigned to highly restricted processes that pose potential security risks

Windows Permissions

Enumerating Windows

Credential Hunting

Service Binary Hijacking

DLL Hijacking

Standard DLL search order

Unquoted Service Paths

Scheduled Tasks

Kernel exploits

Abusing Windows privileges

Resources

Last updated