4.2 Windows Host & Privilege Enumeration

Key Takeaways

  • System profiling with systeminfo and WMIC queries reveals the Windows build number, hotfix patching history, and system architecture needed to assess exploit eligibility.

  • Querying user token privileges with whoami /priv isolates dangerous rights such as SeImpersonatePrivilege, which allows immediate elevation to NT AUTHORITY\SYSTEM via Potato family exploits.

  • Inspecting network configuration and socket state with ipconfig /all and netstat -ano identifies multi-homed pivot interfaces and internal listening services bound to local ports.

  • Service configuration auditing exposes critical privilege escalation vectors such as unquoted service paths and weak file permissions on executable binaries.

Last updated: October 2026

Windows Operating System & Architecture Profiling

Auditing a compromised Windows host requires an understanding of the Windows architecture, user account privileges, security tokens, and service management subsystems. Obtaining an initial low-privilege command shell—whether as a standard domain user, a local user, or a service account like NT AUTHORITY\NETWORK SERVICE or iis apppool\defaultapppool—necessitates immediate local enumeration to chart a path toward NT AUTHORITY\SYSTEM.

System Profiling with systeminfo

The systeminfo command-line utility queries the Windows Management Instrumentation (WMI) subsystem and the registry to generate a comprehensive snapshot of the host's operating system environment:

systeminfo
Host Name:                 CORP-WS01
OS Name:                   Microsoft Windows 10 Pro
OS Version:                10.0.17763 N/A Build 17763
OS Manufacturer:           Microsoft Corporation
OS Build Type:             Multiprocessor Free
System Type:               x64-based PC
Processor(s):              1 Processor(s) Installed.
Domain:                    INTRANET.LOCAL
Hotfix(s):                 3 Hotfix(s) Installed.
                           [01]: KB4465477
                           [02]: KB4465664
                           [03]: KB4470788

Key data points extracted from systeminfo include:

  • OS Version & Build Number: 10.0.17763 Build 17763 identifies Windows 10 Version 1809 (Redstone 5). Operating system builds correlate directly with known local privilege escalation vulnerabilities.
  • System Type: x64-based PC confirms a 64-bit architecture. Executing 32-bit payloads on 64-bit Windows invokes the WOW64 (Windows 32-bit on Windows 64-bit) emulation subsystem, which can complicate token manipulation and in-memory injection.
  • Domain vs. Workgroup: INTRANET.LOCAL indicates that the machine is joined to an Active Directory domain, opening opportunities for Kerberos ticket inspection, bloodhound data collection, and domain reconnaissance.
  • Hotfix List: Enumerates all installed Knowledge Base (KB) updates.

Patch Analysis via WMIC

While systeminfo lists installed hotfixes, it often fails to display complete patch descriptions or truncation occurs in large enterprise environments. The Windows Management Instrumentation Command-line (wmic) tool provides a more detailed query:

wmic qfe get Caption,Description,HotFixID,InstalledOn
Caption                                     Description      HotFixID   InstalledOn
http://support.microsoft.com/?kbid=4465477  Security Update  KB4465477  11/15/2018
http://support.microsoft.com/?kbid=4465664  Update           KB4465664  11/20/2018

Penetration testers compare the installed hotfix IDs against published vulnerability bulletins. If critical elevation patches—such as MS16-032 (Secondary Logon Handle flaw) or specific Windows kernel updates—are missing, corresponding local exploits can be evaluated.

User Accounts, Groups & Token Privileges

Windows implements access control through Access Tokens. When a user logs in, Windows generates an access token containing the user's Security Identifier (SID), group SIDs, and specific assigned administrative privileges. Every process spawned by that user inherits a copy of this token.

Identity & Group Inspection

To view the current user context, groups, and assigned token privileges in a single command:

whoami /all

To view only group memberships:

whoami /groups

To query local accounts and groups via the net command suite:

REM List all local users on the workstation
net user

REM Inspect a specific user account's properties
net user student

REM List all local security groups
net localgroup

REM List all members of the local Administrators group
net localgroup administrators

If the current user is already a member of BUILTIN\Administrators, full system control can be achieved simply by bypassing User Account Control (UAC) if operating in a medium-integrity shell.

Dangerous Token Privileges (whoami /priv)

Running whoami /priv is one of the most critical steps in Windows enumeration. It reveals the granular privileges granted to the active process token:

whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name                Description                               State
============================= ========================================= ======== 
SeSecurityPrivilege           Manage auditing and security log          Disabled
SeShutdownPrivilege           Shut down the system                      Disabled
SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled
SeUndockPrivilege             Remove computer from docking station      Disabled
SeImpersonatePrivilege        Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege       Create global objects                     Enabled

Specific privileges present extraordinary security risks because they permit direct elevation to NT AUTHORITY\SYSTEM:

  1. SeImpersonatePrivilege:

    • Default Context: Held by local service accounts, including LOCAL SERVICE, NETWORK SERVICE, and Microsoft IIS application pools (IIS APPPOOL\*).
    • Security Risk: Grants the ability to impersonate any security token that can be persuaded to authenticate against a local named pipe, RPC endpoint, or COM object controlled by the process.
    • Exploitation: The "Potato" family of exploits—including RottenPotato, JuicyPotato, PrintSpoofer, and GodPotato—abuses this privilege. Attackers force an elevated system service (such as RPC or the Windows Print Spooler via PrintSpoofer.exe) to authenticate against a custom loopback listener, capture the system token, and spawn an arbitrary process as NT AUTHORITY\SYSTEM.
  2. SeDebugPrivilege:

    • Default Context: Held by members of the local Administrators group.
    • Security Risk: Permits attaching debuggers to, and reading/writing the memory of, any active process running on the operating system, bypassing standard discretionary access control lists (DACLs).
    • Exploitation: An attacker with SeDebugPrivilege can attach to the Local Security Authority Subsystem Service (lsass.exe), read process memory, and extract plaintext passwords, Kerberos tickets, and NTLM hashes using Mimikatz or create a full memory dump via Sysinternals ProcDump (procdump.exe -ma lsass.exe lsass.dmp).
  3. SeAssignPrimaryTokenPrivilege:

    • Security Risk: Closely mirrors SeImpersonatePrivilege. It permits assigning a created or impersonated token directly to a new child process.
  4. SeBackupPrivilege & SeRestorePrivilege:

    • Security Risk: Designed for administrative backup software. These privileges grant read (SeBackupPrivilege) or write (SeRestorePrivilege) access to any file on the system, regardless of its file permissions or ACLs.
    • Exploitation: An attacker can read the raw Security Account Manager (SAM) and SYSTEM registry hives (reg save hklm\sam sam.save and reg save hklm\system system.save) or extract Active Directory database files (NTDS.dit), allowing offline password hash cracking.

Network Configuration, Active Connections & Firewall State

Mapping the local network interfaces and active sockets on a Windows target discloses lateral movement vectors and internal listening daemons.

Network Interfaces and ARP Discovery

To view network adapters, DHCP configurations, and DNS servers:

ipconfig /all

Examining the output verifies whether the host connects to multiple subnets (such as an external web-facing interface and an internal database VLAN). To view recently communicated hosts on the local network segment without generating port scan traffic, inspect the Address Resolution Protocol (ARP) table:

arp -a
Interface: 192.168.1.50 --- 0xb
  Internet Address      Physical Address      Type
  192.168.1.1           00-50-56-fa-89-12     dynamic
  192.168.1.5           00-50-56-fa-11-aa     dynamic
  192.168.1.254         00-50-56-fa-fe-01     dynamic

The ARP cache reveals neighboring systems actively communicating with the compromised workstation.

Routing Tables

Inspect static routes, interface metrics, and gateway configurations:

route print

Active Sockets and Process Correlation

To view all active TCP and UDP connections along with their owning Process Identifiers (PIDs):

netstat -ano
Active Connections
  Proto  Local Address          Foreign Address        State           PID
  TCP    0.0.0.0:135            0.0.0.0:0              LISTENING       844
  TCP    0.0.0.0:445            0.0.0.0:0              LISTENING       4
  TCP    127.0.0.1:8080         0.0.0.0:0              LISTENING       3244
  TCP    192.168.1.50:49670     192.168.1.5:445        ESTABLISHED     4

In this output, port 8080 is listening exclusively on 127.0.0.1 and is owned by PID 3244. To identify which executable corresponds to PID 3244:

tasklist /FI "PID eq 3244"
# Output:
# Image Name                     PID Session Name        Session#    Mem Usage
# ========================= ======== ================ =========== ============
# node.exe                       3244 Services                   0     45,210 K

This indicates an internal Node.js web application running locally on port 8080.

Windows Defender Firewall Auditing

To check whether the host firewall is filtering inbound or outbound traffic:

netsh advfirewall show allprofiles

Reviewing the state (ON or OFF) across Domain, Private, and Public profiles indicates whether inbound bind shells or tools will encounter firewall drops.

Services, Scheduled Tasks & Privilege Escalation Vectors

Windows services execute background tasks and frequently run under elevated security contexts such as NT AUTHORITY\SYSTEM. Misconfigurations in how these services are registered and permissioned present reliable privilege escalation vectors.

Enumerating Services and Executable Paths

To list currently running services:

net start

To inspect service details, startup types, and executable binary paths using WMIC:

wmic service get name,displayname,pathname,startmode

Alternatively, query individual services using the Service Control command (sc qc):

sc qc Spooler
# Output:
# [SC] QueryServiceConfig SUCCESS
# SERVICE_NAME: Spooler
#         TYPE               : 110  WIN32_OWN_PROCESS  (interactive)
#         START_TYPE         : 2   AUTO_START
#         BINARY_PATH_NAME   : C:\Windows\System32\spoolsv.exe
#         SERVICE_START_NAME : LocalSystem

Unquoted Service Paths (Deep Dive)

An Unquoted Service Path is a widespread Windows misconfiguration occurring when a service's binary path contains spaces and is not enclosed in quotation marks.

The Underlying Vulnerability Mechanism

When Windows initializes a service executable, the operating system uses the CreateProcess API. If the path parameter is unquoted and contains spaces, Windows cannot inherently distinguish whether a space represents the end of an executable name or a space within a directory title.

For example, consider a service with the following unquoted BINARY_PATH_NAME:

C:\Program Files\Enterprise Software\Backup Agent\agent.exe

Because the path contains spaces and lacks enclosing quotes ("), Windows sequentially evaluates the path at every whitespace boundary, appending .exe to each segment in an attempt to execute the first match:

  1. C:\Program.exe
  2. C:\Program Files\Enterprise.exe
  3. C:\Program Files\Enterprise Software\Backup.exe
  4. C:\Program Files\Enterprise Software\Backup Agent\agent.exe

The Exploitation Vector

If a low-privilege user possesses write or modify permissions in any of the intermediate parent directories (such as C:\Program Files\Enterprise Software\), they can compile a malicious payload, name it Backup.exe, and place it in that directory.

When the system restarts or the service is restarted, Windows attempts to execute C:\Program Files\Enterprise Software\Backup.exe before reaching agent.exe. Because the service runs under the LocalSystem (NT AUTHORITY\SYSTEM) account, the attacker's Backup.exe executes with full administrative privileges.

Querying for Unquoted Service Paths

Testers can query WMIC to automatically locate vulnerable unquoted paths while excluding default Windows system paths:

wmic service get name,displayname,pathname,startmode | findstr /i /v "C:\Windows\\" | findstr /i /v '"'

Verifying Directory Permissions with icacls

Before dropping a payload, the tester must verify write permissions on the intermediate folder using icacls:

icacls "C:\Program Files\Enterprise Software"
C:\Program Files\Enterprise Software BUILTIN\Users:(OI)(CI)(M)
                                    NT AUTHORITY\SYSTEM:(F)
                                    BUILTIN\Administrators:(F)

Key permissions to evaluate:

  • (F): Full Access
  • (M): Modify Access (permits creating, modifying, and deleting files)
  • (W): Write Access

If BUILTIN\Users or NT AUTHORITY\Authenticated Users possesses (M) or (W) rights, the directory is writable, confirming that an unquoted service path exploit can be deployed.

Scheduled Tasks Enumeration

The Windows Task Scheduler runs background scripts and applications at set intervals or upon system events. Querying scheduled tasks exposes tasks that run as SYSTEM or administrative users:

schtasks /query /fo LIST /v

Testers inspect custom tasks located outside C:\Windows\System32. If a scheduled task executes a batch script, PowerShell script, or executable in a directory writable by unprivileged users, replacing the target file or appending commands achieves elevated execution when the task fires.

Windows Enumeration Reference Tables

CommandPrimary Audit ObjectiveKey Insight / Risk
systeminfoDisplays complete OS build, system architecture, and hotfixes.Correlates missing hotfixes with published kernel exploits.
wmic qfe get HotFixID,InstalledOnDetailed listing of installed Windows security updates.Identifies unpatched privilege escalation vulnerabilities.
whoami /privEnumerates token privileges of the active process.Uncovers SeImpersonatePrivilege or SeDebugPrivilege for instant escalation.
net localgroup administratorsLists all users with local administrative authority.Identifies target accounts and validates privilege level.
ipconfig /allDisplays adapter addresses, subnet masks, and DNS servers.Maps multi-homed interfaces for lateral pivoting.
netstat -anoLists listening ports and active sockets with owning PIDs.Discovers internal services (127.0.0.1) not visible externally.
arp -aDisplays neighboring IP and MAC address pairings.Identifies active network neighbors without port scanning.
wmic service get name,pathnameDisplays service names and binary executable paths.Detects unquoted service paths and custom third-party daemons.
icacls <path>Displays discretionary access control lists (permissions).Confirms whether low-privilege users can modify binaries or folders.
schtasks /query /fo LIST /vQueries detailed scheduled task configurations.Uncovers automated administrative tasks running vulnerable scripts.
Privilege NameDefault Assigned GroupsExploitation Mechanism & Impact
SeImpersonatePrivilegeLOCAL SERVICE, NETWORK SERVICE, IIS AppPoolsAbused via Potato exploits (PrintSpoofer, GodPotato) to impersonate SYSTEM tokens and spawn a privileged shell.
SeDebugPrivilegeLocal AdministratorsPermits attaching to any process memory, enabling dumping lsass.exe to extract plaintext credentials and NTLM hashes.
SeAssignPrimaryTokenPrivilegeSystem & Service AccountsAllows assigning impersonated tokens to child processes, facilitating privilege escalation.
SeBackupPrivilegeBackup Operators, AdministratorsBypasses file ACLs to read any file on the system, enabling direct extraction of SAM and SYSTEM registry hives.
SeRestorePrivilegeBackup Operators, AdministratorsBypasses file ACLs to write or overwrite any file on the system, permitting binary replacement in system paths.
SeTakeOwnershipPrivilegeAdministratorsGrants the ability to take ownership of any system object or file, enabling full access configuration.
Test Your Knowledge

A penetration tester gains an initial shell on a Windows Server running Microsoft IIS. Running whoami /priv reveals that SeImpersonatePrivilege is enabled. Which method represents the primary attack vector to leverage this privilege to obtain NT AUTHORITY\SYSTEM access?

A

Overwriting the Kerberos krbtgt account hash using DCSync.

B

Modifying the local Administrator password using net user Administrator NewPass123.

C

Adding a malicious registry key to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run.

D

Deploying a Potato family exploit such as PrintSpoofer or GodPotato to capture and impersonate a SYSTEM token.

Test Your Knowledge

A Windows service is configured with the binary path C:\Program Files\Network Monitor\netmon.exe without enclosing quotation marks. If an unprivileged user has write permissions to C:\, which binary name will the Windows Service Control Manager attempt to execute first upon service startup?

A

C:\Program.exe

B

C:\Program Files\Network.exe

C

C:\Program Files\Network Monitor\netmon.exe

D

C:\netmon.exe

Test Your Knowledge

Which Windows command-line utility and query accurately retrieves a list of installed security hotfixes along with their specific Knowledge Base (KB) identifiers and installation dates?

A

net config server /all

B

sc query type= driver

C

wmic qfe get Caption,Description,HotFixID,InstalledOn

D

tasklist /svc /fi "STATUS eq RUNNING"

Sections you finish are checked off in the contents.