4.2 Windows Host & Privilege Enumeration
Key Takeaways
System profiling with systeminfo and WMIC queries reveals the Windows build number, hotfix patching history, and system architecture needed to assess exploit eligibility.
Querying user token privileges with
whoami /privisolates dangerous rights such asSeImpersonatePrivilege, which allows immediate elevation toNT AUTHORITY\SYSTEMvia Potato family exploits.Inspecting network configuration and socket state with ipconfig /all and netstat -ano identifies multi-homed pivot interfaces and internal listening services bound to local ports.
Service configuration auditing exposes critical privilege escalation vectors such as unquoted service paths and weak file permissions on executable binaries.
Windows Operating System & Architecture Profiling
Auditing a compromised Windows host requires an understanding of the Windows architecture, user account privileges, security tokens, and service management subsystems. Obtaining an initial low-privilege command shell—whether as a standard domain user, a local user, or a service account like NT AUTHORITY\NETWORK SERVICE or iis apppool\defaultapppool—necessitates immediate local enumeration to chart a path toward NT AUTHORITY\SYSTEM.
System Profiling with systeminfo
The systeminfo command-line utility queries the Windows Management Instrumentation (WMI) subsystem and the registry to generate a comprehensive snapshot of the host's operating system environment:
systeminfo
Host Name: CORP-WS01
OS Name: Microsoft Windows 10 Pro
OS Version: 10.0.17763 N/A Build 17763
OS Manufacturer: Microsoft Corporation
OS Build Type: Multiprocessor Free
System Type: x64-based PC
Processor(s): 1 Processor(s) Installed.
Domain: INTRANET.LOCAL
Hotfix(s): 3 Hotfix(s) Installed.
[01]: KB4465477
[02]: KB4465664
[03]: KB4470788
Key data points extracted from systeminfo include:
- OS Version & Build Number:
10.0.17763 Build 17763identifies Windows 10 Version 1809 (Redstone 5). Operating system builds correlate directly with known local privilege escalation vulnerabilities. - System Type:
x64-based PCconfirms a 64-bit architecture. Executing 32-bit payloads on 64-bit Windows invokes the WOW64 (Windows 32-bit on Windows 64-bit) emulation subsystem, which can complicate token manipulation and in-memory injection. - Domain vs. Workgroup:
INTRANET.LOCALindicates that the machine is joined to an Active Directory domain, opening opportunities for Kerberos ticket inspection, bloodhound data collection, and domain reconnaissance. - Hotfix List: Enumerates all installed Knowledge Base (KB) updates.
Patch Analysis via WMIC
While systeminfo lists installed hotfixes, it often fails to display complete patch descriptions or truncation occurs in large enterprise environments. The Windows Management Instrumentation Command-line (wmic) tool provides a more detailed query:
wmic qfe get Caption,Description,HotFixID,InstalledOn
Caption Description HotFixID InstalledOn
http://support.microsoft.com/?kbid=4465477 Security Update KB4465477 11/15/2018
http://support.microsoft.com/?kbid=4465664 Update KB4465664 11/20/2018
Penetration testers compare the installed hotfix IDs against published vulnerability bulletins. If critical elevation patches—such as MS16-032 (Secondary Logon Handle flaw) or specific Windows kernel updates—are missing, corresponding local exploits can be evaluated.
User Accounts, Groups & Token Privileges
Windows implements access control through Access Tokens. When a user logs in, Windows generates an access token containing the user's Security Identifier (SID), group SIDs, and specific assigned administrative privileges. Every process spawned by that user inherits a copy of this token.
Identity & Group Inspection
To view the current user context, groups, and assigned token privileges in a single command:
whoami /all
To view only group memberships:
whoami /groups
To query local accounts and groups via the net command suite:
REM List all local users on the workstation
net user
REM Inspect a specific user account's properties
net user student
REM List all local security groups
net localgroup
REM List all members of the local Administrators group
net localgroup administrators
If the current user is already a member of BUILTIN\Administrators, full system control can be achieved simply by bypassing User Account Control (UAC) if operating in a medium-integrity shell.
Dangerous Token Privileges (whoami /priv)
Running whoami /priv is one of the most critical steps in Windows enumeration. It reveals the granular privileges granted to the active process token:
whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ========================================= ========
SeSecurityPrivilege Manage auditing and security log Disabled
SeShutdownPrivilege Shut down the system Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeUndockPrivilege Remove computer from docking station Disabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
Specific privileges present extraordinary security risks because they permit direct elevation to NT AUTHORITY\SYSTEM:
-
SeImpersonatePrivilege:- Default Context: Held by local service accounts, including
LOCAL SERVICE,NETWORK SERVICE, and Microsoft IIS application pools (IIS APPPOOL\*). - Security Risk: Grants the ability to impersonate any security token that can be persuaded to authenticate against a local named pipe, RPC endpoint, or COM object controlled by the process.
- Exploitation: The "Potato" family of exploits—including RottenPotato, JuicyPotato, PrintSpoofer, and GodPotato—abuses this privilege. Attackers force an elevated system service (such as RPC or the Windows Print Spooler via
PrintSpoofer.exe) to authenticate against a custom loopback listener, capture the system token, and spawn an arbitrary process asNT AUTHORITY\SYSTEM.
- Default Context: Held by local service accounts, including
-
SeDebugPrivilege:- Default Context: Held by members of the local
Administratorsgroup. - Security Risk: Permits attaching debuggers to, and reading/writing the memory of, any active process running on the operating system, bypassing standard discretionary access control lists (DACLs).
- Exploitation: An attacker with
SeDebugPrivilegecan attach to the Local Security Authority Subsystem Service (lsass.exe), read process memory, and extract plaintext passwords, Kerberos tickets, and NTLM hashes using Mimikatz or create a full memory dump via Sysinternals ProcDump (procdump.exe -ma lsass.exe lsass.dmp).
- Default Context: Held by members of the local
-
SeAssignPrimaryTokenPrivilege:- Security Risk: Closely mirrors
SeImpersonatePrivilege. It permits assigning a created or impersonated token directly to a new child process.
- Security Risk: Closely mirrors
-
SeBackupPrivilege&SeRestorePrivilege:- Security Risk: Designed for administrative backup software. These privileges grant read (
SeBackupPrivilege) or write (SeRestorePrivilege) access to any file on the system, regardless of its file permissions or ACLs. - Exploitation: An attacker can read the raw Security Account Manager (
SAM) andSYSTEMregistry hives (reg save hklm\sam sam.saveandreg save hklm\system system.save) or extract Active Directory database files (NTDS.dit), allowing offline password hash cracking.
- Security Risk: Designed for administrative backup software. These privileges grant read (
Network Configuration, Active Connections & Firewall State
Mapping the local network interfaces and active sockets on a Windows target discloses lateral movement vectors and internal listening daemons.
Network Interfaces and ARP Discovery
To view network adapters, DHCP configurations, and DNS servers:
ipconfig /all
Examining the output verifies whether the host connects to multiple subnets (such as an external web-facing interface and an internal database VLAN). To view recently communicated hosts on the local network segment without generating port scan traffic, inspect the Address Resolution Protocol (ARP) table:
arp -a
Interface: 192.168.1.50 --- 0xb
Internet Address Physical Address Type
192.168.1.1 00-50-56-fa-89-12 dynamic
192.168.1.5 00-50-56-fa-11-aa dynamic
192.168.1.254 00-50-56-fa-fe-01 dynamic
The ARP cache reveals neighboring systems actively communicating with the compromised workstation.
Routing Tables
Inspect static routes, interface metrics, and gateway configurations:
route print
Active Sockets and Process Correlation
To view all active TCP and UDP connections along with their owning Process Identifiers (PIDs):
netstat -ano
Active Connections
Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 844
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 127.0.0.1:8080 0.0.0.0:0 LISTENING 3244
TCP 192.168.1.50:49670 192.168.1.5:445 ESTABLISHED 4
In this output, port 8080 is listening exclusively on 127.0.0.1 and is owned by PID 3244. To identify which executable corresponds to PID 3244:
tasklist /FI "PID eq 3244"
# Output:
# Image Name PID Session Name Session# Mem Usage
# ========================= ======== ================ =========== ============
# node.exe 3244 Services 0 45,210 K
This indicates an internal Node.js web application running locally on port 8080.
Windows Defender Firewall Auditing
To check whether the host firewall is filtering inbound or outbound traffic:
netsh advfirewall show allprofiles
Reviewing the state (ON or OFF) across Domain, Private, and Public profiles indicates whether inbound bind shells or tools will encounter firewall drops.
Services, Scheduled Tasks & Privilege Escalation Vectors
Windows services execute background tasks and frequently run under elevated security contexts such as NT AUTHORITY\SYSTEM. Misconfigurations in how these services are registered and permissioned present reliable privilege escalation vectors.
Enumerating Services and Executable Paths
To list currently running services:
net start
To inspect service details, startup types, and executable binary paths using WMIC:
wmic service get name,displayname,pathname,startmode
Alternatively, query individual services using the Service Control command (sc qc):
sc qc Spooler
# Output:
# [SC] QueryServiceConfig SUCCESS
# SERVICE_NAME: Spooler
# TYPE : 110 WIN32_OWN_PROCESS (interactive)
# START_TYPE : 2 AUTO_START
# BINARY_PATH_NAME : C:\Windows\System32\spoolsv.exe
# SERVICE_START_NAME : LocalSystem
Unquoted Service Paths (Deep Dive)
An Unquoted Service Path is a widespread Windows misconfiguration occurring when a service's binary path contains spaces and is not enclosed in quotation marks.
The Underlying Vulnerability Mechanism
When Windows initializes a service executable, the operating system uses the CreateProcess API. If the path parameter is unquoted and contains spaces, Windows cannot inherently distinguish whether a space represents the end of an executable name or a space within a directory title.
For example, consider a service with the following unquoted BINARY_PATH_NAME:
C:\Program Files\Enterprise Software\Backup Agent\agent.exe
Because the path contains spaces and lacks enclosing quotes ("), Windows sequentially evaluates the path at every whitespace boundary, appending .exe to each segment in an attempt to execute the first match:
C:\Program.exeC:\Program Files\Enterprise.exeC:\Program Files\Enterprise Software\Backup.exeC:\Program Files\Enterprise Software\Backup Agent\agent.exe
The Exploitation Vector
If a low-privilege user possesses write or modify permissions in any of the intermediate parent directories (such as C:\Program Files\Enterprise Software\), they can compile a malicious payload, name it Backup.exe, and place it in that directory.
When the system restarts or the service is restarted, Windows attempts to execute C:\Program Files\Enterprise Software\Backup.exe before reaching agent.exe. Because the service runs under the LocalSystem (NT AUTHORITY\SYSTEM) account, the attacker's Backup.exe executes with full administrative privileges.
Querying for Unquoted Service Paths
Testers can query WMIC to automatically locate vulnerable unquoted paths while excluding default Windows system paths:
wmic service get name,displayname,pathname,startmode | findstr /i /v "C:\Windows\\" | findstr /i /v '"'
Verifying Directory Permissions with icacls
Before dropping a payload, the tester must verify write permissions on the intermediate folder using icacls:
icacls "C:\Program Files\Enterprise Software"
C:\Program Files\Enterprise Software BUILTIN\Users:(OI)(CI)(M)
NT AUTHORITY\SYSTEM:(F)
BUILTIN\Administrators:(F)
Key permissions to evaluate:
(F): Full Access(M): Modify Access (permits creating, modifying, and deleting files)(W): Write Access
If BUILTIN\Users or NT AUTHORITY\Authenticated Users possesses (M) or (W) rights, the directory is writable, confirming that an unquoted service path exploit can be deployed.
Scheduled Tasks Enumeration
The Windows Task Scheduler runs background scripts and applications at set intervals or upon system events. Querying scheduled tasks exposes tasks that run as SYSTEM or administrative users:
schtasks /query /fo LIST /v
Testers inspect custom tasks located outside C:\Windows\System32. If a scheduled task executes a batch script, PowerShell script, or executable in a directory writable by unprivileged users, replacing the target file or appending commands achieves elevated execution when the task fires.
Windows Enumeration Reference Tables
| Command | Primary Audit Objective | Key Insight / Risk |
|---|---|---|
systeminfo | Displays complete OS build, system architecture, and hotfixes. | Correlates missing hotfixes with published kernel exploits. |
wmic qfe get HotFixID,InstalledOn | Detailed listing of installed Windows security updates. | Identifies unpatched privilege escalation vulnerabilities. |
whoami /priv | Enumerates token privileges of the active process. | Uncovers SeImpersonatePrivilege or SeDebugPrivilege for instant escalation. |
net localgroup administrators | Lists all users with local administrative authority. | Identifies target accounts and validates privilege level. |
ipconfig /all | Displays adapter addresses, subnet masks, and DNS servers. | Maps multi-homed interfaces for lateral pivoting. |
netstat -ano | Lists listening ports and active sockets with owning PIDs. | Discovers internal services (127.0.0.1) not visible externally. |
arp -a | Displays neighboring IP and MAC address pairings. | Identifies active network neighbors without port scanning. |
wmic service get name,pathname | Displays service names and binary executable paths. | Detects unquoted service paths and custom third-party daemons. |
icacls <path> | Displays discretionary access control lists (permissions). | Confirms whether low-privilege users can modify binaries or folders. |
schtasks /query /fo LIST /v | Queries detailed scheduled task configurations. | Uncovers automated administrative tasks running vulnerable scripts. |
| Privilege Name | Default Assigned Groups | Exploitation Mechanism & Impact |
|---|---|---|
SeImpersonatePrivilege | LOCAL SERVICE, NETWORK SERVICE, IIS AppPools | Abused via Potato exploits (PrintSpoofer, GodPotato) to impersonate SYSTEM tokens and spawn a privileged shell. |
SeDebugPrivilege | Local Administrators | Permits attaching to any process memory, enabling dumping lsass.exe to extract plaintext credentials and NTLM hashes. |
SeAssignPrimaryTokenPrivilege | System & Service Accounts | Allows assigning impersonated tokens to child processes, facilitating privilege escalation. |
SeBackupPrivilege | Backup Operators, Administrators | Bypasses file ACLs to read any file on the system, enabling direct extraction of SAM and SYSTEM registry hives. |
SeRestorePrivilege | Backup Operators, Administrators | Bypasses file ACLs to write or overwrite any file on the system, permitting binary replacement in system paths. |
SeTakeOwnershipPrivilege | Administrators | Grants the ability to take ownership of any system object or file, enabling full access configuration. |
A penetration tester gains an initial shell on a Windows Server running Microsoft IIS. Running whoami /priv reveals that SeImpersonatePrivilege is enabled. Which method represents the primary attack vector to leverage this privilege to obtain NT AUTHORITY\SYSTEM access?
Overwriting the Kerberos krbtgt account hash using DCSync.
Modifying the local Administrator password using net user Administrator NewPass123.
Adding a malicious registry key to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run.
Deploying a Potato family exploit such as PrintSpoofer or GodPotato to capture and impersonate a SYSTEM token.
A Windows service is configured with the binary path C:\Program Files\Network Monitor\netmon.exe without enclosing quotation marks. If an unprivileged user has write permissions to C:\, which binary name will the Windows Service Control Manager attempt to execute first upon service startup?
C:\Program.exe
C:\Program Files\Network.exe
C:\Program Files\Network Monitor\netmon.exe
C:\netmon.exe
Which Windows command-line utility and query accurately retrieves a list of installed security hotfixes along with their specific Knowledge Base (KB) identifiers and installation dates?
net config server /all
sc query type= driver
wmic qfe get Caption,Description,HotFixID,InstalledOn
tasklist /svc /fi "STATUS eq RUNNING"
Sections you finish are checked off in the contents.