User & Group Privileges — Quick Decision Guide¶
This is a quick reference page. For detailed exploitation steps, see the dedicated pages:
User Privileges¶
- SeImpersonate & Potato Attacks — GodPotato, PrintSpoofer, JuicyPotato, etc.
- SeDebug Privilege — LSASS dumping (procdump, comsvcs.dll, Mimikatz)
- SeBackup & SeRestore — SAM/ntds.dit extraction, arbitrary file write
- SeTakeOwnership & SeLoadDriver — File ownership takeover, Capcom.sys
Group Privileges¶
- Windows Group Privileges — DnsAdmins, Server Operators, Backup Operators, Print Operators, Hyper-V Admins, Event Log Readers
Step 1: Check Your Privileges and Groups¶
Step 2: Privilege Decision Tree¶
whoami /priv
│
┌──────────────┼──────────────────┐
│ │ │
SeImpersonate SeDebug SeTakeOwnership
│ │ │
▼ ▼ ▼
Use Potato Dump LSASS Take ownership
attacks (procdump, of SAM/ntds.dit
(GodPotato comsvcs.dll) then extract hashes
first) │ │
│ ▼ ▼
▼ Credentials File Access
SYSTEM
┌──────────────┼──────────────────┐
│ │ │
SeBackup SeRestore SeLoadDriver
│ │ │
▼ ▼ ▼
Copy any file Write any file Load vulnerable
(SAM, ntds.dit) (replace DLL, kernel driver
bypassing DACLs service binary) (Capcom.sys)
Step 3: Group Decision Tree¶
whoami /groups
│
┌───────────────────┼───────────────────┐
│ │ │
DnsAdmins Server Operators Backup Operators
│ │ │
▼ ▼ ▼
Config DNS Modify service reg save SAM
to load DLL binpath, then SYSTEM SECURITY
(UNC path), restart service + diskshadow
restart DNS → SYSTEM for ntds.dit
→ SYSTEM → all hashes
│
├───────────────────┼───────────────────┐
│ │ │
Print Operators Hyper-V Admins Event Log Readers
│ │ │
▼ ▼ ▼
SeLoadDriver Clone DC VHD, Search Event IDs
→ Capcom.sys mount offline, 4688 & 4104 for
→ kernel exec extract ntds.dit cleartext creds