๐พ Overview
Members of the Server Operators
group are able to modify services, this can be used to execute a malicious exe instead of a serviceโs normal binary.
๐ Discovery
This requires a user in the Server Operators
group.
๐ Exploitation
First youโll need to generate a payload to execute, ideally a beacon from Sliver, msfvenom, or another C2 framework.
Next, use PowerShell to edit an existing service to execute your beacon.
This should get a callback as NT AUTHORITY\SYSTEM
.
๐ Resources
๐ Hyperlink | โน๏ธ Info |
---|---|
Hacktricks | Privileged Groups Privesc |
HackingArticles | Server Operators Privesc |