Windows Privilege Escalation Cheatsheet

A practical, ordered checklist for Windows local privilege escalation during labs, CTFs, and authorised internal testing.

May 26, 2026 · 12 min

VulnLab: Baby2

Active Directory machine demonstrating SMB user enumeration, weak password reuse, writable logon script abuse, and GPO-based privilege escalation.

March 22, 2026 · 8 min

HTB: Escape

Active Directory machine demonstrating MSSQL abuse leading to credential leakage and AD CS certificate abuse for full domain compromise.

November 9, 2025 · 7 min

HTB: Forest

Active Directory machine demonstrating anonymous LDAP enumeration, AS-REP Roasting, nested group abuse, and DCSync-based domain compromise.

November 5, 2025 · 6 min

HTB: Sauna

Active Directory machine demonstrating username generation, AS-REP Roasting, AutoLogon credential discovery, and DCSync-based domain compromise.

October 27, 2025 · 5 min