Windows Privilege Escalation Cheatsheet

A practical, ordered checklist for Windows local privilege escalation during labs, CTFs, and authorised internal testing.

May 26, 2026 · 12 min

VulnLab: Breach

Active Directory machine demonstrating NTLM hash capture through a writable SMB share, Kerberoasting, MSSQL Silver Ticket abuse, and SeImpersonatePrivilege escalation.

March 23, 2026 · 7 min

HTB: Flight

Active Directory machine demonstrating NTLM hash capture, SMB abuse, password reuse, IIS pivoting, and SeImpersonatePrivilege escalation.

November 1, 2025 · 9 min

VulnLab: Job

Windows machine demonstrating phishing through a malicious LibreOffice document, IIS web root abuse, SeImpersonatePrivilege, and local administrator access through GodPotato and RunasCs.

October 13, 2025 · 6 min