Windows Privilege Escalation Cheatsheet

A practical, ordered checklist for Windows local privilege escalation during labs, CTFs, and authorised internal testing.

May 26, 2026 · 12 min

VulnLab: Job

Windows machine demonstrating phishing through a malicious LibreOffice document, IIS web root abuse, SeImpersonatePrivilege, and local administrator access through GodPotato and RunasCs.

October 13, 2025 · 6 min

VulnLab: Escape

Windows kiosk-style machine demonstrating RDP access, file-system browsing through Edge, binary restriction bypass via renaming, password recovery from Remote Desktop Plus, and GUI-based UAC elevation.

October 12, 2025 · 6 min