Windows Privilege Escalation Cheatsheet

A practical, ordered checklist for Windows local privilege escalation during labs, CTFs, and authorised internal testing.

May 26, 2026 · 12 min

VulnLab: Breach

Active Directory machine demonstrating NTLM hash capture through a writable SMB share, Kerberoasting, MSSQL Silver Ticket abuse, and SeImpersonatePrivilege escalation.

March 23, 2026 · 7 min

VulnLab: Baby2

Active Directory machine demonstrating SMB user enumeration, weak password reuse, writable logon script abuse, and GPO-based privilege escalation.

March 22, 2026 · 8 min

VulnLab: Baby

Active Directory machine demonstrating anonymous LDAP enumeration, password reset abuse, SeRestorePrivilege execution, and manual NTDS extraction.

March 21, 2026 · 6 min

HTB: Access

Windows machine demonstrating anonymous FTP exposure, credential recovery from MDB and PST files, Telnet access, and stored credential abuse.

March 7, 2026 · 5 min

HTB: Buff

Windows machine demonstrating unauthenticated file upload leading to CloudMe buffer overflow exploitation and administrator access.

March 5, 2026 · 5 min

HTB: Arctic

Windows machine demonstrating Adobe ColdFusion remote code execution and kernel-based privilege escalation to SYSTEM.

March 2, 2026 · 4 min

HTB: Bounty

Windows machine demonstrating IIS upload bypass with web.config abuse and kernel exploit privilege escalation.

March 1, 2026 · 5 min

HTB: Escape

Active Directory machine demonstrating MSSQL abuse leading to credential leakage and AD CS certificate abuse for full domain compromise.

November 9, 2025 · 7 min

HTB: Cicada

Active Directory machine demonstrating exposed SMB data, credential reuse, and Backup Operators abuse to dump domain hashes.

November 7, 2025 · 6 min