# Priv Esc (Windows)

```powerquery
USER INFORMATION
----------------

User Name        SID                                           
================ ==============================================
hospital\drbrown S-1-5-21-4208260710-2273545631-1523135639-1601


GROUP INFORMATION
-----------------

Group Name                                  Type             SID          Attributes                                        
=========================================== ================ ============ ==================================================
Everyone                                    Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
BUILTIN\Users                               Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Desktop Users                Alias            S-1-5-32-555 Mandatory group, Enabled by default, Enabled group
BUILTIN\Performance Log Users               Alias            S-1-5-32-559 Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Management Users             Alias            S-1-5-32-580 Mandatory group, Enabled by default, Enabled group
BUILTIN\Pre-Windows 2000 Compatible Access  Alias            S-1-5-32-554 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NETWORK                        Well-known group S-1-5-2      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users            Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization              Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group
Authentication authority asserted identity  Well-known group S-1-18-1     Mandatory group, Enabled by default, Enabled group
Mandatory Label\Medium Plus Mandatory Level Label            S-1-16-8448                                                    


PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State  
============================= ============================== =======
SeMachineAccountPrivilege     Add workstations to domain     Enabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
```

<figure><img src="https://2227792809-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLw94TQyn4rROgGvJT1nC%2Fuploads%2F6xiJMaCFW7tjJ016lbAJ%2Fimage.png?alt=media&#x26;token=11e2e24b-07b1-4ea6-a695-8c97a4b713cb" alt=""><figcaption></figcaption></figure>

## Unintended Route

Admin creds for webmail were automatically being typed into browser via script; opened notepad to get them

<figure><img src="https://2227792809-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLw94TQyn4rROgGvJT1nC%2Fuploads%2F99dBPRlNy3YZg1j3sNDC%2Fimage.png?alt=media&#x26;token=517946ec-fe82-4c74-b9be-412df8d5d566" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2227792809-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLw94TQyn4rROgGvJT1nC%2Fuploads%2FsMGR51eHJBdGuaRAFRx1%2Fimage.png?alt=media&#x26;token=bbca0331-bee8-4436-9cec-eff2f729b186" alt=""><figcaption></figcaption></figure>
