One Day Sec

What are the prerequisites and common methods to escalate from Administrator to SYSTEM privileges in Windows?

The prerequisite is having administrator privileges on the system. Common methods include creating a service using `sc`, `schtasks`, or `psexec`, exploiting MSIExec with custom `.msi` files, duplicating a SYSTEM token with tools like `incognito` or `Invoke-TokenManipulation`, or leveraging vulnerable drivers like `Capcom.sys`. Each method has specific OS compatibility and detection considerations. For more details, refer to Penetration Techniques - Switching from Admin Privileges to System Privileges.
privilege escalationSYSTEM privilegesservice creationtoken duplicationCapcom.sys

Browse all Q&A →