Windows Group Privilege
Backup Operators
PS C:\> Import-Module .\SeBackupPrivilegeUtils.dll
PS C:\> Import-Module .\SeBackupPrivilegeCmdLets.dllPS C:\> whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ============================== ========
SeMachineAccountPrivilege Add workstations to domain Disabled
SeBackupPrivilege Back up files and directories Disabled
SeRestorePrivilege Restore files and directories Disabled
SeShutdownPrivilege Shut down the system Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set DisabledPS C:\htb> Get-SeBackupPrivilege
SeBackupPrivilege is disabledAttacking a Domain Controller - Copying NTDS.dit
Robocopy
another way
Event Log Readers
DnsAdmins
Leveraging DnsAdmins Access
Cleaning Up
Using Mimilib.dll
Creating a WPAD Record
Hyper-V Administrators
Print Operators
Alternate Exploitation - No GUI
Automating the Steps
Clean-up
Server Operators
Last updated