Skip to main content
INTERMEDIATE TO ADVANCED
4 WEEKS
20 MODULES

Windows Privilege Escalation

Turn a low-privilege foothold into SYSTEM

A foothold is not a compromise. On real engagements the gap between an initial low-privilege shell and meaningful impact is almost always a Windows escalation path, and finding it reliably is what separates a useful report from a thin one. This course works through every major vector, but the emphasis is on enumeration first: understanding why a misconfiguration is exploitable rather than running a tool that flags it.

Instructor credential: I hold this credential myself, completed through TCM Security in June 2026 as part of the PNPT path, and the same techniques appear in my client engagements.

📦
20
Modules
4
weeks
📋
8
Units
🎯
32
Topics

👤Who this is for

  • Penetration testers who keep getting a shell and then stalling
  • PNPT or OSCP candidates who find escalation the weakest part of their methodology
  • Red teamers who need reliable escalation that survives contact with EDR
  • Defenders who want to know exactly what telemetry to hunt for

Prerequisites

Working knowledge of Windows administration
Comfortable getting an initial shell on a target
Basic PowerShell familiarity

Curriculum

8 units · 32 topics · 4 weeks

UNIT 01

Enumeration first

Manual enumeration before tooling
WinPEAS and PowerUp output triage
Reading a system for escalation potential
Prioritising vectors by reliability
UNIT 02

Service and path abuse

Insecure service permissions
Unquoted service paths
Weak registry permissions
DLL hijacking opportunities
UNIT 03

Registry-based escalation

AlwaysInstallElevated
AutoRuns abuse
Stored credentials in the registry
Scheduled task and startup abuse
UNIT 04

Token and privilege abuse

SeImpersonatePrivilege and the Potato family
Juicy, Sweet, and Rogue Potato in practice
Token theft and impersonation
Named pipe attacks
UNIT 05

Credentials and lateral reuse

SAM and SYSTEM hive extraction
Pass-the-Hash
Credential reuse across hosts
Harvesting from memory and config files
UNIT 06

Kernel exploits

Identifying missing patches with Watson
Kernel exploit selection criteria
Compiling and running kernel exploits
Understanding exploit reliability and stability
UNIT 07

UAC and modern defences

UAC bypass techniques
EDR-aware considerations
Detection footprint of each vector
Building escalation into a full engagement
UNIT 08

Capstone labs

Multi-vector escalation chains
Realistic enterprise environment labs
Time-boxed escalation challenges
Documenting escalation paths for reports

What you will be able to do

1Enumerate and exploit every major Windows escalation vector
2Chain a low-privilege foothold to SYSTEM in realistic environments
3Explain why each misconfiguration is exploitable, not just that it is
4Apply escalation reliably inside PNPT, OSCP, and real client engagements

🛠 Tools you will use

WinPEASPowerUpBeRootMetasploitPowerShellWindows APISysinternals

🏆 Certification pathways

This course builds directly toward:

PNPTOSCPCRTO

Frequently asked questions

How is this different from a general ethical hacking course?

It covers one phase of an engagement in depth rather than the whole lifecycle at surface level. General courses give privilege escalation a module or two. Here it is the entire syllabus, which is proportionate to how often escalation is the thing that actually blocks a test from producing meaningful impact.

What is SeImpersonatePrivilege and why does it matter so much?

It is a Windows privilege that lets a process impersonate the security context of a client connecting to it. Service accounts frequently hold it, and it enables the Potato family of attacks to escalate straight to SYSTEM. It comes up constantly in real engagements, which is why the course spends a full unit on it from both the attacker and the detection side.

Will these techniques work against modern EDR?

Some will, some will not, and the course is explicit about which. Detection footprint is covered alongside each vector, because knowing that a technique works in a lab but lights up an EDR in production is exactly the knowledge that distinguishes a professional from a script runner.

Do I need to know Linux privilege escalation first?

No, they are independent skill sets. However, many of the enumeration principles transfer between operating systems. If you have done Linux PrivEsc, the methodology of checking misconfigurations systematically will feel familiar even though the specific vectors are entirely different.

Is this course available for corporate teams?

Yes. Group rates are available and the course can be scoped to focus on the escalation vectors most relevant to your environment. Contact directly to discuss team enrolment and scheduling.

How current are the techniques taught?

The course covers both classic vectors that appear in the majority of real engagements and modern techniques including EDR-aware escalation paths. Techniques are tested against current Windows versions and the detection footprint of each is discussed so you understand what still works and what gets flagged.

Interested in this training?

Reach out to discuss scheduling, format, and pricing. Corporate and group rates available.

Get in touch →View all courses

Other courses