INTERMEDIATE TO ADVANCED
⏱ 4 WEEKS
20 MODULES
Windows Privilege Escalation
Turn a low-privilege foothold into SYSTEM
A foothold is not a compromise. On real engagements the gap between an initial low-privilege shell and meaningful impact is almost always a Windows escalation path, and finding it reliably is what separates a useful report from a thin one. This course works through every major vector, but the emphasis is on enumeration first: understanding why a misconfiguration is exploitable rather than running a tool that flags it.
✓
Instructor credential: I hold this credential myself, completed through TCM Security in June 2026 as part of the PNPT path, and the same techniques appear in my client engagements.
👤Who this is for
- →Penetration testers who keep getting a shell and then stalling
- →PNPT or OSCP candidates who find escalation the weakest part of their methodology
- →Red teamers who need reliable escalation that survives contact with EDR
- →Defenders who want to know exactly what telemetry to hunt for
⚡Prerequisites
•Working knowledge of Windows administration
•Comfortable getting an initial shell on a target
•Basic PowerShell familiarity
Curriculum
8 units · 32 topics · 4 weeks
UNIT 01
Enumeration first
✦Manual enumeration before tooling
✦WinPEAS and PowerUp output triage
✦Reading a system for escalation potential
✦Prioritising vectors by reliability
UNIT 02
Service and path abuse
✦Insecure service permissions
✦Unquoted service paths
✦Weak registry permissions
✦DLL hijacking opportunities
UNIT 03
Registry-based escalation
✦AlwaysInstallElevated
✦AutoRuns abuse
✦Stored credentials in the registry
✦Scheduled task and startup abuse
UNIT 04
Token and privilege abuse
✦SeImpersonatePrivilege and the Potato family
✦Juicy, Sweet, and Rogue Potato in practice
✦Token theft and impersonation
✦Named pipe attacks
UNIT 05
Credentials and lateral reuse
✦SAM and SYSTEM hive extraction
✦Pass-the-Hash
✦Credential reuse across hosts
✦Harvesting from memory and config files
UNIT 06
Kernel exploits
✦Identifying missing patches with Watson
✦Kernel exploit selection criteria
✦Compiling and running kernel exploits
✦Understanding exploit reliability and stability
UNIT 07
UAC and modern defences
✦UAC bypass techniques
✦EDR-aware considerations
✦Detection footprint of each vector
✦Building escalation into a full engagement
UNIT 08
Capstone labs
✦Multi-vector escalation chains
✦Realistic enterprise environment labs
✦Time-boxed escalation challenges
✦Documenting escalation paths for reports