Windows Privilege Escalation in an Authorized Lab: Testing Methodology

Windows Privilege Escalation must only be performed within an approved Scope and Rules of Engagement. The process includes information gathering, controlled verification, Evidence, risk assessment, remediation, and Retest.
Professional penetration testing is an authorized and defined process, not a collection of commands. Scope, Rules of Engagement, evidence, risk assessment, remediation, and Retest are integral parts of the work. This article focuses on Windows Privilege Escalation and is intended for PT students. The goal is to provide a working methodology that can be applied in practice, during a professional interview, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always partial. 4672 special privileges, group membership changes, service/task creation can point to a direction, but their meaning depends on the time, asset, user, and expected activity. Therefore, we will build the test around an investigative question, required evidence, and a clear criterion for completion.
The practical scenario in the article is: Assessment of a dedicated Windows machine in a lab. All examples are lab data or descriptions of processes. When it comes to Penetration Testing, Web, or Cloud, one must only work with explicit authorization, a defined Scope, and the ability to stop the test.




