UAC Bypass
User Account Control
Enumeration
Check current token privileges and UAC settings with Seatbelt:
PS > .\Seatbelt.exe TokenPrivileges UACSystemPropertiesAdvanced.exe
srrstr.dll DLL hijacking.
Upload srrstr.dll to C:\Users\%USERNAME%\AppData\Local\Microsoft\WindowsApps\ and check it:
Exec and get a shell ("requires an interactive window station"):
cmstp.exe
Compile from source, load and execute:
Load from a weaponized PowerShell and execute:
easinvoker.exe
fodhelper.exe
SilentCleanup
SCM UAC Bypass
Task Scheduler
Tricks
Bypass UAC for file read/write:
Last updated