Windows Attacks and Enumerations
Kerberos Attacks
Kerberoasting Kerberoasting is an attack against service accounts that allows an attacker to perf...
Recon
Windows recon Some commands are meant to be executed from a Sliver beacon but can easily be used ...
Windows Local Privilege Escalation
SeDebugPrivilege Migrate PID to privileged process such as WinLogon using ProcessInjection to loa...
Defense Evasion
Defense Evasion Useful Links Win32 API docs NTAPI Undocumented Functions Kernel-specific st...
Persistence
Persistence on Windows The commands that include execute-assembly have been executed from a Slive...
Miscellaneous
User SID and RID In Active Directory, any group or user that Windows doesn't create has a RID of ...