Internal Audit - Plan

Great One

Network discovery

Scanning

Windows AD

Check this

If you have no credentials

Kerberos

If you have credentials

Dumps secrets

Local Privilege Escalation

Juicy Potato

Abuse SeImpersonate or SeAssignPrimaryToken Privileges for System Impersonation

Works only until Windows Server 2016 and Windows 10 until patch 1803.

PrintSpoofer

Exploit the PrinterBug for System Impersonation

Works for Windows Server 2019 and Windows 10.

RoguePotato

From Service Account to System

Works for Windows Server 2019 and Windows 10.

Abusing Token Privileges

SMBGhost CVE-2020–0796

CVE-2021–36934 (HiveNightmare/SeriousSAM)

Linux

Lynis

Lynis is a battle-tested security tool for systems running Linux, macOS, or Unix-based operating system. It performs an extensive health scan of your systems to support system hardening and compliance testing.

In order to install Lynis on your system, you must follow these steps :

Last updated

Was this helpful?