Some news about PrivescCheck! 📰
If you are a Metasploit user, please note that I finally solved a (stupid) issue that prevented the script from working properly with "powershell_execute". 🥳
More info on GitHub.
👉 github.com/itm4n/PrivescC…
👉 github.com/itm4n/PrivescC…
I revisited the Credential Guard bypass originally discussed by @N4k3dTurtl3.
Have a nice reading! 🙂
👉 itm4n.github.io/credential-gua…
TL;DR It is possible to get rid of hardcoded offsets...
Windows Defender AV allows Everyone to read the configured exclusions on the system 🤦
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s