Very interesting post by Microsoft about the internals of the new Admin Protection feature
It seems they have patched my SSPI UAC bypass based on NTLM as well as the Kerberos UAC bypass in which both were able to bypass AP as well
More details here 👇
Looks like this mitigation was added in 1803, build 17134.
It would be sad 😸 if someone would seamlessly 𝐛𝐫𝐞𝐚𝐤 𝐢𝐭 via user-writeable subkeys under the "\Registry\Machine".
Like, you know, HKLM\System\CurrentControlSet\Control\Nsi\{eb004a1c-9b1a-11d4-9123-0050047759bc}\0.
Ok, i think i understood why.
In newer ntoskrnl.exe there is a check in IopLoadDriver->IopBuildFullDriverPath->IopQueryRegistryKeySystemPath that ensure the "ImagePath" value is under a regkey prefixed with \REGISTRY\MACHINE and if not it returns 0xC00000E5
In older ntoskrnl the
There’s a popular Linux privilege escalation script (linpeas) that’s had a copycat create nefarious linpeas[.]sh.
Linpeas (a great tool) has 0 association with linpeas[.]sh (bad)
To all pentesters and cybersecurity folks who run tools and scripts as part of their job, be