jinpwn.dev
Posts Archive Cheatsheets About

Type to search posts and cheatsheets.

Type to search posts and cheatsheets.

Posts Archive Cheatsheets About
All cheatsheets Windows Pentesting
  • Windows MOC
  • Recon & Enum
  • Local Enum
  • PrivEsc - Tokens & Privileges
  • PrivEsc - Services & Registry
  • PrivEsc - DLL & Unquoted Paths
  • PrivEsc - Credentials & Files
  • UAC Bypass
  • PrivEsc - Kernel & Exploits
  • LOLBAS
  • Defender & AMSI Evasion
  • Lateral Movement

Windows MOC

Sections Windows MOC
  • All cheatsheets
  • Windows MOC
  • Recon & Enum
  • Local Enum
  • PrivEsc - Tokens & Privileges
  • PrivEsc - Services & Registry
  • PrivEsc - DLL & Unquoted Paths
  • PrivEsc - Credentials & Files
  • UAC Bypass
  • PrivEsc - Kernel & Exploits
  • LOLBAS
  • Defender & AMSI Evasion
  • Lateral Movement

Local Windows host work. Domain attacks live in AD MOC .

Enumerate #

  • Recon & Enum
  • Local Enum

Escalate #

  • PrivEsc - Tokens & Privileges
  • PrivEsc - Services & Registry
  • PrivEsc - DLL & Unquoted Paths
  • PrivEsc - Credentials & Files
  • UAC Bypass
  • PrivEsc - Kernel & Exploits

Living off the land #

  • LOLBAS
  • Defender & AMSI Evasion

Move #

  • Lateral Movement then AD MOC
Scope

If the host is domain joined, local privesc is often just the step before AD MOC . Loot creds, then pivot to the domain.

Next Recon & Enum

© 2026 JinPwn