Skip to main content

Methodology


Windows Exploit Suggester

Save systeminfo output from victim:
Run:
Filter critical only:

Watson (.NET — Run on Target)

Identifies missing KBs and suggests exploits. Requires .NET 4.5+.

Sherlock (PowerShell — Deprecated but Works)


Check Installed Patches

Compare against known exploit KBs.

Common Kernel Exploits

MS16-032 — Secondary Logon (Windows 7/8/10, Server 2008/2012)

Missing KB: KB3139914

MS15-051 — Win32k (Windows 7, Server 2008)

Missing KB: KB3045171

MS14-058 — TrackPopupMenu (Windows 7, Server 2008)

Missing KB: KB3000061

CVE-2021-1675 / CVE-2021-34527 — PrintNightmare

See dedicated PrintNightmare page.

CVE-2021-36934 — HiveNightmare / SeriousSAM

SAM/SYSTEM readable by non-admin due to shadow copy ACL. Check:
If BUILTIN\Users has read access:
Extract:

CVE-2023-28252 — CLFS Driver

Windows 10/11, Server 2022. CLFS kernel driver elevation.

Pre-compiled Exploits


Quick Reference