September 2018
Intermediate to advanced
480 pages
9h 45m
English
In this case, the bypassuac_eventvwr implant is used for escalating the privileges from ring 3 (user land privs) to SYSTEM. To use an implant, you can execute the following command:
use implant/elevate/bypassuac_eventvwr
The option is changed from stager to the implant now and just like we did it when configuring the stager, we need to configure the implant before executing it.
We can find the options by executing the following command:
Info

This will show two options that need to be configured for a successful implant execution: PAYLOAD and ZOMBIE. To set up the payload, execute the following command:
set payload 0