I just saw a custom #PAM that granted "temporary" administrator privileges by creating a local account. When revoking privileges, it relied on the #Windows task scheduler, which ran a script that deleted the account. So, after obtaining privileges, you could simply open the task scheduler as an administrator and disable the task that ran the script
paralhax@infosec.exchange
@paralhax@infosec.exchange
Posts
-
I just saw a custom #PAM that granted "temporary" administrator privileges by creating a local account.