Server Operators
Last updated
Last updated
Membership of this group confers the powerful SeBackupPrivilege and SeRestorePrivilege privileges and the ability to control local services.
We can use the service viewer/controller PsService, which is part of the Sysinternals suite, to check permissions on the service. PsService works much like the sc utility and can display service status and configurations and also allow you to start, stop, pause, resume, and restart services both locally and on remote hosts.
This confirms that the Server Operators group has SERVICE_ALL_ACCESS access right, which gives us full control over this service.
Now start the service and it will fail:
Check administrators group:
our account will be added.
Check admin privilege with nxc:
Get hashes: