WinPEAS is a Windows-focused post-exploitation enumeration tool from the PEASS-ng project used to identify privilege-escalation paths, credential exposure, and other security weaknesses on compromised hosts. It is widely used by penetration testers and red teams, but is also regularly observed in real intrusions and ransomware operations as an operator-assisted utility rather than as a self-propagating payload.
Its behavior centers on local discovery and credential-access-oriented reconnaissance. Reported use cases include querying registry locations associated with cached domain credential settings and credentials stored in the registry, enumerating user sessions through native utilities such as quser, listing Kerberos ticket information through klist, gathering network configuration details such as DNS cache contents, and searching for private keys and certificate-related material that could enable further access. It has also been associated with registry save and restore operations and with privilege-escalation workflows during hands-on-keyboard activity.
WinPEAS targets Windows systems and is typically executed after initial compromise as part of broader intrusion activity. It has been referenced in operations involving Russian SVR actors exploiting TeamCity and in reporting on Play ransomware tradecraft, where it appeared alongside other dual-use tools used for credential theft, privilege escalation, lateral movement, and data exfiltration. The tool is best characterized as a post-exploitation reconnaissance and privilege-escalation aid for Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“To facilitate privilege escalation … the SVR used multiple techniques, including WinPEAS…”
“To facilitate privilege escalation … the SVR used multiple techniques, including WinPEAS…”
By abusing legitimate tools such as Cobalt Strike, Mimikatz, ProcDump, AdFind, and WinPEAS, the group conducts credential theft, privilege escalation, lateral movement, and data exfiltration.
This activity is significant as it may indicate credential theft attempts, often used by adversaries or post-exploitation tools like winPEAS.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Повышение привилегий Privilege Escalation Exploitation for Privilege Escalation (T1068), Valid Accounts (T1078) LinPEAS, WinPEAS, ручной анализ
The following analytic identifies a process command line querying the CachedLogonsCount registry value in the Winlogon registry.
The following analytic identifies processes querying the registry for potential passwords or credentials... command-line executions that access specific registry paths known to store sensitive information. This activity is significant as it may indicate credential theft attempts... Annotations ID Technique Tactic T1552.002 Credentials in Registry Credential Access
Annotations ID Technique Tactic T1007 System Service Discovery Discovery
Annotations ID Technique Tactic T1016 System Network Configuration Discovery Discovery
Annotations ID Technique Tactic T1033 System Owner/User Discovery Discovery
Adding attack.discovery since rule already have t1082, t1087 and t1046
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows post-exploitation enumeration tool referenced here as using reg save and reg restore to manipulate registry settings during attacker activity.
A post-exploitation enumeration tool used to discover sensitive information on Windows systems, including insecurely stored private keys and credentials that could support privilege escalation, persistence, or remote authentication.
A Windows post-exploitation enumeration tool that can invoke native utilities like klist.exe to gather Kerberos ticket information useful for lateral movement or privilege escalation.
A post-exploitation enumeration tool that can abuse quser.exe to gather user session information on Windows systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.