WinPEAS

Windows privilege-escalation auditing tool.

Windowslow

pkg: peass-ng

WinPEAS enumerates a Windows host for privesc — services, tokens, creds, unquoted paths — with risk highlighting.

Syntax

winpeas.exe

Example

winpeasx64.exe

Scans the host and highlights likely privilege-escalation routes.

Advantages
  • Thorough Windows privesc checks
  • Highlights wins
Disadvantages
  • AV may flag it
  • Verbose
Tags
#privesc#windows#post-ex

Official docs: PEASS-ng

Related commands

Frequently asked questions

What is WinPEAS used for?
WinPEAS enumerates a Windows host for privesc — services, tokens, creds, unquoted paths — with risk highlighting.
What is an example WinPEAS command?
A common example is: winpeasx64.exe — Scans the host and highlights likely privilege-escalation routes.
Is WinPEAS part of a standard install?
WinPEAS runs on Windows. Install the peass-ng package.
What category of security tool is WinPEAS?
WinPEAS is a Vulnerability Analysis tool with a low-risk profile when run against a live target.

Try recon tools live

Run real scans against a domain you control, stage by stage.

Open the lab →