discovered 03 Aug 2026
DeadPotato
→ View on GitHubDeadPotato is a privilege escalation tool designed to exploit the DCOM RPCSS vulnerability to gain NT AUTHORITY\SYSTEM level access on Windows systems. Its primary use case includes executing commands, creating new administrator accounts, establishing reverse shells, and dumping sensitive credentials using various modules like `-cmd`, `-newadmin`, and `-mimi`. Notable features include the ability to disable Windows Defender and collect domain data for BloodHound, making it versatile for penetration testing and security assessments.