Obtain NTLM hashes in Windows Domain Controller machines
Escalate privileges through insecure registry service permissions
Analyzing VBA Macros in Microsoft’s OLE2 files
Windows Privilege Escalation with SeImpersonatePrivilege, and SeAssignPrimaryTokenPrivilege