Advice Request Anyone use(d) nsudo?

Please provide comments and solutions that are helpful to the author of this topic.
Status
Not open for further replies.

ParaXY

Level 6
Thread author
Verified
Mar 14, 2017
273
482
467
CI
I came across this utility last night called nsudu. Basically it grants you TrustedInstaller/System rights for any program you want to run.

To test it I ran it in a VM and then ran regedit as TrustedInstaller rights and in Task Manager it showed me as having SYSTEM rights. This allowed me to delete a registry key that normally would require me to take ownership of the key before deleting.

Uploading the x64 verion to VirusTotal comes back as clean but I'm curious if anyone else has used this as it seems like it could be useful...if used with caution.
 
  • Like
Reactions: tonibalas
Heard about that today only.

Do I really need that? First if Windows have a way for taking ownership, I'll learn and use that first before diving in to some 3rd party stuff. Used this technique before when removing Registry Keys added by TrustedInstaller (Andromeda worm) ages ago.

Right click on a key and click Permissions...

Then check on Full Control

Untitled.png.jpg
 
I wonder if you can make this work on a SUA without knowing any Admin password?
 
Not sure. I can't run it on my machine as an SUA as I have AppLocker blocking it.
 
  • Like
Reactions: WinXPert
I wonder if you can make this work on a SUA without knowing any Admin password?
You can't , SUA block registry tweaks that modify the system but not some that affect the user only.
 
Status
Not open for further replies.

You may also like...