# No Admin?

* Do you have any access to file shares?
* wwwroot: drop a web shell
* web.config: access to cleartext creds
* backdooring any files with your payload
* Pivot through SQL server with your current credentials or with any SQL scripts you have found
* Internal spear phishing
* Pivot to web and cloud services and try to escalate privileges from there(Azure, exchange etc.)
* Search for any low hanging VNC creds or SSH keys/passwords


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://kwcsec.gitbook.io/the-red-team-handbook/techniques/lateral-movement/no-admin.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
