During an authorized penetration test, a tester obtains a low-privilege shell on a Windows server and wants to identify missing patches and insecure configurations that a remote unauthenticated scan may have missed. Which action BEST supports this goal?
Local enumeration tools like WinPEAS and Seatbelt run from the compromised host and collect patch levels, missing updates, weak service permissions, saved credentials, and misconfigurations that remote scans often miss. Because the tester already has a shell, this approach directly answers the goal of finding local vulnerabilities without needing additional credentials or scanner access.
Why this answer
After gaining a foothold, a penetration tester should perform local enumeration to find patch gaps and misconfigurations that remote scanning cannot see. WinPEAS and Seatbelt are purpose-built for this, collecting system, patch, and configuration data directly from the host. The other options either require additional credentials, focus on network discovery, or capture traffic without addressing local vulnerability state.
Exam trap
The trap here is confusing remote vulnerability scanning with local post-exploitation enumeration, and assuming that any network-based technique will reveal host patch levels once a shell is obtained.