Run all checks from :

Unattended Windows Installations

Powershell History

Saved Windows Credentials

IIS Configuration

Retrieve Credentials from Software: PuTTY

Scheduled Tasks

AlwaysInstallElevated

Windows Services

Unquoted Service Paths

Insecure Service Permissions

Windows Privileges

Unpatched Software

Abusing SeLoadDriverPrivilege

Groups

Service Binary Hijacking

Useful Tools

cheat sheet

Initial Enumeration