There are several tools we can use to automate discovery. These can be in several formats such as **executables** (.exe), **PowerShell scripts** (.ps), **C# solutions** (.sln), and even python scripts. 1. Executables - [winPEAS.exe](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS) - [Sealbelt.exe](https://github.com/GhostPack/Seatbelt) - [Watson.exe](https://github.com/rasta-mouse/Watson) - [SharpUp.exe](https://github.com/GhostPack/SharpUp) 2. PowerShell - [Sherlock.ps1](https://github.com/rasta-mouse/Sherlock) - [PowerUp.ps1](https://github.com/PowerShellMafia/PowerSploit/tree/master/Privesc) - [jaws-enum.ps1](https://github.com/411Hall/JAWS) 3. Other - [windows-exploit-suggester.py](https://github.com/AonCyberLabs/Windows-Exploit-Suggester) (EoL since Python2 is no longer supported) - [wesng](https://github.com/bitsadmin/wesng) (Updated wes for python3) - [Exploit Suggester](https://blog.rapid7.com/2015/08/11/metasploit-local-exploit-suggester-do-less-get-more/) (Metasploit) Since automated tools need some pre-requisites to run, some might not run on every machine. Hence, it is always better to try a few of them without sticking to one or two.