InfoSec_Notes

PXE Boot

[Image of process]

Risks

Exploiting the PXE boot images can lead to:

BCD (.bcd) files store relevant information to PXE boots for different types of architecture - use TFTP (not like FTP, needs specific file name and details to transfer the file using UDP, no way of fetch file lists) to request each BCD files and enumerate the configs. WIM files

[]More insight](https://www.riskinsight-wavestone.com/en/2020/01/taking-over-windows-workstations-pxe-laps/)

Tools