KillaBoi/BrokenPipe ? reverse-engineered prompt

Reverse engineered prompt

Build me a single PowerShell script that demonstrates the Steam Client Service local privilege escalation on a Windows 10 or 11 x64 machine I own or have permission to test.

I want it to run from a standard user account, start Steam if needed, talk to the Steam Client Service, and launch a chosen payload as NT AUTHORITY SYSTEM without any UAC prompt. By default it should use cmd.exe so I can clearly see the SYSTEM shell, but I also want to be able to point it at my own executable and pass arguments.

Keep it as one self contained script with no build step and no extra binaries, since this should be easy to run with Windows PowerShell 5.1. If you need to check current docs or the Steam service behavior, look them up online first. Also make it clear when the proof has succeeded, ideally by showing the launched process and a simple whoami check.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab