These permission allow full read (SeBackup) and write (SeRestore) access to any file. The first of these allows for exfiltration, while the second allows binaries to be replaced at will (combine with service- or task-based attacks!). The “Backup Operators” group has both of these permissions!
Backup useful registry hives:
Run a local SMB server with Impacket:
Then, just use copy on Windows:
Use Impacket to dump hashes from a hive and perform a pass-the-hash attack: