access-tokens.md (12500B)
1 --- 2 title: "Access Tokens" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/access-tokens.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/access-tokens.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Access Tokens 14 15 ## Access Tokens 16 17 Each **user logged** onto the system **holds an access token with security information** for that logon session. The system creates an access token when the user logs on. **Every process executed** on behalf of the user **has a copy of the access token**. The token identifies the user, the user's groups, and the user's privileges. A token also contains a logon SID (Security Identifier) that identifies the current logon session. 18 19 You can see this information executing `whoami /all` 20 21 ```text 22 whoami /all 23 24 USER INFORMATION 25 ---------------- 26 27 User Name SID 28 ===================== ============================================ 29 desktop-rgfrdxl\cpolo S-1-5-21-3359511372-53430657-2078432294-1001 30 31 32 GROUP INFORMATION 33 ----------------- 34 35 Group Name Type SID Attributes 36 ============================================================= ================ ============================================================================================================= ================================================== 37 Mandatory Label\Medium Mandatory Level Label S-1-16-8192 38 Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group 39 NT AUTHORITY\Local account and member of Administrators group Well-known group S-1-5-114 Group used for deny only 40 BUILTIN\Administrators Alias S-1-5-32-544 Group used for deny only 41 BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group 42 BUILTIN\Performance Log Users Alias S-1-5-32-559 Mandatory group, Enabled by default, Enabled group 43 NT AUTHORITY\INTERACTIVE Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group 44 CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group 45 NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group 46 NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group 47 MicrosoftAccount\cpolop@outlook.com User S-1-11-96-3623454863-58364-18864-2661722203-1597581903-3158937479-2778085403-3651782251-2842230462-2314292098 Mandatory group, Enabled by default, Enabled group 48 NT AUTHORITY\Local account Well-known group S-1-5-113 Mandatory group, Enabled by default, Enabled group 49 LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group 50 NT AUTHORITY\Cloud Account Authentication Well-known group S-1-5-64-36 Mandatory group, Enabled by default, Enabled group 51 52 53 PRIVILEGES INFORMATION 54 ---------------------- 55 56 Privilege Name Description State 57 ============================= ==================================== ======== 58 SeShutdownPrivilege Shut down the system Disabled 59 SeChangeNotifyPrivilege Bypass traverse checking Enabled 60 SeUndockPrivilege Remove computer from docking station Disabled 61 SeIncreaseWorkingSetPrivilege Increase a process working set Disabled 62 SeTimeZonePrivilege Change the time zone Disabled 63 ``` 64 65 or using _Process Explorer_ from Sysinternals (select process and access"Security" tab): 66 67  68 69 ### Local administrator 70 71 When a local administrator logins, **two access tokens are created**: One with admin rights and other one with normal rights. **By default**, when this user executes a process the one with **regular** (non-administrator) **rights is used**. When this user tries to **execute** anything **as administrator** ("Run as Administrator" for example) the **UAC** will be used to ask for permission.\ 72 If you want to [**learn more about the UAC read this page**](../authentication-credentials-uac-and-efs/index.html#uac)**.** 73 74 In practice, this means a **non-elevated admin shell usually runs with a filtered token**. That is why `whoami /groups` often shows **`BUILTIN\Administrators` as `Deny only`** until the process is elevated. Internally, Windows keeps a **linked elevated token** (`TokenLinkedToken`) and tracks the state with fields such as `TokenElevationType`. 75 76 ### Credentials user impersonation 77 78 If you have **valid credentials of any other user**, you can **create** a **new logon session** with those credentials : 79 80 ```text 81 runas /user:domain\username cmd.exe 82 ``` 83 84 The **access token** has also a **reference** of the logon sessions inside the **LSASS**, this is useful if the process needs to access some objects of the network.\ 85 You can launch a process that **uses different credentials for accessing network services** using: 86 87 ```text 88 runas /user:domain\username /netonly cmd.exe 89 ``` 90 91 This is useful if you have useful credentials to access objects in the network but those credentials aren't valid inside the current host as they are only going to be used in the network (in the current host your current user privileges will be used). 92 93 #### `runas /netonly` details 94 95 `runas /netonly` (and C2 helpers such as `make_token`) creates a **`LOGON32_LOGON_NEW_CREDENTIALS`** token. This is very useful to understand during lateral movement because:<sup>[[3]](#references)</sup> 96 97 - **Locally**, the new process keeps the **same local identity**, groups, integrity level, and most of the same access decisions as the current token. 98 - **Remotely**, outbound authentication can use the **supplied credentials** for SMB / WinRM / LDAP / HTTP / Kerberos / NTLM. 99 - Therefore `whoami` may still show the **original local user** while network access happens as the **alternate account**. 100 101 This is a great option when the credentials are valid in the domain or in another host, but the user **cannot or should not log on locally** to the current machine. 102 103 ### Types of tokens 104 105 There are two types of tokens available: 106 107 - **Primary Token**: It serves as a representation of a process's security credentials. The creation and association of primary tokens with processes are actions that require elevated privileges, emphasizing the principle of privilege separation. Typically, an authentication service is responsible for token creation, while a logon service handles its association with the user's operating system shell. It is worth noting that processes inherit the primary token of their parent process at creation. 108 - **Impersonation Token**: Empowers a server application to adopt the client's identity temporarily for accessing secure objects. This mechanism is stratified into four levels of operation: 109 - **Anonymous**: Grants server access akin to that of an unidentified user. 110 - **Identification**: Allows the server to verify the client's identity without utilizing it for object access. 111 - **Impersonation**: Enables the server to operate under the client's identity. 112 - **Delegation**: Similar to Impersonation but includes the ability to extend this identity assumption to remote systems the server interacts with, ensuring credential preservation. 113 114 #### Impersonate Tokens 115 116 Using the _**incognito**_ module of metasploit if you have enough privileges you can easily **list** and **impersonate** other **tokens**. This could be useful to perform **actions as if you where the other user**. You could also **escalate privileges** with this technique. 117 118 Some practical notes that are easy to forget while operating:<sup>[[1]](#references)</sup> 119 120 - **`CreateProcessWithTokenW`** requires **`SeImpersonatePrivilege`** in the caller and the new process will run in the **caller's session**. 121 - **`CreateProcessAsUserW`** is the usual fallback when `CreateProcessWithTokenW` fails with `1314`, or when you need to launch in the **session referenced by the token**. 122 - If a token comes from **`LogonUser(LOGON32_LOGON_NETWORK)`**, it is usually an **impersonation token**, so you need **`DuplicateTokenEx(..., TokenPrimary, ...)`** before trying to spawn a process with it. 123 - Not every impersonation token is equally useful: **`SecurityIdentification`** lets you inspect the user but **not act as them**. If a coercion primitive or pipe/RPC client gives you only an identification-level token, check **`TokenImpersonationLevel`** and switch to a primitive that yields **`SecurityImpersonation`** or better. 124 125 #### Token theft without touching LSASS 126 127 If you already have a **service** or **SYSTEM** context and a **privileged user is logged on**, stealing or duplicating that user's token is often quieter than dumping **LSASS**. In many real intrusions this is enough to:<sup>[[2]](#references)</sup> 128 129 - run local actions as that user 130 - access remote resources as that user 131 - perform AD operations without extracting reusable credentials first 132 133 For examples of **session/user token hijacking** from a privileged context, check [**WTS Impersonator**](/hacktricks/windows-hardening/stealing-credentials/wts-impersonator). Remember that APIs such as **`WTSQueryUserToken`** are meant for **highly trusted services** and normally require **`LocalSystem` + `SeTcbPrivilege`**, so they are primarily useful once you already control a service-level context. For privilege-specific ways to obtain **SYSTEM** first, check the pages below. 134 135 ### Token Privileges 136 137 Learn which **token privileges can be abused to escalate privileges:** 138 139 140 [Privilege Escalation Abusing Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens) 141 142 Take a look to [**all the possible token privileges and some definitions on this external page**](https://github.com/gtworek/Priv2Admin). 143 144 ## References 145 146 - [1] [Understanding and Abusing Access Tokens — Part II](https://medium.com/@seemant.bisht24/understanding-and-abusing-access-tokens-part-ii-b9069f432962) 147 - [2] [Abusing Windows' tokens to compromise Active Directory without touching LSASS](https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/) 148 - [3] [Demystifying Cobalt Strike's "make_token" Command](https://www.fox-it.com/nl-en/demystifying-cobalt-strike-s-make_token-command/)