daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

access-tokens.md (12500B)


      1 ---
      2 title: "Access Tokens"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/access-tokens.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/access-tokens.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Access Tokens
     14 
     15 ## Access Tokens
     16 
     17 Each **user logged** onto the system **holds an access token with security information** for that logon session. The system creates an access token when the user logs on. **Every process executed** on behalf of the user **has a copy of the access token**. The token identifies the user, the user's groups, and the user's privileges. A token also contains a logon SID (Security Identifier) that identifies the current logon session.
     18 
     19 You can see this information executing `whoami /all`
     20 
     21 ```text
     22 whoami /all
     23 
     24 USER INFORMATION
     25 ----------------
     26 
     27 User Name             SID
     28 ===================== ============================================
     29 desktop-rgfrdxl\cpolo S-1-5-21-3359511372-53430657-2078432294-1001
     30 
     31 
     32 GROUP INFORMATION
     33 -----------------
     34 
     35 Group Name                                                    Type             SID                                                                                                           Attributes
     36 ============================================================= ================ ============================================================================================================= ==================================================
     37 Mandatory Label\Medium Mandatory Level                        Label            S-1-16-8192
     38 Everyone                                                      Well-known group S-1-1-0                                                                                                       Mandatory group, Enabled by default, Enabled group
     39 NT AUTHORITY\Local account and member of Administrators group Well-known group S-1-5-114                                                                                                     Group used for deny only
     40 BUILTIN\Administrators                                        Alias            S-1-5-32-544                                                                                                  Group used for deny only
     41 BUILTIN\Users                                                 Alias            S-1-5-32-545                                                                                                  Mandatory group, Enabled by default, Enabled group
     42 BUILTIN\Performance Log Users                                 Alias            S-1-5-32-559                                                                                                  Mandatory group, Enabled by default, Enabled group
     43 NT AUTHORITY\INTERACTIVE                                      Well-known group S-1-5-4                                                                                                       Mandatory group, Enabled by default, Enabled group
     44 CONSOLE LOGON                                                 Well-known group S-1-2-1                                                                                                       Mandatory group, Enabled by default, Enabled group
     45 NT AUTHORITY\Authenticated Users                              Well-known group S-1-5-11                                                                                                      Mandatory group, Enabled by default, Enabled group
     46 NT AUTHORITY\This Organization                                Well-known group S-1-5-15                                                                                                      Mandatory group, Enabled by default, Enabled group
     47 MicrosoftAccount\cpolop@outlook.com                           User             S-1-11-96-3623454863-58364-18864-2661722203-1597581903-3158937479-2778085403-3651782251-2842230462-2314292098 Mandatory group, Enabled by default, Enabled group
     48 NT AUTHORITY\Local account                                    Well-known group S-1-5-113                                                                                                     Mandatory group, Enabled by default, Enabled group
     49 LOCAL                                                         Well-known group S-1-2-0                                                                                                       Mandatory group, Enabled by default, Enabled group
     50 NT AUTHORITY\Cloud Account Authentication                     Well-known group S-1-5-64-36                                                                                                   Mandatory group, Enabled by default, Enabled group
     51 
     52 
     53 PRIVILEGES INFORMATION
     54 ----------------------
     55 
     56 Privilege Name                Description                          State
     57 ============================= ==================================== ========
     58 SeShutdownPrivilege           Shut down the system                 Disabled
     59 SeChangeNotifyPrivilege       Bypass traverse checking             Enabled
     60 SeUndockPrivilege             Remove computer from docking station Disabled
     61 SeIncreaseWorkingSetPrivilege Increase a process working set       Disabled
     62 SeTimeZonePrivilege           Change the time zone                 Disabled
     63 ```
     64 
     65 or using _Process Explorer_ from Sysinternals (select process and access"Security" tab):
     66 
     67 ![Access Tokens - Access Tokens: or using Process Explorer from Sysinternals (select process and access"Security" tab)](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28772%29.png)
     68 
     69 ### Local administrator
     70 
     71 When a local administrator logins, **two access tokens are created**: One with admin rights and other one with normal rights. **By default**, when this user executes a process the one with **regular** (non-administrator) **rights is used**. When this user tries to **execute** anything **as administrator** ("Run as Administrator" for example) the **UAC** will be used to ask for permission.\
     72 If you want to [**learn more about the UAC read this page**](../authentication-credentials-uac-and-efs/index.html#uac)**.**
     73 
     74 In practice, this means a **non-elevated admin shell usually runs with a filtered token**. That is why `whoami /groups` often shows **`BUILTIN\Administrators` as `Deny only`** until the process is elevated. Internally, Windows keeps a **linked elevated token** (`TokenLinkedToken`) and tracks the state with fields such as `TokenElevationType`.
     75 
     76 ### Credentials user impersonation
     77 
     78 If you have **valid credentials of any other user**, you can **create** a **new logon session** with those credentials :
     79 
     80 ```text
     81 runas /user:domain\username cmd.exe
     82 ```
     83 
     84 The **access token** has also a **reference** of the logon sessions inside the **LSASS**, this is useful if the process needs to access some objects of the network.\
     85 You can launch a process that **uses different credentials for accessing network services** using:
     86 
     87 ```text
     88 runas /user:domain\username /netonly cmd.exe
     89 ```
     90 
     91 This is useful if you have useful credentials to access objects in the network but those credentials aren't valid inside the current host as they are only going to be used in the network (in the current host your current user privileges will be used).
     92 
     93 #### `runas /netonly` details
     94 
     95 `runas /netonly` (and C2 helpers such as `make_token`) creates a **`LOGON32_LOGON_NEW_CREDENTIALS`** token. This is very useful to understand during lateral movement because:<sup>[[3]](#references)</sup>
     96 
     97 - **Locally**, the new process keeps the **same local identity**, groups, integrity level, and most of the same access decisions as the current token.
     98 - **Remotely**, outbound authentication can use the **supplied credentials** for SMB / WinRM / LDAP / HTTP / Kerberos / NTLM.
     99 - Therefore `whoami` may still show the **original local user** while network access happens as the **alternate account**.
    100 
    101 This is a great option when the credentials are valid in the domain or in another host, but the user **cannot or should not log on locally** to the current machine.
    102 
    103 ### Types of tokens
    104 
    105 There are two types of tokens available:
    106 
    107 - **Primary Token**: It serves as a representation of a process's security credentials. The creation and association of primary tokens with processes are actions that require elevated privileges, emphasizing the principle of privilege separation. Typically, an authentication service is responsible for token creation, while a logon service handles its association with the user's operating system shell. It is worth noting that processes inherit the primary token of their parent process at creation.
    108 - **Impersonation Token**: Empowers a server application to adopt the client's identity temporarily for accessing secure objects. This mechanism is stratified into four levels of operation:
    109   - **Anonymous**: Grants server access akin to that of an unidentified user.
    110   - **Identification**: Allows the server to verify the client's identity without utilizing it for object access.
    111   - **Impersonation**: Enables the server to operate under the client's identity.
    112   - **Delegation**: Similar to Impersonation but includes the ability to extend this identity assumption to remote systems the server interacts with, ensuring credential preservation.
    113 
    114 #### Impersonate Tokens
    115 
    116 Using the _**incognito**_ module of metasploit if you have enough privileges you can easily **list** and **impersonate** other **tokens**. This could be useful to perform **actions as if you where the other user**. You could also **escalate privileges** with this technique.
    117 
    118 Some practical notes that are easy to forget while operating:<sup>[[1]](#references)</sup>
    119 
    120 - **`CreateProcessWithTokenW`** requires **`SeImpersonatePrivilege`** in the caller and the new process will run in the **caller's session**.
    121 - **`CreateProcessAsUserW`** is the usual fallback when `CreateProcessWithTokenW` fails with `1314`, or when you need to launch in the **session referenced by the token**.
    122 - If a token comes from **`LogonUser(LOGON32_LOGON_NETWORK)`**, it is usually an **impersonation token**, so you need **`DuplicateTokenEx(..., TokenPrimary, ...)`** before trying to spawn a process with it.
    123 - Not every impersonation token is equally useful: **`SecurityIdentification`** lets you inspect the user but **not act as them**. If a coercion primitive or pipe/RPC client gives you only an identification-level token, check **`TokenImpersonationLevel`** and switch to a primitive that yields **`SecurityImpersonation`** or better.
    124 
    125 #### Token theft without touching LSASS
    126 
    127 If you already have a **service** or **SYSTEM** context and a **privileged user is logged on**, stealing or duplicating that user's token is often quieter than dumping **LSASS**. In many real intrusions this is enough to:<sup>[[2]](#references)</sup>
    128 
    129 - run local actions as that user
    130 - access remote resources as that user
    131 - perform AD operations without extracting reusable credentials first
    132 
    133 For examples of **session/user token hijacking** from a privileged context, check [**WTS Impersonator**](/hacktricks/windows-hardening/stealing-credentials/wts-impersonator). Remember that APIs such as **`WTSQueryUserToken`** are meant for **highly trusted services** and normally require **`LocalSystem` + `SeTcbPrivilege`**, so they are primarily useful once you already control a service-level context. For privilege-specific ways to obtain **SYSTEM** first, check the pages below.
    134 
    135 ### Token Privileges
    136 
    137 Learn which **token privileges can be abused to escalate privileges:**
    138 
    139 
    140 [Privilege Escalation Abusing Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens)
    141 
    142 Take a look to [**all the possible token privileges and some definitions on this external page**](https://github.com/gtworek/Priv2Admin).
    143 
    144 ## References
    145 
    146 - [1] [Understanding and Abusing Access Tokens — Part II](https://medium.com/@seemant.bisht24/understanding-and-abusing-access-tokens-part-ii-b9069f432962)
    147 - [2] [Abusing Windows' tokens to compromise Active Directory without touching LSASS](https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/)
    148 - [3] [Demystifying Cobalt Strike's "make_token" Command](https://www.fox-it.com/nl-en/demystifying-cobalt-strike-s-make_token-command/)