daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

integrity-levels.md (8804B)


      1 ---
      2 title: "Integrity Levels"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/integrity-levels.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/integrity-levels.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Integrity Levels
     14 
     15 ## Integrity Levels
     16 
     17 In Windows Vista and later versions, securable objects can carry an **integrity level** label. Most objects are treated as medium integrity, while specific locations intended for low-integrity applications can be labelled low. Processes started by standard users normally run at medium integrity, elevated applications run at high integrity, and many services run at system integrity.<sup>[[1]](#references)</sup>
     18 
     19 A key rule is that objects cannot be modified by processes with a lower integrity level than the object's level. Windows applies this Mandatory Integrity Control (MIC) check before evaluating the object's discretionary access control list (DACL). The commonly encountered levels are:<sup>[[1]](#references)[[2]](#references)</sup>
     20 
     21 - **Untrusted**: The lowest level, represented by `SECURITY_MANDATORY_UNTRUSTED_RID` (`S-1-16-0`). Do not confuse this integrity label with the **Anonymous Logon** identity (`S-1-5-7`); authentication identities and MIC labels are separate SID namespaces. As a real-world example, Chromium's Windows sandbox initially assigns sandboxed targets Low integrity and then lowers renderer targets to Untrusted integrity after startup.<sup>[[5]](#references)[[6]](#references)</sup>
     22 - **Low**: Mainly for internet interactions, especially in Internet Explorer's Protected Mode, affecting associated files and processes, and certain folders like the **Temporary Internet Folder**. Low integrity processes face significant restrictions, including no registry write access and limited user profile write access.
     23 - **Medium**: The default level for most activities, assigned to standard users and objects without specific integrity levels. Even members of the Administrators group operate at this level by default.
     24 - **High**: Reserved for administrators, allowing them to modify objects at lower integrity levels, including those at the high level itself.
     25 - **System**: The highest operational level for the Windows kernel and core services, out of reach even for administrators, ensuring protection of vital system functions.
     26 
     27 Windows also defines a protected-process integrity value above System. **TrustedInstaller**, however, is a Windows service identity rather than a separate MIC level; its ability to modify protected operating-system resources comes from the permissions granted to that identity.
     28 
     29 Do not assume that a location such as the root of a system drive always has a fixed High integrity label. Inspect the effective DACL and any explicit mandatory label with `icacls`; an unlabeled object is treated as Medium for MIC, while its DACL and ownership can still independently restrict access.<sup>[[1]](#references)[[4]](#references)</sup>
     30 
     31 You can obtain the integrity level of a process using **Process Explorer** from **Sysinternals** by opening the process properties and viewing the **Security** tab:<sup>[[3]](#references)</sup>
     32 
     33 ![Integrity Levels - Integrity Levels: You can get the integrity level of a process using Process Explorer from Sysinternals , accessing the properties of the process and viewing the "...](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28824%29.png)
     34 
     35 You can also obtain your **current integrity level** using `whoami /groups`:
     36 
     37 ![Integrity Levels - Integrity Levels: You can also get your current integrity level using whoami /groups](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28325%29.png)
     38 
     39 ### Integrity Levels in the File System
     40 
     41 An object in the file system may have a **minimum integrity-level requirement**. A process below that level is subject to the object's mandatory policy even when its DACL would otherwise grant access. For example, create a regular file from a standard-user console and inspect its permissions:<sup>[[1]](#references)[[4]](#references)</sup>
     42 
     43 ```text
     44 echo asd >asd.txt
     45 icacls asd.txt
     46 asd.txt BUILTIN\Administrators:(I)(F)
     47         DESKTOP-IDJHTKP\user:(I)(F)
     48         NT AUTHORITY\SYSTEM:(I)(F)
     49         NT AUTHORITY\INTERACTIVE:(I)(M,DC)
     50         NT AUTHORITY\SERVICE:(I)(M,DC)
     51         NT AUTHORITY\BATCH:(I)(M,DC)
     52 ```
     53 
     54 Now, assign a minimum integrity level of **High** to the file. This **must be done from a console** running as **administrator**, because a regular console runs at Medium integrity and **will not be allowed** to assign High integrity to an object:
     55 
     56 ```text
     57 icacls asd.txt /setintegritylevel(oi)(ci) High
     58 processed file: asd.txt
     59 Successfully processed 1 files; Failed processing 0 files
     60 
     61 C:\Users\Public>icacls asd.txt
     62 asd.txt BUILTIN\Administrators:(I)(F)
     63         DESKTOP-IDJHTKP\user:(I)(F)
     64         NT AUTHORITY\SYSTEM:(I)(F)
     65         NT AUTHORITY\INTERACTIVE:(I)(M,DC)
     66         NT AUTHORITY\SERVICE:(I)(M,DC)
     67         NT AUTHORITY\BATCH:(I)(M,DC)
     68         Mandatory Label\High Mandatory Level:(NW)
     69 ```
     70 
     71 The user `DESKTOP-IDJHTKP\user` has **FULL privileges** over the file because that user created it. However, the mandatory label prevents the user from modifying the file unless the process is running at High integrity. The user can still read it because the displayed mandatory policy is `(NW)`, or no-write-up:
     72 
     73 ```text
     74 echo 1234 > asd.txt
     75 Access is denied.
     76 
     77 del asd.txt
     78 C:\Users\Public\asd.txt
     79 Access is denied.
     80 ```
     81 
     82 > [!TIP]
     83 > **Therefore, when a file has a minimum integrity level, in order to modify it you need to be running at least in that integrity level.**
     84 
     85 ### Integrity Levels in Binaries
     86 
     87 The following example uses a copy of `cmd.exe` at `C:\Windows\System32\cmd-low.exe` and assigns it a **Low integrity level from an administrator console**:
     88 
     89 ```text
     90 icacls C:\Windows\System32\cmd-low.exe
     91 C:\Windows\System32\cmd-low.exe NT AUTHORITY\SYSTEM:(I)(F)
     92                                 BUILTIN\Administrators:(I)(F)
     93                                 BUILTIN\Users:(I)(RX)
     94                                 APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(I)(RX)
     95                                 APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APP PACKAGES:(I)(RX)
     96                                 Mandatory Label\Low Mandatory Level:(NW)
     97 ```
     98 
     99 Now, when I run `cmd-low.exe` it will **run under a low-integrity level** instead of a medium one:
    100 
    101 ![Integrity Levels in File-system - Integrity Levels in Binaries: Now, when I run cmd-low.exe it will run under a low-integrity level instead of a medium one](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28313%29.png)
    102 
    103 Assigning a High integrity label to a binary (`icacls C:\Windows\System32\cmd-high.exe /setintegritylevel high`) does not make it run at High integrity automatically. If invoked from a Medium-integrity process, it runs at Medium integrity because a new process receives the lower of the executable file's and the caller's integrity levels.<sup>[[1]](#references)</sup>
    104 
    105 ### Integrity Levels in Processes
    106 
    107 Not all files and folders have an explicit minimum integrity label, **but every process runs at an integrity level**. As with file-system objects, **a process that wants write access to another process must have at least the same integrity level**. Therefore, a Low-integrity process cannot open a Medium-integrity process with full access.<sup>[[1]](#references)</sup>
    108 
    109 Because of these restrictions, the safest approach is to **run each process at the lowest integrity level that still lets it perform its intended work**.
    110 
    111 ## References
    112 
    113 - [1] [Microsoft Learn – Mandatory Integrity Control](https://learn.microsoft.com/en-us/windows/win32/secauthz/mandatory-integrity-control)
    114 - [2] [Microsoft Learn – MANDATORY_LEVEL enumeration](https://learn.microsoft.com/en-us/windows/win32/api/winnt/ne-winnt-mandatory_level)
    115 - [3] [Microsoft Sysinternals – Process Explorer](https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer)
    116 - [4] [Microsoft Learn – icacls](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/icacls)
    117 - [5] [Chromium source – Default Windows sandbox integrity policy](https://github.com/chromium/chromium/blob/main/sandbox/policy/win/sandbox_win.cc#L212-L216)
    118 - [6] [Microsoft Learn – Well-known SIDs](https://learn.microsoft.com/en-us/windows/win32/secauthz/well-known-sids)