integrity-levels.md (8804B)
1 --- 2 title: "Integrity Levels" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/integrity-levels.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/integrity-levels.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Integrity Levels 14 15 ## Integrity Levels 16 17 In Windows Vista and later versions, securable objects can carry an **integrity level** label. Most objects are treated as medium integrity, while specific locations intended for low-integrity applications can be labelled low. Processes started by standard users normally run at medium integrity, elevated applications run at high integrity, and many services run at system integrity.<sup>[[1]](#references)</sup> 18 19 A key rule is that objects cannot be modified by processes with a lower integrity level than the object's level. Windows applies this Mandatory Integrity Control (MIC) check before evaluating the object's discretionary access control list (DACL). The commonly encountered levels are:<sup>[[1]](#references)[[2]](#references)</sup> 20 21 - **Untrusted**: The lowest level, represented by `SECURITY_MANDATORY_UNTRUSTED_RID` (`S-1-16-0`). Do not confuse this integrity label with the **Anonymous Logon** identity (`S-1-5-7`); authentication identities and MIC labels are separate SID namespaces. As a real-world example, Chromium's Windows sandbox initially assigns sandboxed targets Low integrity and then lowers renderer targets to Untrusted integrity after startup.<sup>[[5]](#references)[[6]](#references)</sup> 22 - **Low**: Mainly for internet interactions, especially in Internet Explorer's Protected Mode, affecting associated files and processes, and certain folders like the **Temporary Internet Folder**. Low integrity processes face significant restrictions, including no registry write access and limited user profile write access. 23 - **Medium**: The default level for most activities, assigned to standard users and objects without specific integrity levels. Even members of the Administrators group operate at this level by default. 24 - **High**: Reserved for administrators, allowing them to modify objects at lower integrity levels, including those at the high level itself. 25 - **System**: The highest operational level for the Windows kernel and core services, out of reach even for administrators, ensuring protection of vital system functions. 26 27 Windows also defines a protected-process integrity value above System. **TrustedInstaller**, however, is a Windows service identity rather than a separate MIC level; its ability to modify protected operating-system resources comes from the permissions granted to that identity. 28 29 Do not assume that a location such as the root of a system drive always has a fixed High integrity label. Inspect the effective DACL and any explicit mandatory label with `icacls`; an unlabeled object is treated as Medium for MIC, while its DACL and ownership can still independently restrict access.<sup>[[1]](#references)[[4]](#references)</sup> 30 31 You can obtain the integrity level of a process using **Process Explorer** from **Sysinternals** by opening the process properties and viewing the **Security** tab:<sup>[[3]](#references)</sup> 32 33  34 35 You can also obtain your **current integrity level** using `whoami /groups`: 36 37  38 39 ### Integrity Levels in the File System 40 41 An object in the file system may have a **minimum integrity-level requirement**. A process below that level is subject to the object's mandatory policy even when its DACL would otherwise grant access. For example, create a regular file from a standard-user console and inspect its permissions:<sup>[[1]](#references)[[4]](#references)</sup> 42 43 ```text 44 echo asd >asd.txt 45 icacls asd.txt 46 asd.txt BUILTIN\Administrators:(I)(F) 47 DESKTOP-IDJHTKP\user:(I)(F) 48 NT AUTHORITY\SYSTEM:(I)(F) 49 NT AUTHORITY\INTERACTIVE:(I)(M,DC) 50 NT AUTHORITY\SERVICE:(I)(M,DC) 51 NT AUTHORITY\BATCH:(I)(M,DC) 52 ``` 53 54 Now, assign a minimum integrity level of **High** to the file. This **must be done from a console** running as **administrator**, because a regular console runs at Medium integrity and **will not be allowed** to assign High integrity to an object: 55 56 ```text 57 icacls asd.txt /setintegritylevel(oi)(ci) High 58 processed file: asd.txt 59 Successfully processed 1 files; Failed processing 0 files 60 61 C:\Users\Public>icacls asd.txt 62 asd.txt BUILTIN\Administrators:(I)(F) 63 DESKTOP-IDJHTKP\user:(I)(F) 64 NT AUTHORITY\SYSTEM:(I)(F) 65 NT AUTHORITY\INTERACTIVE:(I)(M,DC) 66 NT AUTHORITY\SERVICE:(I)(M,DC) 67 NT AUTHORITY\BATCH:(I)(M,DC) 68 Mandatory Label\High Mandatory Level:(NW) 69 ``` 70 71 The user `DESKTOP-IDJHTKP\user` has **FULL privileges** over the file because that user created it. However, the mandatory label prevents the user from modifying the file unless the process is running at High integrity. The user can still read it because the displayed mandatory policy is `(NW)`, or no-write-up: 72 73 ```text 74 echo 1234 > asd.txt 75 Access is denied. 76 77 del asd.txt 78 C:\Users\Public\asd.txt 79 Access is denied. 80 ``` 81 82 > [!TIP] 83 > **Therefore, when a file has a minimum integrity level, in order to modify it you need to be running at least in that integrity level.** 84 85 ### Integrity Levels in Binaries 86 87 The following example uses a copy of `cmd.exe` at `C:\Windows\System32\cmd-low.exe` and assigns it a **Low integrity level from an administrator console**: 88 89 ```text 90 icacls C:\Windows\System32\cmd-low.exe 91 C:\Windows\System32\cmd-low.exe NT AUTHORITY\SYSTEM:(I)(F) 92 BUILTIN\Administrators:(I)(F) 93 BUILTIN\Users:(I)(RX) 94 APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(I)(RX) 95 APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APP PACKAGES:(I)(RX) 96 Mandatory Label\Low Mandatory Level:(NW) 97 ``` 98 99 Now, when I run `cmd-low.exe` it will **run under a low-integrity level** instead of a medium one: 100 101  102 103 Assigning a High integrity label to a binary (`icacls C:\Windows\System32\cmd-high.exe /setintegritylevel high`) does not make it run at High integrity automatically. If invoked from a Medium-integrity process, it runs at Medium integrity because a new process receives the lower of the executable file's and the caller's integrity levels.<sup>[[1]](#references)</sup> 104 105 ### Integrity Levels in Processes 106 107 Not all files and folders have an explicit minimum integrity label, **but every process runs at an integrity level**. As with file-system objects, **a process that wants write access to another process must have at least the same integrity level**. Therefore, a Low-integrity process cannot open a Medium-integrity process with full access.<sup>[[1]](#references)</sup> 108 109 Because of these restrictions, the safest approach is to **run each process at the lowest integrity level that still lets it perform its intended work**. 110 111 ## References 112 113 - [1] [Microsoft Learn – Mandatory Integrity Control](https://learn.microsoft.com/en-us/windows/win32/secauthz/mandatory-integrity-control) 114 - [2] [Microsoft Learn – MANDATORY_LEVEL enumeration](https://learn.microsoft.com/en-us/windows/win32/api/winnt/ne-winnt-mandatory_level) 115 - [3] [Microsoft Sysinternals – Process Explorer](https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer) 116 - [4] [Microsoft Learn – icacls](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/icacls) 117 - [5] [Chromium source – Default Windows sandbox integrity policy](https://github.com/chromium/chromium/blob/main/sandbox/policy/win/sandbox_win.cc#L212-L216) 118 - [6] [Microsoft Learn – Well-known SIDs](https://learn.microsoft.com/en-us/windows/win32/secauthz/well-known-sids)