semanagevolume-perform-volume-maintenance-tasks.md (6506B)
1 --- 2 title: "SeManageVolumePrivilege: Volume-maintenance abuse and raw-access validation" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/semanagevolume-perform-volume-maintenance-tasks.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/semanagevolume-perform-volume-maintenance-tasks.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # SeManageVolumePrivilege: Volume-maintenance abuse and raw-access validation 14 15 ## Overview 16 17 Windows user right: Perform volume maintenance tasks (constant: SeManageVolumePrivilege). 18 19 The right authorizes volume-maintenance operations such as defragmentation and creating or removing volumes. Microsoft warns that a holder may be able to extend files into storage containing other data and then read or modify the acquired bytes.<sup>[[1]](#references)</sup> 20 21 Do not equate possession of `SeManageVolumePrivilege` with guaranteed raw-disk access. Microsoft documents that opening a physical disk or volume through `CreateFile` for direct access requires administrative privileges, and normal object/device access checks still apply. On a particular build or product, test whether the token, device ACL, requested access, share flags, and volume state permit a raw handle before claiming arbitrary file read.<sup>[[3]](#references)</sup> 22 23 Default: Administrators on servers and domain controllers.<sup>[[1]](#references)</sup> 24 25 ## Abuse scenarios 26 27 - If the account can actually obtain a readable raw-volume handle, an NTFS-aware parser can bypass per-file ACLs and recover protected or locked files from allocated clusters. 28 - Possible targets include locked or ACL-protected content under `C:\Windows\System32`, registry hives, DPAPI master keys, the SAM, and—where separately accessible through a snapshot or offline volume—`ntds.dit`. 29 - On certificate services hosts, useful software-key locations include `%ProgramData%\Microsoft\Crypto\RSA\MachineKeys` and `%ProgramData%\Microsoft\Crypto\Keys`; recovering a file is useful only when its key material is exportable and can also be decrypted.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup> 30 - On an AD CS host, a successfully recovered **exportable/software-backed** CA private key can enable Golden Certificate abuse. Hardware-backed or non-exportable key designs change this path.<sup>[[2]](#references)</sup> 31 32 Note: You still need a parser for NTFS structures unless you rely on helper tools. Many off-the-shelf tools abstract the raw access. 33 34 ## Practical techniques 35 36 - Open a raw volume handle and read clusters: 37 38 <details> 39 <summary>Click to expand</summary> 40 41 ```powershell 42 # Validation attempt: current Windows versions normally require an administrative token 43 $fs = [System.IO.File]::Open("\\.\\C:",[System.IO.FileMode]::Open,[System.IO.FileAccess]::Read,[System.IO.FileShare]::ReadWrite) 44 $buf = New-Object byte[] (1MB) 45 $null = $fs.Read($buf,0,$buf.Length) 46 $fs.Close() 47 [IO.File]::WriteAllBytes("C:\\temp\\c_first_mb.bin", $buf) 48 ``` 49 50 ```csharp 51 // C# (compile with Add-Type) – read an arbitrary offset of \\.\nusing System; 52 using System.IO; 53 class R { 54 static void Main(string[] a){ 55 using(var fs = new FileStream("\\\\.\\C:", FileMode.Open, FileAccess.Read, FileShare.ReadWrite)){ 56 fs.Position = 0x100000; // seek 57 var buf = new byte[4096]; 58 fs.Read(buf,0,buf.Length); 59 File.WriteAllBytes("C:\\temp\\blk.bin", buf); 60 } 61 } 62 } 63 ``` 64 65 </details> 66 67 - Use an NTFS-aware tool to recover specific files from raw volume: 68 - RawCopy/RawCopy64 (sector-level copy of in-use files) 69 - FTK Imager or The Sleuth Kit (read-only imaging, then carve files) 70 - vssadmin/diskshadow + shadow copy, then copy target file from the snapshot (if you can create VSS; often requires admin but commonly available to the same operators that hold SeManageVolumePrivilege) 71 72 Typical sensitive paths to target: 73 - %ProgramData%\Microsoft\Crypto\RSA\MachineKeys\ 74 - %ProgramData%\Microsoft\Crypto\Keys\ 75 - C:\Windows\System32\config\SAM, SYSTEM, SECURITY (local secrets) 76 - C:\Windows\NTDS\ntds.dit (domain controllers – via shadow copy) 77 - C:\Windows\System32\CertSrv\CertEnroll\ (CA certs/CRLs; private keys live in the machine key store above) 78 79 ## AD CS tie‑in: Forging a Golden Certificate 80 81 If you can read the Enterprise CA’s private key from the machine key store, you can forge client‑auth certificates for arbitrary principals and authenticate via PKINIT/Schannel. This is often referred to as a Golden Certificate.<sup>[[2]](#references)</sup> See: 82 83 [Domain Persistence](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/domain-persistence) 84 85 (Section: “Forging Certificates with Stolen CA Certificates (Golden Certificate) – DPERSIST1”). 86 87 ## Detection and hardening 88 89 - Strongly limit assignment of SeManageVolumePrivilege (Perform volume maintenance tasks) to only trusted admins. 90 - Monitor Sensitive Privilege Use and process handle opens to device objects like \\.\C:, \\.\PhysicalDrive0. 91 - Prefer properly configured HSM- or TPM-backed, non-exportable CA keys so a copied key-container file is not sufficient to recover usable private-key material. 92 - For application secrets outside the CA-key path, DPAPI or DPAPI-NG can make a copied data file insufficient by protecting it to a user, machine, group, or other authorized principal. This does not protect plaintext already accessible to the compromised principal.<sup>[[4]](#references)</sup> 93 - Keep uploads, temp, and extraction paths non-executable and separated (web context defense that often pairs with this chain post‑exploitation). 94 95 ## References 96 97 - [1] [Microsoft – Perform volume maintenance tasks (SeManageVolumePrivilege)](https://learn.microsoft.com/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/perform-volume-maintenance-tasks) 98 - [2] [0xdf – HTB: Certificate (SeManageVolumePrivilege used to read CA key → Golden Certificate)](https://0xdf.gitlab.io/2025/10/04/htb-certificate.html) 99 - [3] [Microsoft - `CreateFile` physical disks and volumes](https://learn.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-createfilea#physical-disks-and-volumes) 100 - [4] [Microsoft - Cryptography API: Next Generation and DPAPI-NG](https://learn.microsoft.com/en-us/windows/win32/seccng/cng-portal)