daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

semanagevolume-perform-volume-maintenance-tasks.md (6506B)


      1 ---
      2 title: "SeManageVolumePrivilege: Volume-maintenance abuse and raw-access validation"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/semanagevolume-perform-volume-maintenance-tasks.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/semanagevolume-perform-volume-maintenance-tasks.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # SeManageVolumePrivilege: Volume-maintenance abuse and raw-access validation
     14 
     15 ## Overview
     16 
     17 Windows user right: Perform volume maintenance tasks (constant: SeManageVolumePrivilege).
     18 
     19 The right authorizes volume-maintenance operations such as defragmentation and creating or removing volumes. Microsoft warns that a holder may be able to extend files into storage containing other data and then read or modify the acquired bytes.<sup>[[1]](#references)</sup>
     20 
     21 Do not equate possession of `SeManageVolumePrivilege` with guaranteed raw-disk access. Microsoft documents that opening a physical disk or volume through `CreateFile` for direct access requires administrative privileges, and normal object/device access checks still apply. On a particular build or product, test whether the token, device ACL, requested access, share flags, and volume state permit a raw handle before claiming arbitrary file read.<sup>[[3]](#references)</sup>
     22 
     23 Default: Administrators on servers and domain controllers.<sup>[[1]](#references)</sup>
     24 
     25 ## Abuse scenarios
     26 
     27 - If the account can actually obtain a readable raw-volume handle, an NTFS-aware parser can bypass per-file ACLs and recover protected or locked files from allocated clusters.
     28 - Possible targets include locked or ACL-protected content under `C:\Windows\System32`, registry hives, DPAPI master keys, the SAM, and—where separately accessible through a snapshot or offline volume—`ntds.dit`.
     29 - On certificate services hosts, useful software-key locations include `%ProgramData%\Microsoft\Crypto\RSA\MachineKeys` and `%ProgramData%\Microsoft\Crypto\Keys`; recovering a file is useful only when its key material is exportable and can also be decrypted.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup>
     30 - On an AD CS host, a successfully recovered **exportable/software-backed** CA private key can enable Golden Certificate abuse. Hardware-backed or non-exportable key designs change this path.<sup>[[2]](#references)</sup>
     31 
     32 Note: You still need a parser for NTFS structures unless you rely on helper tools. Many off-the-shelf tools abstract the raw access.
     33 
     34 ## Practical techniques
     35 
     36 - Open a raw volume handle and read clusters:
     37 
     38 <details>
     39 <summary>Click to expand</summary>
     40 
     41 ```powershell
     42 # Validation attempt: current Windows versions normally require an administrative token
     43 $fs = [System.IO.File]::Open("\\.\\C:",[System.IO.FileMode]::Open,[System.IO.FileAccess]::Read,[System.IO.FileShare]::ReadWrite)
     44 $buf = New-Object byte[] (1MB)
     45 $null = $fs.Read($buf,0,$buf.Length)
     46 $fs.Close()
     47 [IO.File]::WriteAllBytes("C:\\temp\\c_first_mb.bin", $buf)
     48 ```
     49 
     50 ```csharp
     51 // C# (compile with Add-Type) – read an arbitrary offset of \\.\nusing System;
     52 using System.IO;
     53 class R {
     54   static void Main(string[] a){
     55     using(var fs = new FileStream("\\\\.\\C:", FileMode.Open, FileAccess.Read, FileShare.ReadWrite)){
     56       fs.Position = 0x100000; // seek
     57       var buf = new byte[4096];
     58       fs.Read(buf,0,buf.Length);
     59       File.WriteAllBytes("C:\\temp\\blk.bin", buf);
     60     }
     61   }
     62 }
     63 ```
     64 
     65 </details>
     66 
     67 - Use an NTFS-aware tool to recover specific files from raw volume:
     68   - RawCopy/RawCopy64 (sector-level copy of in-use files)
     69   - FTK Imager or The Sleuth Kit (read-only imaging, then carve files)
     70   - vssadmin/diskshadow + shadow copy, then copy target file from the snapshot (if you can create VSS; often requires admin but commonly available to the same operators that hold SeManageVolumePrivilege)
     71 
     72 Typical sensitive paths to target:
     73 - %ProgramData%\Microsoft\Crypto\RSA\MachineKeys\
     74 - %ProgramData%\Microsoft\Crypto\Keys\
     75 - C:\Windows\System32\config\SAM, SYSTEM, SECURITY (local secrets)
     76 - C:\Windows\NTDS\ntds.dit (domain controllers – via shadow copy)
     77 - C:\Windows\System32\CertSrv\CertEnroll\ (CA certs/CRLs; private keys live in the machine key store above)
     78 
     79 ## AD CS tie‑in: Forging a Golden Certificate
     80 
     81 If you can read the Enterprise CA’s private key from the machine key store, you can forge client‑auth certificates for arbitrary principals and authenticate via PKINIT/Schannel. This is often referred to as a Golden Certificate.<sup>[[2]](#references)</sup> See:
     82 
     83 [Domain Persistence](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/domain-persistence)
     84 
     85 (Section: “Forging Certificates with Stolen CA Certificates (Golden Certificate) – DPERSIST1”).
     86 
     87 ## Detection and hardening
     88 
     89 - Strongly limit assignment of SeManageVolumePrivilege (Perform volume maintenance tasks) to only trusted admins.
     90 - Monitor Sensitive Privilege Use and process handle opens to device objects like \\.\C:, \\.\PhysicalDrive0.
     91 - Prefer properly configured HSM- or TPM-backed, non-exportable CA keys so a copied key-container file is not sufficient to recover usable private-key material.
     92 - For application secrets outside the CA-key path, DPAPI or DPAPI-NG can make a copied data file insufficient by protecting it to a user, machine, group, or other authorized principal. This does not protect plaintext already accessible to the compromised principal.<sup>[[4]](#references)</sup>
     93 - Keep uploads, temp, and extraction paths non-executable and separated (web context defense that often pairs with this chain post‑exploitation).
     94 
     95 ## References
     96 
     97 - [1] [Microsoft – Perform volume maintenance tasks (SeManageVolumePrivilege)](https://learn.microsoft.com/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/perform-volume-maintenance-tasks)
     98 - [2] [0xdf – HTB: Certificate (SeManageVolumePrivilege used to read CA key → Golden Certificate)](https://0xdf.gitlab.io/2025/10/04/htb-certificate.html)
     99 - [3] [Microsoft - `CreateFile` physical disks and volumes](https://learn.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-createfilea#physical-disks-and-volumes)
    100 - [4] [Microsoft - Cryptography API: Next Generation and DPAPI-NG](https://learn.microsoft.com/en-us/windows/win32/seccng/cng-portal)