Skip to content

Privilege and Token Abuse

On Windows, what a process can do isn’t decided just by “being admin”: it’s decided by its access token, which carries the user’s SID, their groups, and a list of privileges (SeXxxPrivilege). Several of those privileges, even without making you an administrator on paper, let you reach SYSTEM directly. Enumerating whoami /priv and knowing what each privilege does is often the entire escalation.

The design flaw the attacker exploits is that certain privileges are equivalent to SYSTEM even though Windows grants them to “ordinary” service accounts (IIS, MSSQL, tasks). The system trusts that only legitimate code will use them; an attacker inheriting that token turns them into full control. Nothing needs breaking: the privilege is already granted.

SeImpersonatePrivilege / SeAssignPrimaryTokenPrivilege

Section titled “SeImpersonatePrivilege / SeAssignPrimaryTokenPrivilege”

The most common on service accounts. Lets you impersonate a connecting client’s token. The Potato family forces a SYSTEM service (spooler, RPC, DCOM) to authenticate to the attacker, who steals and impersonates its token:

PrintSpoofer.exe -i -c "cmd.exe" # SeImpersonate -> SYSTEM
GodPotato.exe -cmd "cmd /c whoami"
RoguePotato.exe -r <ip> -e "cmd.exe" -l 9999

Open any process, including LSASS. Lets you dump credentials (procdump lsass, mimikatz sekurlsa) or inject code into SYSTEM processes.

mimikatz # privilege::debug
mimikatz # sekurlsa::logonpasswords

SeBackup ignores ACLs on read: copy the SAM, SYSTEM, SECURITY, or NTDS.dit hives even when protected. SeRestore ignores ACLs on write: overwrite protected binaries or service keys.

reg save HKLM\SAM sam.hive # with SeBackup
reg save HKLM\SYSTEM system.hive
# then: secretsdump.py -sam sam.hive -system system.hive LOCAL

Take ownership of any object (file, key, service) to then rewrite its DACL and modify it → control of a privileged binary/service.

Load drivers → BYOVD (Bring Your Own Vulnerable Driver): load a signed-but-vulnerable driver and exploit it to run in the kernel (e.g. Capcom.sys).

SeManageVolumePrivilege, SeTcbPrivilege, SeCreateToken…

Section titled “SeManageVolumePrivilege, SeTcbPrivilege, SeCreateToken…”

Other high-impact privileges; SeTcb/SeCreateToken allow forging arbitrary tokens (acting as part of the OS).

The token also carries an integrity level (Low/Medium/High/System). Elevating Medium to High is a UAC bypass (see UAC Bypass); High to System is typically impersonation or services.

  • PrintSpoofer / GodPotato / JuicyPotato / RoguePotato — SeImpersonate exploitation.
  • mimikatz (token::elevate, privilege::debug, sekurlsa) — token manipulation and dumping.
  • incognito (Metasploit list_tokens/impersonate_token) — steal and impersonate logged-on users’ tokens.
  • SeBackupPrivilege / SeRestore PoCs and reg save; secretsdump to process hives.

Direct local SYSTEM (impersonation), dumping of all host credentials (debug/backup), kernel execution (load driver). On a DC, SeBackup over NTDS.dit = all domain hashes.

  • Service accounts with SYSTEM shells after named-pipe activity (Potato).
  • LSASS access (Sysmon event 10 with suspicious GrantedAccess) → SeDebug/dump.
  • reg save of SAM/SYSTEM/SECURITY; loading of unusual drivers (Sysmon event 6, service 7045 of kernel type).
  • Use of SeBackupPrivilege to open protected files.

Audit special privilege assignment (event 4672 on logon, 4673/4674 sensitive privilege use), Sysmon 1/6/10, and service/driver creation.

  • Least privilege on service accounts: strip SeImpersonate/SeDebug/SeBackup if not essential; use gMSA with scoped rights.
  • Credential Guard and LSASS protection (RunAsPPL) against SeDebug dumping.
  • Microsoft Driver Blocklist / WDAC to stop BYOVD; HVCI.
  • Restrict who holds SeBackup/SeRestore (real backup operators, not app accounts).

If a privilege led to SYSTEM/credentials, treat the host as compromised: rotate secrets, review what was dumped, and remove the excess privilege from the affected account.

  • The Potato family (SeImpersonate) is a standard TTP against IIS/MSSQL (MITRE T1134.001/.002).
  • BYOVD: ransomware and APT campaigns load vulnerable drivers (RTCore64, Capcom, Dell dbutil CVE-2021-21551) to disable EDR.
  • SeBackupPrivilege → NTDS.dit is a common DC post-exploitation technique (MITRE T1003.003).
  • mimikatz sekurlsa via SeDebug: one of the most documented TTPs in real breaches.
  • whoami /priv — list all enabled/disabled privileges
  • SeImpersonate/SeAssignPrimaryToken → Potato to SYSTEM
  • SeDebug → LSASS dump (mimikatz/procdump)
  • SeBackup → reg save of SAM/SYSTEM or read NTDS.dit
  • SeRestore/SeTakeOwnership → rewrite a protected binary/service
  • SeLoadDriver → BYOVD (signed vulnerable driver)
  • Other logged-on users’ tokens impersonable (incognito)
  • Is LSASS protected (RunAsPPL/Credential Guard)?