Privilege and Token Abuse
On Windows, what a process can do isn’t decided just by “being admin”: it’s decided by its access token, which carries the user’s SID, their groups, and a list of privileges (SeXxxPrivilege). Several of those privileges, even without making you an administrator on paper, let you reach SYSTEM directly. Enumerating whoami /priv and knowing what each privilege does is often the entire escalation.
Threat model
Section titled “Threat model”The design flaw the attacker exploits is that certain privileges are equivalent to SYSTEM even though Windows grants them to “ordinary” service accounts (IIS, MSSQL, tasks). The system trusts that only legitimate code will use them; an attacker inheriting that token turns them into full control. Nothing needs breaking: the privilege is already granted.
Dangerous privileges and what they allow
Section titled “Dangerous privileges and what they allow”SeImpersonatePrivilege / SeAssignPrimaryTokenPrivilege
Section titled “SeImpersonatePrivilege / SeAssignPrimaryTokenPrivilege”The most common on service accounts. Lets you impersonate a connecting client’s token. The Potato family forces a SYSTEM service (spooler, RPC, DCOM) to authenticate to the attacker, who steals and impersonates its token:
PrintSpoofer.exe -i -c "cmd.exe" # SeImpersonate -> SYSTEMGodPotato.exe -cmd "cmd /c whoami"RoguePotato.exe -r <ip> -e "cmd.exe" -l 9999SeDebugPrivilege
Section titled “SeDebugPrivilege”Open any process, including LSASS. Lets you dump credentials (procdump lsass, mimikatz sekurlsa) or inject code into SYSTEM processes.
mimikatz # privilege::debugmimikatz # sekurlsa::logonpasswordsSeBackupPrivilege / SeRestorePrivilege
Section titled “SeBackupPrivilege / SeRestorePrivilege”SeBackup ignores ACLs on read: copy the SAM, SYSTEM, SECURITY, or NTDS.dit hives even when protected. SeRestore ignores ACLs on write: overwrite protected binaries or service keys.
reg save HKLM\SAM sam.hive # with SeBackupreg save HKLM\SYSTEM system.hive# then: secretsdump.py -sam sam.hive -system system.hive LOCALSeTakeOwnershipPrivilege
Section titled “SeTakeOwnershipPrivilege”Take ownership of any object (file, key, service) to then rewrite its DACL and modify it → control of a privileged binary/service.
SeLoadDriverPrivilege
Section titled “SeLoadDriverPrivilege”Load drivers → BYOVD (Bring Your Own Vulnerable Driver): load a signed-but-vulnerable driver and exploit it to run in the kernel (e.g. Capcom.sys).
SeManageVolumePrivilege, SeTcbPrivilege, SeCreateToken…
Section titled “SeManageVolumePrivilege, SeTcbPrivilege, SeCreateToken…”Other high-impact privileges; SeTcb/SeCreateToken allow forging arbitrary tokens (acting as part of the OS).
Red Team — integrity and UAC
Section titled “Red Team — integrity and UAC”The token also carries an integrity level (Low/Medium/High/System). Elevating Medium to High is a UAC bypass (see UAC Bypass); High to System is typically impersonation or services.
- PrintSpoofer / GodPotato / JuicyPotato / RoguePotato — SeImpersonate exploitation.
- mimikatz (
token::elevate,privilege::debug,sekurlsa) — token manipulation and dumping. - incognito (Metasploit
list_tokens/impersonate_token) — steal and impersonate logged-on users’ tokens. - SeBackupPrivilege / SeRestore PoCs and
reg save; secretsdump to process hives.
Impact
Section titled “Impact”Direct local SYSTEM (impersonation), dumping of all host credentials (debug/backup), kernel execution (load driver). On a DC, SeBackup over NTDS.dit = all domain hashes.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- Service accounts with SYSTEM shells after named-pipe activity (Potato).
- LSASS access (Sysmon event 10 with suspicious
GrantedAccess) → SeDebug/dump. reg saveof SAM/SYSTEM/SECURITY; loading of unusual drivers (Sysmon event 6, service 7045 of kernel type).- Use of
SeBackupPrivilegeto open protected files.
Telemetry
Section titled “Telemetry”Audit special privilege assignment (event 4672 on logon, 4673/4674 sensitive privilege use), Sysmon 1/6/10, and service/driver creation.
Hardening
Section titled “Hardening”- Least privilege on service accounts: strip SeImpersonate/SeDebug/SeBackup if not essential; use gMSA with scoped rights.
- Credential Guard and LSASS protection (RunAsPPL) against SeDebug dumping.
- Microsoft Driver Blocklist / WDAC to stop BYOVD; HVCI.
- Restrict who holds SeBackup/SeRestore (real backup operators, not app accounts).
Response
Section titled “Response”If a privilege led to SYSTEM/credentials, treat the host as compromised: rotate secrets, review what was dumped, and remove the excess privilege from the affected account.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- The Potato family (SeImpersonate) is a standard TTP against IIS/MSSQL (MITRE T1134.001/.002).
- BYOVD: ransomware and APT campaigns load vulnerable drivers (RTCore64, Capcom, Dell dbutil CVE-2021-21551) to disable EDR.
- SeBackupPrivilege → NTDS.dit is a common DC post-exploitation technique (MITRE T1003.003).
- mimikatz
sekurlsavia SeDebug: one of the most documented TTPs in real breaches.
Testing checklist
Section titled “Testing checklist”-
whoami /priv— list all enabled/disabled privileges - SeImpersonate/SeAssignPrimaryToken → Potato to SYSTEM
- SeDebug → LSASS dump (mimikatz/procdump)
- SeBackup →
reg saveof SAM/SYSTEM or read NTDS.dit - SeRestore/SeTakeOwnership → rewrite a protected binary/service
- SeLoadDriver → BYOVD (signed vulnerable driver)
- Other logged-on users’ tokens impersonable (incognito)
- Is LSASS protected (RunAsPPL/Credential Guard)?