Skip to main content

Overview

Havoc implements a comprehensive token management system that allows operators to steal, store, and impersonate Windows access tokens. This enables privilege escalation, lateral movement, and operating under different security contexts.
The token vault maintains a linked list of stolen and created tokens that persist across commands, allowing operators to switch between security contexts on demand.

Token Vault Architecture

The token vault is a linked list structure that stores token metadata: Source: payloads/Demon/include/core/Token.h:80

Token Operations

Stealing Tokens

Tokens can be stolen from running processes using NtOpenProcessToken or NtDuplicateObject: Source: payloads/Demon/src/core/Token.c:414
Steals the primary token from process ID 1234.

Make Token

Create tokens from credentials using LogonUserW: Source: payloads/Demon/src/core/Token.c:598
Logon Types:
  • LOGON32_LOGON_NEW_CREDENTIALS (9): Network credentials only (like runas /netonly)
  • LOGON32_LOGON_INTERACTIVE (2): Full interactive logon
  • LOGON32_LOGON_NETWORK (3): Network logon

Token Duplication

Tokens are duplicated to create impersonation tokens: Source: payloads/Demon/src/core/Token.c:37

Impersonation

Tokens are applied to the current thread using NtSetInformationThread: Source: payloads/Demon/src/core/Token.c:1281

Reverting Impersonation

Remove thread impersonation: Source: payloads/Demon/src/core/Token.c:74

Privilege Management

Havoc can enable/disable token privileges: Source: payloads/Demon/src/core/Token.c:203

Common Privileges

Source: payloads/Demon/src/core/Token.c:240Enables opening handles to any process:
Source: payloads/Demon/src/core/Token.c:271Required for impersonating tokens:

Token Enumeration

Havoc can enumerate all accessible tokens on the system: Source: payloads/Demon/src/core/Token.c:1130

Token Validation

Source: payloads/Demon/src/core/Token.c:802

Token Metadata Extraction

Source: payloads/Demon/src/core/Token.c:103

OPSEC Considerations

Detection Vectors:
  1. Handle Duplication: Duplicating tokens from other processes generates ObRegisterCallbacks events
  2. Token Enumeration: Querying all system handles is highly anomalous
  3. Impersonation Events: Thread impersonation can trigger ETW events
  4. Privilege Changes: Enabling SeDebugPrivilege is a common IoC
  5. Credential Use: LogonUserW generates Windows Event ID 4624

Stealth Recommendations

  1. Targeted Stealing: Only steal tokens from specific processes, not enumerate all
  2. Legitimate Processes: Target tokens from expected service accounts
  3. Short Duration: Minimize time spent impersonating
  4. Clean Vault: Remove tokens after use with token clear

Vault Management

Adding Tokens

Source: payloads/Demon/src/core/Token.c:323

Removing Tokens

Source: payloads/Demon/src/core/Token.c:474 Tokens are securely removed from the vault with memory zeroing:
  • Indirect Syscalls - Used for all token operations
  • Process injection with stolen tokens
  • Kerberos ticket extraction and injection

References

  • Token implementation: payloads/Demon/src/core/Token.c
  • Header definitions: payloads/Demon/include/core/Token.h
  • Syscall usage: payloads/Demon/src/core/Syscalls.c