Overview
Havoc implements a comprehensive token management system that allows operators to steal, store, and impersonate Windows access tokens. This enables privilege escalation, lateral movement, and operating under different security contexts.The token vault maintains a linked list of stolen and created tokens that persist across commands, allowing operators to switch between security contexts on demand.
Token Vault Architecture
The token vault is a linked list structure that stores token metadata: Source:payloads/Demon/include/core/Token.h:80
Token Operations
Stealing Tokens
Tokens can be stolen from running processes usingNtOpenProcessToken or NtDuplicateObject:
Source: payloads/Demon/src/core/Token.c:414
Usage Example
Usage Example
Make Token
Create tokens from credentials usingLogonUserW:
Source: payloads/Demon/src/core/Token.c:598
LOGON32_LOGON_NEW_CREDENTIALS(9): Network credentials only (likerunas /netonly)LOGON32_LOGON_INTERACTIVE(2): Full interactive logonLOGON32_LOGON_NETWORK(3): Network logon
Token Duplication
Tokens are duplicated to create impersonation tokens: Source:payloads/Demon/src/core/Token.c:37
Impersonation
Tokens are applied to the current thread usingNtSetInformationThread:
Source: payloads/Demon/src/core/Token.c:1281
Reverting Impersonation
Remove thread impersonation: Source:payloads/Demon/src/core/Token.c:74
Privilege Management
Havoc can enable/disable token privileges: Source:payloads/Demon/src/core/Token.c:203
Common Privileges
SeDebugPrivilege
SeDebugPrivilege
Source:
payloads/Demon/src/core/Token.c:240Enables opening handles to any process:SeImpersonatePrivilege
SeImpersonatePrivilege
Source:
payloads/Demon/src/core/Token.c:271Required for impersonating tokens:Token Enumeration
Havoc can enumerate all accessible tokens on the system: Source:payloads/Demon/src/core/Token.c:1130
Token Validation
Source:payloads/Demon/src/core/Token.c:802
Token Metadata Extraction
Source:payloads/Demon/src/core/Token.c:103
OPSEC Considerations
Stealth Recommendations
- Targeted Stealing: Only steal tokens from specific processes, not enumerate all
- Legitimate Processes: Target tokens from expected service accounts
- Short Duration: Minimize time spent impersonating
- Clean Vault: Remove tokens after use with
token clear
Vault Management
Adding Tokens
Source:payloads/Demon/src/core/Token.c:323
Removing Tokens
Source:payloads/Demon/src/core/Token.c:474
Tokens are securely removed from the vault with memory zeroing:
Related Techniques
- Indirect Syscalls - Used for all token operations
- Process injection with stolen tokens
- Kerberos ticket extraction and injection
References
- Token implementation:
payloads/Demon/src/core/Token.c - Header definitions:
payloads/Demon/include/core/Token.h - Syscall usage:
payloads/Demon/src/core/Syscalls.c
