Skip to main content

Overview

The token command implements a comprehensive token management system that allows operators to steal, store, impersonate, and create Windows access tokens. All stolen tokens are preserved in a token vault for later use.

Token Vault

Tokens are duplicated with SecurityIdentification and SecurityImpersonate privileges, allowing OpenThreadToken to work on impersonated UIDs with OpenAsSelf set to TRUE.

Syntax

Subcommands

getuid

Display the current user context from the active token.
string
Current user in DOMAIN\username format
string
Security Identifier (SID) of the current user
string
Token type: Primary or Impersonation

list

Display all tokens currently stored in the token vault.
array
integer
Vault ID for the token (used for impersonation)
string
User associated with the token
string
Domain or computer name
string
Token type (Primary or Impersonation)
string
Impersonation level (SecurityAnonymous, SecurityIdentification, SecurityImpersonation, SecurityDelegation)

find-tokens

Enumerate all accessible tokens on the system that can be stolen.
Scans running processes and identifies tokens that can be duplicated.
array
integer
Process ID containing the token
string
Process name
string
User context of the token
integer
Session ID

steal

Steal a token from a specified process and add it to the vault.
integer
required
Process identifier to steal token from
hex
Specific token handle to duplicate (optional, defaults to primary token)

impersonate

Impersonate a token from the vault.
integer
required
Token vault ID (from token list)

make

Create a new token from credentials and add it to the vault.
string
required
Domain name or computer name for local accounts
string
required
Username for authentication
string
required
Password for authentication
integer
default:"9"
Windows logon type:
  • 2 - Interactive (LOGON32_LOGON_INTERACTIVE)
  • 3 - Network (LOGON32_LOGON_NETWORK)
  • 4 - Batch (LOGON32_LOGON_BATCH)
  • 5 - Service (LOGON32_LOGON_SERVICE)
  • 9 - NewCredentials (LOGON32_LOGON_NEW_CREDENTIALS) - Default

privs-get

Attempt to enable all privileges on the current token.
Attempts to enable:
  • SeDebugPrivilege
  • SeImpersonatePrivilege
  • SeTcbPrivilege
  • And all other available privileges

privs-list

List all privileges and their status for the current token.
array
string
Privilege name (e.g., SeDebugPrivilege)
string
Enabled or Disabled
string
Human-readable description of the privilege

revert

Revert to the original process token.
Stops impersonating any token and returns to the default process token.

remove

Remove a token from the vault.
integer
required
Token vault ID to remove

clear

Remove all tokens from the vault.
Clears the entire token vault and reverts to the original process token.

Examples

Basic Token Theft and Impersonation

Create Token from Credentials

Privilege Escalation

Multiple Token Management

Cleanup

OPSEC Considerations

Token operations can generate significant security events and may be monitored by EDR solutions.

Token Theft Detection

  • Opening process handles (especially to LSASS) triggers monitoring
  • OpenProcessToken and DuplicateTokenEx are commonly hooked
  • Consider using indirect syscalls for token operations
  • Avoid repeatedly accessing sensitive processes

Impersonation Detection

  • Thread token changes may be logged by security products
  • Some actions while impersonating generate events with the impersonated user
  • Network authentication will use the impersonated context

Best Practices

  1. Selective Theft: Only steal tokens you need
  2. Clean Up: Remove tokens from vault when done
  3. Verification: Always verify context with token getuid after impersonation
  4. Revert: Use token revert when impersonation is no longer needed
  5. Privilege Management: Only enable required privileges, not all

Use Cases

Lateral Movement

Privilege Escalation

Credential-Based Access

Token Types

Represents the security context of a process.
  • Associated with processes
  • Contains user SID, groups, privileges
  • Used for process-level access checks

Impersonation Levels

  • SecurityAnonymous (0): Server cannot impersonate or identify client
  • SecurityIdentification (1): Server can obtain identity and privileges but cannot impersonate
  • SecurityImpersonation (2): Server can impersonate client’s security context on local system
  • SecurityDelegation (3): Server can impersonate client’s security context on remote systems

Notes

  • Token vault is maintained per-agent session
  • Tokens do not persist across agent restarts
  • Impersonation affects the current thread only
  • Network operations use the impersonated token automatically
  • Some operations require specific privileges (e.g., SeDebugPrivilege for stealing from protected processes)
  • Delegation-level tokens are rare and valuable for remote access