Overview
Thetoken command implements a comprehensive token management system that allows operators to steal, store, impersonate, and create Windows access tokens. All stolen tokens are preserved in a token vault for later use.
Token Vault
Tokens are duplicated withSecurityIdentification and SecurityImpersonate privileges, allowing OpenThreadToken to work on impersonated UIDs with OpenAsSelf set to TRUE.
Syntax
Subcommands
getuid
Display the current user context from the active token.string
Current user in DOMAIN\username format
string
Security Identifier (SID) of the current user
string
Token type: Primary or Impersonation
list
Display all tokens currently stored in the token vault.array
find-tokens
Enumerate all accessible tokens on the system that can be stolen.array
steal
Steal a token from a specified process and add it to the vault.integer
required
Process identifier to steal token from
hex
Specific token handle to duplicate (optional, defaults to primary token)
impersonate
Impersonate a token from the vault.integer
required
Token vault ID (from
token list)make
Create a new token from credentials and add it to the vault.string
required
Domain name or computer name for local accounts
string
required
Username for authentication
string
required
Password for authentication
integer
default:"9"
Windows logon type:
2- Interactive (LOGON32_LOGON_INTERACTIVE)3- Network (LOGON32_LOGON_NETWORK)4- Batch (LOGON32_LOGON_BATCH)5- Service (LOGON32_LOGON_SERVICE)9- NewCredentials (LOGON32_LOGON_NEW_CREDENTIALS) - Default
privs-get
Attempt to enable all privileges on the current token.- SeDebugPrivilege
- SeImpersonatePrivilege
- SeTcbPrivilege
- And all other available privileges
privs-list
List all privileges and their status for the current token.array
revert
Revert to the original process token.remove
Remove a token from the vault.integer
required
Token vault ID to remove
clear
Remove all tokens from the vault.Examples
Basic Token Theft and Impersonation
Create Token from Credentials
Privilege Escalation
Multiple Token Management
Cleanup
OPSEC Considerations
Token Theft Detection
- Opening process handles (especially to LSASS) triggers monitoring
OpenProcessTokenandDuplicateTokenExare commonly hooked- Consider using indirect syscalls for token operations
- Avoid repeatedly accessing sensitive processes
Impersonation Detection
- Thread token changes may be logged by security products
- Some actions while impersonating generate events with the impersonated user
- Network authentication will use the impersonated context
Best Practices
- Selective Theft: Only steal tokens you need
- Clean Up: Remove tokens from vault when done
- Verification: Always verify context with
token getuidafter impersonation - Revert: Use
token revertwhen impersonation is no longer needed - Privilege Management: Only enable required privileges, not all
Use Cases
Lateral Movement
Privilege Escalation
Credential-Based Access
Token Types
- Primary Token
- Impersonation Token
Represents the security context of a process.
- Associated with processes
- Contains user SID, groups, privileges
- Used for process-level access checks
Impersonation Levels
- SecurityAnonymous (0): Server cannot impersonate or identify client
- SecurityIdentification (1): Server can obtain identity and privileges but cannot impersonate
- SecurityImpersonation (2): Server can impersonate client’s security context on local system
- SecurityDelegation (3): Server can impersonate client’s security context on remote systems
Notes
- Token vault is maintained per-agent session
- Tokens do not persist across agent restarts
- Impersonation affects the current thread only
- Network operations use the impersonated token automatically
- Some operations require specific privileges (e.g.,
SeDebugPrivilegefor stealing from protected processes) - Delegation-level tokens are rare and valuable for remote access
