Abusing Windows’ tokens to compromise Active Directory without touching LSASS
ID: e01ed5bc-b940-5663-a79b-fa42c1df468f
STIX ID: report--e01ed5bc-b940-5663-a79b-fa42c1df468f
Feed Name: SensePost Blog
This technical write-up demonstrates how to compromise a Windows AD environment by abusing access token manipulation rather than dumping LSASS, moving from local admin to SYSTEM and then to a logged-in domain admin via token duplication, impersonation, and session ID modification. It explains token types, privileges (e.g., SeImpersonate, SeTCB), and sessions, and shows practical use of ImpersonateLoggedOnUser, CreateProcessWithTokenW, and CreateProcessAsUserW. The author releases an accompanying Impersonate tool and a CrackMapExec module to automate listing, impersonation, command execution, and domain user creation, noting that common EDRs failed to prevent the technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
