logo

Abusing Windows’ tokens to compromise Active Directory without touching LSASS

ID: e01ed5bc-b940-5663-a79b-fa42c1df468f

STIX ID: report--e01ed5bc-b940-5663-a79b-fa42c1df468f

Feed Name: SensePost Blog

Date Published: 2022-10-27

Date Updated: 2026-04-30

...
...

This technical write-up demonstrates how to compromise a Windows AD environment by abusing access token manipulation rather than dumping LSASS, moving from local admin to SYSTEM and then to a logged-in domain admin via token duplication, impersonation, and session ID modification. It explains token types, privileges (e.g., SeImpersonate, SeTCB), and sessions, and shows practical use of ImpersonateLoggedOnUser, CreateProcessWithTokenW, and CreateProcessAsUserW. The author releases an accompanying Impersonate tool and a CrackMapExec module to automate listing, impersonation, command execution, and domain user creation, noting that common EDRs failed to prevent the technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.