[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frDhhRxrN5g_kqkLxCcZIYrZJZYJAe1G7WYHgOZEb2mM":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},579,"How can I automate hidden account creation using PowerShell scripts, and what permissions are needed?","PowerShell scripts can automate the process by first gaining edit permissions on the SAM registry. One approach uses `regini` with an ini file to grant full access to Administrators and System. Another method employs token manipulation to obtain System privileges—using Invoke-TokenManipulation.ps1 to spawn a cmd.exe process as SYSTEM—then script the export, replacement, and import of registry keys. The script from Evilcg (e.g., `Create-Clone.ps1`) provides a full implementation, as referenced in the article.","\u003Cp>PowerShell scripts can automate the process by first gaining edit permissions on the SAM registry. One approach uses `regini` with an ini file to grant full access to Administrators and System. Another method employs token manipulation to obtain System privileges—using Invoke-TokenManipulation.ps1 to spawn a cmd.exe process as SYSTEM—then script the export, replacement, and import of registry keys. The script from Evilcg (e.g., `Create-Clone.ps1`) provides a full implementation, as referenced in the article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-account-hiding-in-windows-systems\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-automate-hidden-account-creation-using-powershell-scripts-and-what-per-1777483054843","PowerShell, automation, token manipulation, regini, System privileges",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},143,"Penetration Techniques - Account Hiding in Windows Systems","penetration-techniques-account-hiding-in-windows-systems","Learn advanced Windows account hiding via registry cloning, combined with remote desktop multi-user login exploitation techniques for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Penetration Techniques - Multi-User Login for Windows System Remote Desktop,' we discussed the exploitation techniques for Windows system remote desktop, achieving multi-user remote login on non-server versions of Windows. Recently, Evilcg and I have researched the exploitation techniques for hidden accounts through account cloning. What exploitation techniques can be achieved by combining these two? This article will introduce them one by one.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for account hiding\u003C\u002Fli>\u003Cli>Script implementation approach\u003C\u002Fli>\u003Cli>Exploitation ideas combined with remote desktop multi-user login\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for Account Hiding\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method has been documented online; this section will only briefly reproduce it.\u003C\u002Fp>\u003Cp>Test system: Win7x86\u003C\u002Fp>\u003Ch3>1. Granting permissions to the registry\u003C\u002Fh3>\u003Cp>The default registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\ can only be modified with system privileges.\u003C\u002Fp>\u003Cp>Now it is necessary to add administrator permissions to it.\u003C\u002Fp>\u003Cp>Right-click - Permissions - Select Administrators, allow full control.\u003C\u002Fp>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017969127_0_85b9543015.jpeg\">\u003C\u002Fp>\u003Cp>Restart the registry editor regedit.exe to gain modification permissions for this key.\u003C\u002Fp>\u003Ch3>2. Create a special account\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$ 123456 \u002Fadd\u003Cbr>net localgroup administrators test$ \u002Fadd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The username must end with $.\u003C\u002Fp>\u003Cp>After adding, this account can be hidden under certain conditions; entering net user cannot retrieve it, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975550_1_1ea4a0bbd0.jpeg\">\u003C\u002Fp>\u003Cp>However, the account can be discovered in the Control Panel.\u003C\u002Fp>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017986090_2_ecfa7f77e9.jpeg\">\u003C\u002Fp>\u003Ch3>3. Export the registry\u003C\u002Fh3>\u003Cp>Locate the newly created account test$ under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names\u003C\u002Fp>\u003Cp>Obtain the default type 0x3ea\u003C\u002Fp>\u003Cp>Export the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names\\test$ as 1.reg\u003C\u002Fp>\u003Cp>Find the corresponding registry entry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003EA under the registry based on the type name\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017990587_3_fea26cb48f.jpeg\">\u003C\u002Fp>\u003Cp>Right-click and export this key as 2.reg; the saved file information is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017995111_4_e2d592de40.jpeg\">\u003C\u002Fp>\u003Cp>By default, the registry key value corresponding to the administrator account Administrator is HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000001F4\u003C\u002Fp>\u003Cp>Similarly, right-click and export this key as 3.reg\u003C\u002Fp>\u003Cp>Replace the value of key F under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003EA with the value of key F under HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000001F4, i.e., replace the value of key F in 2.reg with the value of key F in 3.reg\u003C\u002Fp>\u003Cp>After replacement, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017998266_5_224ebc074e.jpeg\">\u003C\u002Fp>\u003Ch3>4. Delete special account via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$ \u002Fdel\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Import registry files\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regedit \u002Fs 1.reg\u003Cbr>regedit \u002Fs 2.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Hidden account creation completed. Account test$ does not appear in Control Panel\u003C\u002Fp>\u003Cp>The account cannot be listed via net user\u003C\u002Fp>\u003Cp>The account also cannot be listed in Computer Management - Local Users and Groups - Users\u003C\u002Fp>\u003Cp>But it can be viewed using the following method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018001607_6_f9960e3ce7.jpeg\">\u003C\u002Fp>\u003Cp>Cannot delete this user via net user test$ \u002Fdel, prompts 'user does not belong to this group', as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018007422_7_37203a62ab.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Deletion method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete the key values corresponding to the account under the registry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\ (there are two locations in total)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The tool HideAdmin can automatically perform the above creation and deletion operations\u003C\u002Fp>\u003Ch2>0x03 Script Implementation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Two approaches using PowerShell scripts:\u003C\u002Fp>\u003Ch3>1. Add edit permissions for the administrator account to the registry\u003C\u002Fh3>\u003Cp>Use regini to register an ini file to grant permissions to the registry and its subkeys\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Grant permissions to the registry using Set-Acl in PowerShell, example code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:SAM\\SAM\\\u003Cbr>$person = [System.Security.Principal.NTAccount]\"Administrators\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"NoPropagateInherit\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.ResetAccessRule($rule)\u003Cbr>Set-Acl HKLM:SAM\\SAM\\Domains\\Account\\Users\\Names $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, it does not support permission assignment for subkeys, so this method is not adopted.\u003C\u002Fp>\u003Cp>Save the following content as a.ini:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SAM\\SAM\\* [1 17]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>* represents enumerating all subkeys\u003C\u002Fp>\u003Cp>1 represents Administrators full access\u003C\u002Fp>\u003Cp>17 represents System full access\u003C\u002Fp>\u003Cp>Detailed permission descriptions can be obtained by executing regini in cmd for help, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018009891_8_fc86a3d980.jpeg\">\u003C\u002Fp>\u003Cp>Register via regini:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regini a.ini\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Evilcg implemented it this way, script address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FRidter\u002FPentest\u002Fblob\u002Fmaster\u002Fpowershell\u002FMyShell\u002FCreate-Clone.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using * requires system permissions, but only listing the relevant ones requires administrator permissions, for example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SAM [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names [1 17]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Directly obtain System permissions\u003C\u002Fh3>\u003Cp>In my previous article 'Penetration Techniques - Token Theft and Exploitation', I introduced the method of obtaining system permissions through token duplication\u003C\u002Fp>\u003Cp>Therefore, you can first obtain System permissions, thereby gaining editing rights to the registry\u003C\u002Fp>\u003Cp>A simple way is through Invoke-TokenManipulation.ps1, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-TokenManipulation.ps1\u003C\u002Fp>\u003Cp>However, during testing I discovered a bug: using Invoke-TokenManipulation -ImpersonateUser -Username \"nt authority\\system\" cannot switch the current privileges to System authority\u003C\u002Fp>\u003Cp>But you can use Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -Username \"nt authority\\system\" to open a new process with System privileges\u003C\u002Fp>\u003Cp>Next, write a script to implement the registry export and replacement functionality:\u003C\u002Fp>\u003Cul>\u003Cli>Create a test account\u003C\u002Fli>\u003Cli>Export the registry to the temp directory and perform replacement\u003C\u002Fli>\u003Cli>Delete the special account\u003C\u002Fli>\u003Cli>Import the registry file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>My implementation method refers to Evilcg's original version with detailed optimizations. Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach Combining Remote Desktop Multi-User Login\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From the above introduction, the advantages of this method can be summarized:\u003C\u002Fp>\u003Cp>\u003Cstrong>Cloning can inherit the permissions of the original account\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following issues need attention during exploitation:\u003C\u002Fp>\u003Ch3>1. Copy the Administrator account\u003C\u002Fh3>\u003Cp>Note whether the Administrator account is disabled. If disabled, the cloned hidden account will also be disabled\u003C\u002Fp>\u003Ch3>2. Copy an existing account\u003C\u002Fh3>\u003Cp>There is a conflict with duplicate accounts when utilizing 3389 remote login\u003C\u002Fp>\u003Cp>Enable the local 3389 remote login feature via cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" \u002Fv fDenyTSConnections \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003Cbr>REG ADD \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" \u002Fv PortNumber \u002Ft REG_DWORD \u002Fd 0x00000d3d \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Using the above method, clone the permissions of account a to create hidden account aaa$\u003C\u002Fp>\u003Cp>If the currently logged-in account on the system is a, logging in with hidden account aaa$ will cause the system to recognize it as account a, resulting in account a being logged out\u003C\u002Fp>\u003Ch3>3. Create a new account and then copy\u003C\u002Fh3>\u003Cp>Further, think boldly\u003C\u002Fp>\u003Cp>Create a new Administrator account b, clone account b, and establish hidden account bbb$\u003C\u002Fp>\u003Cp>Delete Administrator account b, and hidden account bbb$ remains effective\u003C\u002Fp>\u003Ch3>4. Maintenance of the original account\u003C\u002Fh3>\u003Cp>Go even further\u003C\u002Fp>\u003Cp>Clone the permissions of account a to create a hidden account aaa$\u003C\u002Fp>\u003Cp>Change the password of account a, the hidden account aaa$ remains valid\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To exploit hidden accounts, view the registry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\\u003C\u002Fp>\u003Cp>Of course, default administrator permissions cannot view it; you need to assign permissions or elevate to System privileges\u003C\u002Fp>\u003Cp>Login records of hidden accounts can be obtained by checking logs\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces related exploitation techniques for hidden accounts. If applied to multi-user login via remote desktop, stealthiness can be greatly improved. From a defensive perspective, sharing this exploitation method helps everyone better understand and defend against it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Penetration Techniques - Multi-User Login for Windows System Remote Desktop,' we discussed the exploitation techniques for Windows system remote desktop, achieving multi-user remote login on non-server versions of Windows. Recently, Evilcg and I have researched the exploitation techniques for hidden accounts through account cloning. What exploitation techniques can be achieved by combining these two? This article will introduce them one by one.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for account hiding\u003C\u002Fli>\u003Cli>Script implementation approach\u003C\u002Fli>\u003Cli>Exploitation ideas combined with remote desktop multi-user login\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for Account Hiding\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method has been documented online; this section will only briefly reproduce it.\u003C\u002Fp>\u003Cp>Test system: Win7x86\u003C\u002Fp>\u003Ch3>1. Granting permissions to the registry\u003C\u002Fh3>\u003Cp>The default registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\ can only be modified with system privileges.\u003C\u002Fp>\u003Cp>Now it is necessary to add administrator permissions to it.\u003C\u002Fp>\u003Cp>Right-click - Permissions - Select Administrators, allow full control.\u003C\u002Fp>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017969127_0_85b9543015-1.jpeg\">\u003C\u002Fp>\u003Cp>Restart the registry editor regedit.exe to gain modification permissions for this key.\u003C\u002Fp>\u003Ch3>2. Create a special account\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$ 123456 \u002Fadd\u003Cbr>net localgroup administrators test$ \u002Fadd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The username must end with $.\u003C\u002Fp>\u003Cp>After adding, this account can be hidden under certain conditions; entering net user cannot retrieve it, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975550_1_1ea4a0bbd0-1.jpeg\">\u003C\u002Fp>\u003Cp>However, the account can be discovered in the Control Panel.\u003C\u002Fp>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017986090_2_ecfa7f77e9-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Export the registry\u003C\u002Fh3>\u003Cp>Locate the newly created account test$ under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names\u003C\u002Fp>\u003Cp>Obtain the default type 0x3ea\u003C\u002Fp>\u003Cp>Export the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names\\test$ as 1.reg\u003C\u002Fp>\u003Cp>Find the corresponding registry entry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003EA under the registry based on the type name\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017990587_3_fea26cb48f-1.jpeg\">\u003C\u002Fp>\u003Cp>Right-click and export this key as 2.reg; the saved file information is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017995111_4_e2d592de40-1.jpeg\">\u003C\u002Fp>\u003Cp>By default, the registry key value corresponding to the administrator account Administrator is HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000001F4\u003C\u002Fp>\u003Cp>Similarly, right-click and export this key as 3.reg\u003C\u002Fp>\u003Cp>Replace the value of key F under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003EA with the value of key F under HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000001F4, i.e., replace the value of key F in 2.reg with the value of key F in 3.reg\u003C\u002Fp>\u003Cp>After replacement, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017998266_5_224ebc074e-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Delete special account via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$ \u002Fdel\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Import registry files\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regedit \u002Fs 1.reg\u003Cbr>regedit \u002Fs 2.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Hidden account creation completed. Account test$ does not appear in Control Panel\u003C\u002Fp>\u003Cp>The account cannot be listed via net user\u003C\u002Fp>\u003Cp>The account also cannot be listed in Computer Management - Local Users and Groups - Users\u003C\u002Fp>\u003Cp>But it can be viewed using the following method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018001607_6_f9960e3ce7-1.jpeg\">\u003C\u002Fp>\u003Cp>Cannot delete this user via net user test$ \u002Fdel, prompts 'user does not belong to this group', as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018007422_7_37203a62ab-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Deletion method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete the key values corresponding to the account under the registry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\ (there are two locations in total)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The tool HideAdmin can automatically perform the above creation and deletion operations\u003C\u002Fp>\u003Ch2>0x03 Script Implementation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Two approaches using PowerShell scripts:\u003C\u002Fp>\u003Ch3>1. Add edit permissions for the administrator account to the registry\u003C\u002Fh3>\u003Cp>Use regini to register an ini file to grant permissions to the registry and its subkeys\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Grant permissions to the registry using Set-Acl in PowerShell, example code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:SAM\\SAM\\\u003Cbr>$person = [System.Security.Principal.NTAccount]\"Administrators\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"NoPropagateInherit\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.ResetAccessRule($rule)\u003Cbr>Set-Acl HKLM:SAM\\SAM\\Domains\\Account\\Users\\Names $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, it does not support permission assignment for subkeys, so this method is not adopted.\u003C\u002Fp>\u003Cp>Save the following content as a.ini:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SAM\\SAM\\* [1 17]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>* represents enumerating all subkeys\u003C\u002Fp>\u003Cp>1 represents Administrators full access\u003C\u002Fp>\u003Cp>17 represents System full access\u003C\u002Fp>\u003Cp>Detailed permission descriptions can be obtained by executing regini in cmd for help, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018009891_8_fc86a3d980-1.jpeg\">\u003C\u002Fp>\u003Cp>Register via regini:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regini a.ini\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Evilcg implemented it this way, script address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FRidter\u002FPentest\u002Fblob\u002Fmaster\u002Fpowershell\u002FMyShell\u002FCreate-Clone.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using * requires system permissions, but only listing the relevant ones requires administrator permissions, for example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SAM [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names [1 17]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Directly obtain System permissions\u003C\u002Fh3>\u003Cp>In my previous article 'Penetration Techniques - Token Theft and Exploitation', I introduced the method of obtaining system permissions through token duplication\u003C\u002Fp>\u003Cp>Therefore, you can first obtain System permissions, thereby gaining editing rights to the registry\u003C\u002Fp>\u003Cp>A simple way is through Invoke-TokenManipulation.ps1, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-TokenManipulation.ps1\u003C\u002Fp>\u003Cp>However, during testing I discovered a bug: using Invoke-TokenManipulation -ImpersonateUser -Username \"nt authority\\system\" cannot switch the current privileges to System authority\u003C\u002Fp>\u003Cp>But you can use Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -Username \"nt authority\\system\" to open a new process with System privileges\u003C\u002Fp>\u003Cp>Next, write a script to implement the registry export and replacement functionality:\u003C\u002Fp>\u003Cul>\u003Cli>Create a test account\u003C\u002Fli>\u003Cli>Export the registry to the temp directory and perform replacement\u003C\u002Fli>\u003Cli>Delete the special account\u003C\u002Fli>\u003Cli>Import the registry file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>My implementation method refers to Evilcg's original version with detailed optimizations. Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach Combining Remote Desktop Multi-User Login\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From the above introduction, the advantages of this method can be summarized:\u003C\u002Fp>\u003Cp>\u003Cstrong>Cloning can inherit the permissions of the original account\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following issues need attention during exploitation:\u003C\u002Fp>\u003Ch3>1. Copy the Administrator account\u003C\u002Fh3>\u003Cp>Note whether the Administrator account is disabled. If disabled, the cloned hidden account will also be disabled\u003C\u002Fp>\u003Ch3>2. Copy an existing account\u003C\u002Fh3>\u003Cp>There is a conflict with duplicate accounts when utilizing 3389 remote login\u003C\u002Fp>\u003Cp>Enable the local 3389 remote login feature via cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" \u002Fv fDenyTSConnections \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003Cbr>REG ADD \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" \u002Fv PortNumber \u002Ft REG_DWORD \u002Fd 0x00000d3d \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Using the above method, clone the permissions of account a to create hidden account aaa$\u003C\u002Fp>\u003Cp>If the currently logged-in account on the system is a, logging in with hidden account aaa$ will cause the system to recognize it as account a, resulting in account a being logged out\u003C\u002Fp>\u003Ch3>3. Create a new account and then copy\u003C\u002Fh3>\u003Cp>Further, think boldly\u003C\u002Fp>\u003Cp>Create a new Administrator account b, clone account b, and establish hidden account bbb$\u003C\u002Fp>\u003Cp>Delete Administrator account b, and hidden account bbb$ remains effective\u003C\u002Fp>\u003Ch3>4. Maintenance of the original account\u003C\u002Fh3>\u003Cp>Go even further\u003C\u002Fp>\u003Cp>Clone the permissions of account a to create a hidden account aaa$\u003C\u002Fp>\u003Cp>Change the password of account a, the hidden account aaa$ remains valid\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To exploit hidden accounts, view the registry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\\u003C\u002Fp>\u003Cp>Of course, default administrator permissions cannot view it; you need to assign permissions or elevate to System privileges\u003C\u002Fp>\u003Cp>Login records of hidden accounts can be obtained by checking logs\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces related exploitation techniques for hidden accounts. If applied to multi-user login via remote desktop, stealthiness can be greatly improved. From a defensive perspective, sharing this exploitation method helps everyone better understand and defend against it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",955,"Onedaysec",6,"published","2026-02-02T07:51:00.061Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows Account Hiding & Remote Desktop Exploitation Techniques","Windows account hiding, penetration testing, registry cloning, hidden accounts, remote desktop exploitation, PowerShell scripts, SAM registry, account security, Windows 7, Evilcg",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],581,580,578,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.583Z","2026-07-23T16:01:46.737Z","draft","2026-07-23T16:13:30.944Z"]