[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuMXUDcNCX5o7IVFfxk_teniWhqlM4fxnukn-bAw2-bo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1073,"What is the recommended universal method for privilege reduction from SYSTEM to a normal user, and what tool helps identify suitable parent processes?","The universal method is using SelectMyParent to spawn a process as a child of a process already running with the target user's privileges. To find such a parent, you can use `tasklist \u002Fv \u002Ffo list \u002Ffi \"USERNAME eq \u003Cwhoami output>\"` or a custom C++ tool that differentiates between admin and standard user processes. The article includes a small tool for traversing and judging process permissions (admin or not), which is especially useful because `tasklist` alone cannot distinguish between administrator and standard user tokens. This combined approach reliably reduces privileges from SYSTEM.","\u003Cp>The universal method is using SelectMyParent to spawn a process as a child of a process already running with the target user&#39;s privileges. To find such a parent, you can use `tasklist \u002Fv \u002Ffo list \u002Ffi &quot;USERNAME eq &lt;whoami output&gt;&quot;` or a custom C++ tool that differentiates between admin and standard user processes. The article includes a small tool for traversing and judging process permissions (admin or not), which is especially useful because `tasklist` alone cannot distinguish between administrator and standard user tokens. This combined approach reliably reduces privileges from SYSTEM.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-program-privilege-reduction-startup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-recommended-universal-method-for-privilege-reduction-from-system-to--1777480888019","SelectMyParent, process permission tool, tasklist, admin vs standard user, universal privilege reduction",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},261,"Penetration Techniques - Program Privilege Reduction Startup","penetration-techniques-program-privilege-reduction-startup","Learn methods to reduce program privileges from SYSTEM to standard user in penetration testing, including tools like runas, lsrunas, CPAU, and SelectMyParent.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, situations often arise where it is necessary to change the startup privileges of a program (divided into privilege escalation and privilege reduction).\u003C\u002Fp>\u003Cp>Privilege escalation includes moving from ordinary user privileges to administrator privileges and from administrator privileges to SYSTEM privileges. Privilege reduction in penetration testing typically refers to dropping from SYSTEM privileges to ordinary user privileges (dropping from administrator to ordinary user is relatively simple with many methods). This is often done to operate on the current user's files (such as capturing the desktop, manipulating the registry, etc.).\u003C\u002Fp>\u003Cp>This article will introduce specific methods for privilege reduction (from SYSTEM to ordinary user), clarify key points, and open-source a small tool for determining process privileges.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Why reduce privileges?\u003C\u002Fli>\u003Cli>Methods to drop from administrator to ordinary user privileges\u003C\u002Fli>\u003Cli>Methods to drop from SYSTEM to ordinary user privileges\u003C\u002Fli>\u003Cli>Using SelectMyParent to achieve privilege escalation and reduction\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test System: Win7\u003C\u002Fp>\u003Ch2>0x02 Why De-escalate Privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Processes running with system privileges may encounter the following issues:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Unable to access the current user's file content\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For example, unable to capture the user's screen\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Differences in environment variables\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Such as the following environment variables:\u003C\u002Fp>\u003Cul>\u003Cli>APPDATA\u003C\u002Fli>\u003Cli>Temp\u003C\u002Fli>\u003Cli>Tmp\u003C\u002Fli>\u003Cli>USERDOMAIN\u003C\u002Fli>\u003Cli>USERNAME\u003C\u002Fli>\u003Cli>USERPROFILE\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In cmd, environment variables can be viewed using echo, for example, the command to view the APPDATA environment variable is:\u003C\u002Fp>\u003Cp>echo %appdata%\u003C\u002Fp>\u003Cp>Under SYSTEM privileges, the queried environment variable APPDATA is C:\\Windows\\system32\\config\\systemprofile\\AppData\\Roaming\u003C\u002Fp>\u003Cp>Under administrator privileges, the queried environment variable APPDATA is C:\\Users\\a\\AppData\\Roaming\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015592140_0_8a7a530533.jpeg\">\u003C\u002Fp>\u003Cp>Using the API SHGetSpecialFolderPath to retrieve specified system paths, such as APPDATA, also reveals differences caused by varying privileges\u003C\u002Fp>\u003Cp>C++ code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#include \u003Cshlobj.h>\u003Cbr>\u003Cbr>bool IsSystemPrivilegeCmp()\u003Cbr>{\u003Cbr>    static bool isSystemPrivilege = false;\u003Cbr>\tchar *flag=\"C:\\\\Windows\";\u003Cbr>    if (isSystemPrivilege)\u003Cbr>    {\u003Cbr>        return isSystemPrivilege;\u003Cbr>    }\u003Cbr>    char szPath[MAX_PATH] = {0};\u003Cbr>    if (SHGetSpecialFolderPathA(NULL, szPath, CSIDL_APPDATA, TRUE))\u003Cbr>    {\u003Cbr>        printf(\"APPDATA Path:%s\\n\",szPath);\u003Cbr>\t\tif(memcmp(szPath,flag,strlen(flag))==0)\u003Cbr>\t\t\tprintf(\"[+]I'm System Privilege\\n\");\u003Cbr>\t\telse\u003Cbr>\t\t\tprintf(\"[-]Not System Privilege\\n\");\u003Cbr>    }\u003Cbr>    return isSystemPrivilege;\u003Cbr>}\u003Cbr>\u003Cbr>int main(int argc, CHAR* argv[])\u003Cbr>{\u003Cbr>\tIsSystemPrivilegeCmp();\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fshlobj.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015595809_1_424c0032d3.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>System paths supported by SHGetSpecialFolderPath can be obtained from Shlobj.h\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015598462_2_9b5a692c5c.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Registry differences\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some registry operations on HKCU will be redirected to HKEY_USERS\\.DEFAULT\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015600833_3_ee06b7e0ca.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Methods to downgrade from administrator to standard user privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. runas\u003C\u002Fh3>\u003Cp>cmd：\u003C\u002Fp>\u003Cp>runas \u002Fuser:a calc.exe\u003C\u002Fp>\u003Cp>Then enter password: 123456\u003C\u002Fp>\u003Cp>calc.exe runs with user a's privileges\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015603669_4_73918137de.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires waiting for manual password entry, lacks automation\u003C\u002Fp>\u003Cp>However, automatic password input can be achieved via piping, requiring third-party tool Sanur (method not detailed here)\u003C\u002Fp>\u003Ch3>2. Third-party tool: lsrunas\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.verydoc.com\u002Fexeshell.html\u003C\u002Fp>\u003Cp>cmd：\u003C\u002Fp>\u003Cp>lsrunas.exe \u002Fuser:a \u002Fpassword:123456 \u002Fdomain: \u002Fcommand:\"calc.exe\" \u002Frunpath:c:\\\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u002Fdomain: Empty parameter indicates the local machine\u003C\u002Fp>\u003Cp>Successfully downgraded from administrator privileges to standard user privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015606380_5_1ddb4d229c.jpeg\">\u003C\u002Fp>\u003Ch3>3. Third-party tool: CPAU\u003C\u002Fh3>\u003Cp>Download address can be referenced from my GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>CPAU.exe -u a -p 123456 -ex \"calc.exe\" -cwd c:\\windows\\system32 -lwp\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The parameter -lwp or -lwop must be added, otherwise privilege downgrade cannot be achieved\u003C\u002Fp>\u003Cp>Successfully downgraded from administrator privileges to standard user privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015607971_6_bdbd4771f8.jpeg\">\u003C\u002Fp>\u003Ch3>4. PowerShell\u003C\u002Fh3>\u003Cp>Code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"a\"\u003Cbr>$pwd=ConvertTo-SecureString  \"123456\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Start-Process -FilePath  \"calc.exe\" -Credential $cred  \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5、c++\u003C\u002Fh3>\u003Cp>Using API:\u003C\u002Fp>\u003Cul>\u003Cli>CreateProcessAsUser\u003C\u002Fli>\u003Cli>CreateProcess\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Methods to downgrade from system privileges to normal user privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The system privileges in this test were obtained through a vulnerability\u003C\u002Fp>\u003Ch3>1、runas\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>runas \u002Fuser:a calc.exe\u003C\u002Fp>\u003Cp>Then enter the password: 123456\u003C\u002Fp>\u003Cp>Successfully downgraded privileges, but failed to start, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015610366_7_59e7e16010.jpeg\">\u003C\u002Fp>\u003Ch3>2. Third-party tool: lsrunas\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>lsrunas.exe \u002Fuser:a \u002Fpassword:123456 \u002Fdomain: \u002Fcommand:\"calc.exe\" \u002Frunpath:c:\\\u003C\u002Fp>\u003Cp>Same as above, successfully downgraded privileges, but failed to start\u003C\u002Fp>\u003Ch3>3. Third-party tool: CPAU\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>CPAU.exe -u a -p 123456 -ex \"calc.exe\" -lwp\u003C\u002Fp>\u003Cp>CPAU does not support starting with system privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015612224_8_246d5a6c72.jpeg\">\u003C\u002Fp>\u003Ch3>4. powershell\u003C\u002Fh3>\u003Cp>Same as 1, successfully downgraded privileges, but failed to start\u003C\u002Fp>\u003Ch3>5. c++\u003C\u002Fh3>\u003Cp>Didier Stevens' tool SelectMyParent can be used\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The code is not yet shared on GitHub, so I have uploaded it to my GitHub repository, crediting the author as Didier Stevens\u003C\u002Fp>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>SelectMyParent:\u003C\u002Fh3>\u003Cp>Used to create a Windows process with a selected parent process\u003C\u002Fp>\u003Cp>For example: When creating a new process calc.exe, using SelectMyParent allows setting the new process calc.exe as a child process of winlogon.exe\u003C\u002Fp>\u003Cp>Usage steps:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtain the PID of process winlogon.exe\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In my test system, the PID of process winlogon.exe is 504\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Launch SelectMyParent\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Parameters as follows:\u003C\u002Fp>\u003Cp>SelectMyParent.exe calc.exe 504\u003C\u002Fp>\u003Cp>Shows calc.exe as a child process of winlogon.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015613550_9_953c3c7c4d.jpeg\">\u003C\u002Fp>\u003Cp>This method can primarily be used to enhance process stealth and deceive users\u003C\u002Fp>\u003Cp>\u003Cstrong>Special aspects:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since child processes inherit the permissions of the parent process, and winlogon.exe has system-level permissions, its child process calc.exe will also acquire system-level permissions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015615166_10_69f1561dfd.jpeg\">\u003C\u002Fp>\u003Cp>That is to say, based on SelectMyParent, we can implement the following privilege escalation and de-escalation operations:\u003C\u002Fp>\u003Cul>\u003Cli>Privilege escalation: From administrator privileges to system privileges\u003C\u002Fli>\u003Cli>Privilege de-escalation: From system privileges to admin privileges\u003C\u002Fli>\u003Cli>Privilege de-escalation: From system privileges to standard user privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Operation steps:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtain the process PID\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Method to obtain process PID in cmd:\u003C\u002Fp>\u003Cp>tasklist \u002Fv \u002Ffo list\u003C\u002Fp>\u003Cp>Can retrieve the corresponding PID and permissions (indicated by the username value) for each process, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015616233_11_f319d3e766.jpeg\">\u003C\u002Fp>\u003Cp>For testing convenience, filtering can be used to select processes with specific permissions, such as filtering NT AUTHORITY\\SYSTEM.\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>tasklist \u002Fv \u002Ffo list \u002Ffi \"USERNAME eq NT AUTHORITY\\SYSTEM\"\u003C\u002Fp>\u003Cp>If obtaining processes with regular user permissions, the USERNAME filter can be set to the return result of whoami.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Using SelectMyParent.exe\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>From administrator permissions to system permissions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As demonstrated earlier, no further introduction is needed.\u003C\u002Fp>\u003Cp>\u003Cstrong>From system permissions to admin permissions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using tasklist cannot distinguish whether a process has administrator or regular user permissions.\u003C\u002Fp>\u003Cp>Therefore, I wrote a small tool in C++ with the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Traverse processes\u003C\u002Fli>\u003Cli>Determine process permissions; if administrator permissions, mark them.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Tool usage is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015616591_12_23a66bf1c7.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>From SYSTEM Privileges to Standard User Privileges:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Select a standard user privilege process with PID 3864; the created calc.exe will also have standard user privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015617222_13_e5d8447780.jpeg\">\u003C\u002Fp>\u003Cp>Successfully achieved privilege reduction from SYSTEM to standard user\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests common privilege reduction methods, concluding that some methods may fail under certain conditions. The universal approach is to use SelectMyParent for privilege reduction.\u003C\u002Fp>\u003Cp>In practice, a small tool for traversing and judging process privileges has been open-sourced to improve efficiency.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, situations often arise where it is necessary to change the startup privileges of a program (divided into privilege escalation and privilege reduction).\u003C\u002Fp>\u003Cp>Privilege escalation includes moving from ordinary user privileges to administrator privileges and from administrator privileges to SYSTEM privileges. Privilege reduction in penetration testing typically refers to dropping from SYSTEM privileges to ordinary user privileges (dropping from administrator to ordinary user is relatively simple with many methods). This is often done to operate on the current user's files (such as capturing the desktop, manipulating the registry, etc.).\u003C\u002Fp>\u003Cp>This article will introduce specific methods for privilege reduction (from SYSTEM to ordinary user), clarify key points, and open-source a small tool for determining process privileges.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Why reduce privileges?\u003C\u002Fli>\u003Cli>Methods to drop from administrator to ordinary user privileges\u003C\u002Fli>\u003Cli>Methods to drop from SYSTEM to ordinary user privileges\u003C\u002Fli>\u003Cli>Using SelectMyParent to achieve privilege escalation and reduction\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test System: Win7\u003C\u002Fp>\u003Ch2>0x02 Why De-escalate Privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Processes running with system privileges may encounter the following issues:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Unable to access the current user's file content\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For example, unable to capture the user's screen\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Differences in environment variables\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Such as the following environment variables:\u003C\u002Fp>\u003Cul>\u003Cli>APPDATA\u003C\u002Fli>\u003Cli>Temp\u003C\u002Fli>\u003Cli>Tmp\u003C\u002Fli>\u003Cli>USERDOMAIN\u003C\u002Fli>\u003Cli>USERNAME\u003C\u002Fli>\u003Cli>USERPROFILE\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In cmd, environment variables can be viewed using echo, for example, the command to view the APPDATA environment variable is:\u003C\u002Fp>\u003Cp>echo %appdata%\u003C\u002Fp>\u003Cp>Under SYSTEM privileges, the queried environment variable APPDATA is C:\\Windows\\system32\\config\\systemprofile\\AppData\\Roaming\u003C\u002Fp>\u003Cp>Under administrator privileges, the queried environment variable APPDATA is C:\\Users\\a\\AppData\\Roaming\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015592140_0_8a7a530533-1.jpeg\">\u003C\u002Fp>\u003Cp>Using the API SHGetSpecialFolderPath to retrieve specified system paths, such as APPDATA, also reveals differences caused by varying privileges\u003C\u002Fp>\u003Cp>C++ code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#include \u003Cshlobj.h>\u003Cbr>\u003Cbr>bool IsSystemPrivilegeCmp()\u003Cbr>{\u003Cbr>    static bool isSystemPrivilege = false;\u003Cbr>\tchar *flag=\"C:\\\\Windows\";\u003Cbr>    if (isSystemPrivilege)\u003Cbr>    {\u003Cbr>        return isSystemPrivilege;\u003Cbr>    }\u003Cbr>    char szPath[MAX_PATH] = {0};\u003Cbr>    if (SHGetSpecialFolderPathA(NULL, szPath, CSIDL_APPDATA, TRUE))\u003Cbr>    {\u003Cbr>        printf(\"APPDATA Path:%s\\n\",szPath);\u003Cbr>\t\tif(memcmp(szPath,flag,strlen(flag))==0)\u003Cbr>\t\t\tprintf(\"[+]I'm System Privilege\\n\");\u003Cbr>\t\telse\u003Cbr>\t\t\tprintf(\"[-]Not System Privilege\\n\");\u003Cbr>    }\u003Cbr>    return isSystemPrivilege;\u003Cbr>}\u003Cbr>\u003Cbr>int main(int argc, CHAR* argv[])\u003Cbr>{\u003Cbr>\tIsSystemPrivilegeCmp();\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fshlobj.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015595809_1_424c0032d3-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>System paths supported by SHGetSpecialFolderPath can be obtained from Shlobj.h\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015598462_2_9b5a692c5c-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Registry differences\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some registry operations on HKCU will be redirected to HKEY_USERS\\.DEFAULT\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015600833_3_ee06b7e0ca-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Methods to downgrade from administrator to standard user privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. runas\u003C\u002Fh3>\u003Cp>cmd：\u003C\u002Fp>\u003Cp>runas \u002Fuser:a calc.exe\u003C\u002Fp>\u003Cp>Then enter password: 123456\u003C\u002Fp>\u003Cp>calc.exe runs with user a's privileges\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015603669_4_73918137de-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires waiting for manual password entry, lacks automation\u003C\u002Fp>\u003Cp>However, automatic password input can be achieved via piping, requiring third-party tool Sanur (method not detailed here)\u003C\u002Fp>\u003Ch3>2. Third-party tool: lsrunas\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.verydoc.com\u002Fexeshell.html\u003C\u002Fp>\u003Cp>cmd：\u003C\u002Fp>\u003Cp>lsrunas.exe \u002Fuser:a \u002Fpassword:123456 \u002Fdomain: \u002Fcommand:\"calc.exe\" \u002Frunpath:c:\\\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u002Fdomain: Empty parameter indicates the local machine\u003C\u002Fp>\u003Cp>Successfully downgraded from administrator privileges to standard user privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015606380_5_1ddb4d229c-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Third-party tool: CPAU\u003C\u002Fh3>\u003Cp>Download address can be referenced from my GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>CPAU.exe -u a -p 123456 -ex \"calc.exe\" -cwd c:\\windows\\system32 -lwp\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The parameter -lwp or -lwop must be added, otherwise privilege downgrade cannot be achieved\u003C\u002Fp>\u003Cp>Successfully downgraded from administrator privileges to standard user privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015607971_6_bdbd4771f8-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. PowerShell\u003C\u002Fh3>\u003Cp>Code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"a\"\u003Cbr>$pwd=ConvertTo-SecureString  \"123456\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Start-Process -FilePath  \"calc.exe\" -Credential $cred  \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5、c++\u003C\u002Fh3>\u003Cp>Using API:\u003C\u002Fp>\u003Cul>\u003Cli>CreateProcessAsUser\u003C\u002Fli>\u003Cli>CreateProcess\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Methods to downgrade from system privileges to normal user privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The system privileges in this test were obtained through a vulnerability\u003C\u002Fp>\u003Ch3>1、runas\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>runas \u002Fuser:a calc.exe\u003C\u002Fp>\u003Cp>Then enter the password: 123456\u003C\u002Fp>\u003Cp>Successfully downgraded privileges, but failed to start, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015610366_7_59e7e16010-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Third-party tool: lsrunas\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>lsrunas.exe \u002Fuser:a \u002Fpassword:123456 \u002Fdomain: \u002Fcommand:\"calc.exe\" \u002Frunpath:c:\\\u003C\u002Fp>\u003Cp>Same as above, successfully downgraded privileges, but failed to start\u003C\u002Fp>\u003Ch3>3. Third-party tool: CPAU\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>CPAU.exe -u a -p 123456 -ex \"calc.exe\" -lwp\u003C\u002Fp>\u003Cp>CPAU does not support starting with system privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015612224_8_246d5a6c72-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. powershell\u003C\u002Fh3>\u003Cp>Same as 1, successfully downgraded privileges, but failed to start\u003C\u002Fp>\u003Ch3>5. c++\u003C\u002Fh3>\u003Cp>Didier Stevens' tool SelectMyParent can be used\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The code is not yet shared on GitHub, so I have uploaded it to my GitHub repository, crediting the author as Didier Stevens\u003C\u002Fp>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>SelectMyParent:\u003C\u002Fh3>\u003Cp>Used to create a Windows process with a selected parent process\u003C\u002Fp>\u003Cp>For example: When creating a new process calc.exe, using SelectMyParent allows setting the new process calc.exe as a child process of winlogon.exe\u003C\u002Fp>\u003Cp>Usage steps:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtain the PID of process winlogon.exe\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In my test system, the PID of process winlogon.exe is 504\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Launch SelectMyParent\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Parameters as follows:\u003C\u002Fp>\u003Cp>SelectMyParent.exe calc.exe 504\u003C\u002Fp>\u003Cp>Shows calc.exe as a child process of winlogon.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015613550_9_953c3c7c4d-1.jpeg\">\u003C\u002Fp>\u003Cp>This method can primarily be used to enhance process stealth and deceive users\u003C\u002Fp>\u003Cp>\u003Cstrong>Special aspects:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since child processes inherit the permissions of the parent process, and winlogon.exe has system-level permissions, its child process calc.exe will also acquire system-level permissions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015615166_10_69f1561dfd-1.jpeg\">\u003C\u002Fp>\u003Cp>That is to say, based on SelectMyParent, we can implement the following privilege escalation and de-escalation operations:\u003C\u002Fp>\u003Cul>\u003Cli>Privilege escalation: From administrator privileges to system privileges\u003C\u002Fli>\u003Cli>Privilege de-escalation: From system privileges to admin privileges\u003C\u002Fli>\u003Cli>Privilege de-escalation: From system privileges to standard user privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Operation steps:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtain the process PID\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Method to obtain process PID in cmd:\u003C\u002Fp>\u003Cp>tasklist \u002Fv \u002Ffo list\u003C\u002Fp>\u003Cp>Can retrieve the corresponding PID and permissions (indicated by the username value) for each process, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015616233_11_f319d3e766-1.jpeg\">\u003C\u002Fp>\u003Cp>For testing convenience, filtering can be used to select processes with specific permissions, such as filtering NT AUTHORITY\\SYSTEM.\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>tasklist \u002Fv \u002Ffo list \u002Ffi \"USERNAME eq NT AUTHORITY\\SYSTEM\"\u003C\u002Fp>\u003Cp>If obtaining processes with regular user permissions, the USERNAME filter can be set to the return result of whoami.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Using SelectMyParent.exe\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>From administrator permissions to system permissions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As demonstrated earlier, no further introduction is needed.\u003C\u002Fp>\u003Cp>\u003Cstrong>From system permissions to admin permissions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using tasklist cannot distinguish whether a process has administrator or regular user permissions.\u003C\u002Fp>\u003Cp>Therefore, I wrote a small tool in C++ with the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Traverse processes\u003C\u002Fli>\u003Cli>Determine process permissions; if administrator permissions, mark them.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Tool usage is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015616591_12_23a66bf1c7-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>From SYSTEM Privileges to Standard User Privileges:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Select a standard user privilege process with PID 3864; the created calc.exe will also have standard user privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015617222_13_e5d8447780-1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully achieved privilege reduction from SYSTEM to standard user\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests common privilege reduction methods, concluding that some methods may fail under certain conditions. The universal approach is to use SelectMyParent for privilege reduction.\u003C\u002Fp>\u003Cp>In practice, a small tool for traversing and judging process privileges has been open-sourced to improve efficiency.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",289,"Onedaysec",5,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Program Privilege Reduction Techniques in Penetration Testing","penetration testing, privilege reduction, SYSTEM to user, administrator downgrade, SelectMyParent, runas, lsrunas, CPAU, Windows security",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],1072,1071,1070,1069,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.854Z","2026-07-23T16:02:29.519Z","draft","2026-07-23T16:16:29.247Z"]