[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFO81FnNaa9_KG8MsheaWkTVkOwdeU79afXtfdfZmwIo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1175,"Why does mimikatz's `process::start` command fail to create a process using an impersonated token from a net session, and how can this be overcome?","When mimikatz impersonates a token via `token::elevate`, it only changes the Thread Token (Impersonation Token), but `process::start` uses `CreateProcess` without passing a token, so the new process runs under the original primary token. To successfully create a process with the net session's token, you either need to modify mimikatz source code to use `CreateProcessAsUser` or use a tool like incognito, as described in [Penetration Techniques - Token Theft and Exploitation](\u002Fnews\u002Fpenetration-techniques-token-theft-and-exploitation).","\u003Cp>When mimikatz impersonates a token via `token::elevate`, it only changes the Thread Token (Impersonation Token), but `process::start` uses `CreateProcess` without passing a token, so the new process runs under the original primary token. To successfully create a process with the net session&#39;s token, you either need to modify mimikatz source code to use `CreateProcessAsUser` or use a tool like incognito, as described in [Penetration Techniques - Token Theft and Exploitation](\u002Fnews\u002Fpenetration-techniques-token-theft-and-exploitation).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-exploitation-of-net-session-in-windows\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-does-mimikatzs-processstart-command-fail-to-create-a-process-using-an-impers-1777480151865","mimikatz, CreateProcess, CreateProcessAsUser, impersonation token, incognito",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},285,"Penetration Techniques - Exploitation of net session in Windows","penetration-techniques-exploitation-of-net-session-in-windows","Learn how to exploit net sessions in Windows for penetration testing, including token theft with mimikatz and incognito, for privilege escalation and lateral movement.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, using the net use command enables remote connections to shared resources on other computers in the network. After establishing a connection, a net session is created.\u003C\u002Fp>\u003Cp>During penetration testing, if we gain access to a Windows host and discover a net session, we can exploit this net session by using its token to create a process.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to view net sessions\u003C\u002Fli>\u003Cli>Exploitation of net sessions\u003C\u002Fli>\u003Cli>Clearing net sessions\u003C\u002Fli>\u003Cli>Exploitation strategies\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Test Environment\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>COMPUTER01:\u003C\u002Fp>\u003Cul>\u003Cli>Win7 x64\u003C\u002Fli>\u003Cli>A host within the domain\u003C\u002Fli>\u003Cli>192.168.10.2\u003C\u002Fli>\u003Cli>Logged in with account test1\u003C\u002Fli>\u003C\u002Ful>\u003Cp>DC:\u003C\u002Fp>\u003Cul>\u003Cli>Server2008 R2 x64\u003C\u002Fli>\u003Cli>Domain controller server\u003C\u002Fli>\u003Cli>192.168.10.1\u003C\u002Fli>\u003C\u002Ful>\u003Cp>On the DC, using the domain administrator account Administrator to remotely connect to COMPUTER01 via net use, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016721565_0_7498941855.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Method for viewing net session\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. cmd command\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net session\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016727655_1_0ccde6269f.jpeg\">\u003C\u002Fp>\u003Ch3>2. LogonSessions\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fdownloads\u002Flogonsessions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016731908_2_0a78638e5d.jpeg\">\u003C\u002Fp>\u003Cp>It can be observed that the Logon type for net session is Network\u003C\u002Fp>\u003Ch3>3. C++ Implementation\u003C\u002Fh3>\u003Cp>First, enumerate the current Logon Sessions using the Windows API LsaEnumerateLogonSessions()\u003C\u002Fp>\u003Cp>Then, use LsaGetLogonSessionData() to obtain detailed information for each Logon Session\u003C\u002Fp>\u003Cp>In programming, note that SID and time cannot be displayed directly; format conversion is required\u003C\u002Fp>\u003Cp>Open-source code address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code outputs results in the format of LogonSessions\u003C\u002Fp>\u003Ch3>4. mimikatz\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>token::list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016736497_3_21ff12949a.jpeg\">\u003C\u002Fp>\u003Cp>The ID corresponding to TEST\\Administrator is 6919466\u003C\u002Fp>\u003Ch4>Supplement mimikatz commands\u003C\u002Fh4>\u003Cp>View current token:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore process token:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::revert\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as system:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as domain admin:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fdomainadmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as enterprise admin:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fenterpriseadmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as admin:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fadmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as token with ID 123456:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fid:123456\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>Exploitation of 0x04 net session\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The token of net session is stored in the lsass process, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016739832_4_8a28870ee9.jpeg\">\u003C\u002Fp>\u003Cp>In terms of exploitation, net session is equivalent to exploiting its token\u003C\u002Fp>\u003Ch3>1、mimikatz\u003C\u002Fh3>\u003Cp>Impersonate as token with ID 6919466:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fid:6919466\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016743284_5_97b8cf6c3f.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above operation only changed the Thread Token\u003C\u002Fp>\u003Cp>There are two types of tokens in Windows: Primary Token and Impersonation Token\u003C\u002Fp>\u003Cp>Primary Token corresponds to Process Token, each process has a unique Primary Token\u003C\u002Fp>\u003Cp>Impersonation Token corresponds to Thread Token, which can be modified\u003C\u002Fp>\u003Cp>Next, use this token to create a process cmd.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>process::start cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, this command does not use the new Thread Token, meaning the process cmd.exe is not launched as TEST\\Administrator\u003C\u002Fp>\u003Ch4>The reason is as follows:\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002F110a831ebe7b529c5dd3010f9e7fced0d3e3a46c\u002Fmimikatz\u002Fmodules\u002Fkuhl_m_process.c#L38\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016746434_6_31a4181e9f.jpeg\">\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002F110a831ebe7b529c5dd3010f9e7fced0d3e3a46c\u002Fmodules\u002Fkull_m_process.c#L490\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016748289_7_99f9e1d553.jpeg\">\u003C\u002Fp>\u003Cp>When mimikatz executes the process::start command, it uses CreateProcess to create the process without passing a token\u003C\u002Fp>\u003Ch4>Solution:\u003C\u002Fh4>\u003Cp>Modify the source code of mimikatz to use CreateProcessAsUser() for process creation, which allows passing a Token\u003C\u002Fp>\u003Cp>Of course, we can also use other tools to achieve this process\u003C\u002Fp>\u003Ch3>2、Using incognito\u003C\u002Fh3>\u003Cp>Open-source code address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffdiskyou\u002Fincognito2\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In a previous article titled 'Penetration Techniques – Token Theft and Exploitation,' the usage of incognito was introduced\u003C\u002Fp>\u003Cp>List current tokens:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe list_tokens -u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Start cmd.exe as \"TEST\\Administrator\":\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"TEST\\Administrator\" cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016750006_8_041bf958f4.jpeg\">\u003C\u002Fp>\u003Cp>net session exploitation succeeded, process cmd.exe launched with user \"TEST\\Administrator\", as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016751076_9_000591be84.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Clearing net session\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. cmd command\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net session \u002Fdelete \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Delete net use connections\u003C\u002Fh3>\u003Cp>Initiator deletes net use connections:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net use * \u002Fdel \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Exploitation ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Local privilege escalation\u003C\u002Fh3>\u003Cp>If local administrator privileges have not been obtained yet, but SeImpersonate or SeAssignPrimaryToken privileges have been acquired, the token in net session can be used to create new processes, achieving privilege escalation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As mentioned in previous articles 'Analysis of Windows Local Privilege Escalation Tool Juicy Potato' and 'Penetration Techniques – Exploitation of Nine Windows Privileges', this method has been discussed.\u003C\u002Fp>\u003Ch3>2. Domain Penetration\u003C\u002Fh3>\u003Cp>Depending on the permissions of the net session, the newly created process can inherit the token of the net session.\u003C\u002Fp>\u003Ch2>0x07 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Restrict user permissions within the domain environment and avoid using domain administrator accounts for remote connections whenever possible.\u003C\u002Fp>\u003Cp>2. Remember to clear net use remote connections promptly after use.\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of creating processes using the token from net sessions, analyzes the exploitation approach, and provides defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, using the net use command enables remote connections to shared resources on other computers in the network. After establishing a connection, a net session is created.\u003C\u002Fp>\u003Cp>During penetration testing, if we gain access to a Windows host and discover a net session, we can exploit this net session by using its token to create a process.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to view net sessions\u003C\u002Fli>\u003Cli>Exploitation of net sessions\u003C\u002Fli>\u003Cli>Clearing net sessions\u003C\u002Fli>\u003Cli>Exploitation strategies\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Test Environment\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>COMPUTER01:\u003C\u002Fp>\u003Cul>\u003Cli>Win7 x64\u003C\u002Fli>\u003Cli>A host within the domain\u003C\u002Fli>\u003Cli>192.168.10.2\u003C\u002Fli>\u003Cli>Logged in with account test1\u003C\u002Fli>\u003C\u002Ful>\u003Cp>DC:\u003C\u002Fp>\u003Cul>\u003Cli>Server2008 R2 x64\u003C\u002Fli>\u003Cli>Domain controller server\u003C\u002Fli>\u003Cli>192.168.10.1\u003C\u002Fli>\u003C\u002Ful>\u003Cp>On the DC, using the domain administrator account Administrator to remotely connect to COMPUTER01 via net use, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016721565_0_7498941855-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Method for viewing net session\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. cmd command\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net session\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016727655_1_0ccde6269f-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. LogonSessions\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fdownloads\u002Flogonsessions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016731908_2_0a78638e5d-1.jpeg\">\u003C\u002Fp>\u003Cp>It can be observed that the Logon type for net session is Network\u003C\u002Fp>\u003Ch3>3. C++ Implementation\u003C\u002Fh3>\u003Cp>First, enumerate the current Logon Sessions using the Windows API LsaEnumerateLogonSessions()\u003C\u002Fp>\u003Cp>Then, use LsaGetLogonSessionData() to obtain detailed information for each Logon Session\u003C\u002Fp>\u003Cp>In programming, note that SID and time cannot be displayed directly; format conversion is required\u003C\u002Fp>\u003Cp>Open-source code address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code outputs results in the format of LogonSessions\u003C\u002Fp>\u003Ch3>4. mimikatz\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>token::list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016736497_3_21ff12949a-1.jpeg\">\u003C\u002Fp>\u003Cp>The ID corresponding to TEST\\Administrator is 6919466\u003C\u002Fp>\u003Ch4>Supplement mimikatz commands\u003C\u002Fh4>\u003Cp>View current token:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore process token:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::revert\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as system:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as domain admin:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fdomainadmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as enterprise admin:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fenterpriseadmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as admin:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fadmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Impersonate as token with ID 123456:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fid:123456\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>Exploitation of 0x04 net session\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The token of net session is stored in the lsass process, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016739832_4_8a28870ee9-1.jpeg\">\u003C\u002Fp>\u003Cp>In terms of exploitation, net session is equivalent to exploiting its token\u003C\u002Fp>\u003Ch3>1、mimikatz\u003C\u002Fh3>\u003Cp>Impersonate as token with ID 6919466:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>token::elevate \u002Fid:6919466\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016743284_5_97b8cf6c3f-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above operation only changed the Thread Token\u003C\u002Fp>\u003Cp>There are two types of tokens in Windows: Primary Token and Impersonation Token\u003C\u002Fp>\u003Cp>Primary Token corresponds to Process Token, each process has a unique Primary Token\u003C\u002Fp>\u003Cp>Impersonation Token corresponds to Thread Token, which can be modified\u003C\u002Fp>\u003Cp>Next, use this token to create a process cmd.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>process::start cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, this command does not use the new Thread Token, meaning the process cmd.exe is not launched as TEST\\Administrator\u003C\u002Fp>\u003Ch4>The reason is as follows:\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002F110a831ebe7b529c5dd3010f9e7fced0d3e3a46c\u002Fmimikatz\u002Fmodules\u002Fkuhl_m_process.c#L38\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016746434_6_31a4181e9f-1.jpeg\">\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002F110a831ebe7b529c5dd3010f9e7fced0d3e3a46c\u002Fmodules\u002Fkull_m_process.c#L490\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016748289_7_99f9e1d553-1.jpeg\">\u003C\u002Fp>\u003Cp>When mimikatz executes the process::start command, it uses CreateProcess to create the process without passing a token\u003C\u002Fp>\u003Ch4>Solution:\u003C\u002Fh4>\u003Cp>Modify the source code of mimikatz to use CreateProcessAsUser() for process creation, which allows passing a Token\u003C\u002Fp>\u003Cp>Of course, we can also use other tools to achieve this process\u003C\u002Fp>\u003Ch3>2、Using incognito\u003C\u002Fh3>\u003Cp>Open-source code address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffdiskyou\u002Fincognito2\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In a previous article titled 'Penetration Techniques – Token Theft and Exploitation,' the usage of incognito was introduced\u003C\u002Fp>\u003Cp>List current tokens:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe list_tokens -u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Start cmd.exe as \"TEST\\Administrator\":\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>incognito.exe execute -c \"TEST\\Administrator\" cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016750006_8_041bf958f4-1.jpeg\">\u003C\u002Fp>\u003Cp>net session exploitation succeeded, process cmd.exe launched with user \"TEST\\Administrator\", as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016751076_9_000591be84-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Clearing net session\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. cmd command\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net session \u002Fdelete \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Delete net use connections\u003C\u002Fh3>\u003Cp>Initiator deletes net use connections:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net use * \u002Fdel \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Exploitation ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Local privilege escalation\u003C\u002Fh3>\u003Cp>If local administrator privileges have not been obtained yet, but SeImpersonate or SeAssignPrimaryToken privileges have been acquired, the token in net session can be used to create new processes, achieving privilege escalation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As mentioned in previous articles 'Analysis of Windows Local Privilege Escalation Tool Juicy Potato' and 'Penetration Techniques – Exploitation of Nine Windows Privileges', this method has been discussed.\u003C\u002Fp>\u003Ch3>2. Domain Penetration\u003C\u002Fh3>\u003Cp>Depending on the permissions of the net session, the newly created process can inherit the token of the net session.\u003C\u002Fp>\u003Ch2>0x07 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Restrict user permissions within the domain environment and avoid using domain administrator accounts for remote connections whenever possible.\u003C\u002Fp>\u003Cp>2. Remember to clear net use remote connections promptly after use.\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of creating processes using the token from net sessions, analyzes the exploitation approach, and provides defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",40,"Onedaysec",4,"published","2026-02-02T07:25:19.685Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exploit Windows Net Session for Penetration Testing & Token Theft","Windows net session exploitation, penetration testing, token theft, mimikatz, incognito, net use, network sessions, Windows security, privilege escalation, lateral movement",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],1177,1176,1174,1173,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.100Z","2026-07-23T16:02:38.760Z","draft","2026-07-23T16:17:11.077Z"]