
Manipulando e Abusando de Tokens de Acesso do Windows.
Manipulando e Abusando de Tokens de Acesso do Windows.
TokenPlayer é apenas uma pequena ferramenta que criei para aprender programação da win32 api e entender melhor o modelo de tokens de acesso do Windows.
General options:
--help Display help menu.
Impersonation Options:
--impersonate Impersonates the specified pid and spawns a new child
process under its context.
--pid arg Proccess ID to steal the token from.
--spawn Spawns a new command prompt under the context of the
stolen token.
Execution Options:
--exec Execute an instance of a specified program under the
impersonated context.
--pid arg Proccess ID to steal the token from.
--prog The full path to the program to be executed.
--args Optional execution arguments for the specified
program.
Make Token Options:
--maketoken Create a new process under a set of creds for only
network authentication (Similar to runas /netonly).
--username arg Username
--password arg Password in plaintext format.
--domain arg The domain the user belongs, if domain isn't specified
the local machine will be used.
UAC Bypass Options:
--pwnuac Will try to bypass UAC using the token-duplication
method.
--spawn Spawns a new elevated prompt.
--prog arg The full path to the program to be executed.
--args arg Optional execution arguments for the specified
program.
Parent Process Spoofing Options:
--spoofppid Spawn a new instance of an application with spoofed
parent process.
--ppid arg The PID of the parent process.
--prog arg The full path to the program to be executed.
--args arg Optional execution arguments for the specified
program.






Para compilar você mesmo, precisará instalar a biblioteca boost, pois ela é usada para analisar e lidar com os argumentos de linha de comando. Além disso, você precisará especificar a pasta da biblioteca externa nas configurações do projeto.