-
Notifications
You must be signed in to change notification settings - Fork 199
Stealing Tokens
Alexander edited this page Oct 2, 2018
·
10 revisions
Mandatory Parameters: -
Optional Parameters: Process ID, Command
Examples:
(Tokens) > GetSystem
(Tokens) > GetSystem regedit.exe
(Tokens) > GetSystem 504
(Tokens) > GetSystem 504 regedit.exe
Mandatory Parameters: -
Optional Parameters: Command
Examples:
(Tokens) > GetTrustedInstaller
(Tokens) > GetTrustedInstaller regedit.exe
Mandatory Parameters: Process ID or Process Name
Optional Parameters: Command
Examples:
(Tokens) > StealToken 1008
(Tokens) > StealToken calc regedit.exe
(Tokens) > StealToken 1008 regedit.exe
Mandatory Parameters: Command
Optional Parameters: Process ID
Examples:
(Tokens) > BypassUAC regedit.exe
(Tokens) > BypassUAC 1008 regedit.exe