{"enrichment":{"faq":[{"a":"Windows Token Impersonation is a technique for escalating privileges on Windows systems by leveraging dangerous token privileges like SeImpersonate and SeDebug. The skill guides you through obtaining a service account shell, checking for exploitable privileges, and using tools like JuicyPotato, PrintSpoofer, and GodPotato to reach SYSTEM access.","q":"What is Windows Token Impersonation and how does it work?"},{"a":"Windows Token Impersonation teaches the process of impersonating user tokens by first identifying which privileges are available on your current account. Once you confirm SeImpersonate or SeDebug privileges exist, you can use exploitation tools to interact with higher-privileged processes and assume their token context to execute commands at elevated privilege levels.","q":"How do you impersonate a user token on Windows systems?"},{"a":"Windows Token Impersonation covers three primary exploitation tools: JuicyPotato, PrintSpoofer, and GodPotato. Each tool exploits different Windows mechanisms to perform token impersonation attacks. The skill teaches when and how to deploy each tool depending on your target system's configuration and available privileges.","q":"What are the main tools used for Windows token impersonation?"},{"a":"Yes, Windows Token Impersonation enables lateral movement by allowing attackers to execute commands under different user contexts after impersonating their tokens. Once you achieve SYSTEM or another privileged account's token, you can move across the network using those elevated credentials to access additional systems and resources.","q":"Can Windows token impersonation be used for lateral movement?"},{"a":"Windows Token Impersonation exploits dangerous token privileges, primarily SeImpersonate and SeDebug. The skill teaches you to check for these exploitable privileges on your current account. When present, these privileges allow you to interact with and assume the tokens of other processes, enabling privilege escalation to SYSTEM.","q":"What privileges enable Windows token impersonation attacks?"},{"a":"Windows Token Impersonation covers defensive perspectives by explaining token impersonation techniques so security teams understand the attack surface. Defenders can monitor for suspicious token privilege usage, restrict SeImpersonate and SeDebug assignments to trusted accounts, and implement detection rules for exploitation tool behavior patterns.","q":"How can defenders detect and prevent token impersonation?"}],"shadow_tags":["privilege-escalation","lateral-movement","post-exploitation","windows-security","access-control","credential-theft","attack-technique"],"summary_rewrite":"Windows Token Impersonation helps penetration testers escalate privileges on Windows systems by leveraging dangerous token privileges like SeImpersonate and SeDebug. The skill guides you through obtaining a service account shell, checking for exploitable privileges, and using tools like JuicyPotato, PrintSpoofer, and GodPotato to reach SYSTEM."},"gist":{"api_url":"https://skillfed.io/api/skills/blacklanternsecurity/red-run/windows-token-impersonation.json","as_of":"2026-04-01","description":"Windows Token Impersonation exploits dangerous token privileges to escalate from service accounts to SYSTEM.","install":{"manual":["git clone https://github.com/blacklanternsecurity/red-run","cp -r red-run ~/.claude/skills/windows-token-impersonation"],"primary":"npx skillfed install blacklanternsecurity/red-run/windows-token-impersonation","version":"8dd0c137"},"kind":"skill","mirror_url":"https://skillfed.io/blacklanternsecurity/red-run/windows-token-impersonation.md","similar":[{"id":"yaklang/hack-skills/windows-privilege-escalation","name":"windows-privilege-escalation","publisher":"yaklang/hack-skills","url":"https://skillfed.io/yaklang/hack-skills/windows-privilege-escalation"},{"id":"hypnguyen1209/offensive-claude/privesc-windows","name":"privesc-windows","publisher":"hypnguyen1209/offensive-claude","url":"https://skillfed.io/hypnguyen1209/offensive-claude/privesc-windows"},{"id":"hypnguyen1209/offensive-claude/windows-boundaries","name":"windows-boundaries","publisher":"hypnguyen1209/offensive-claude","url":"https://skillfed.io/hypnguyen1209/offensive-claude/windows-boundaries"},{"id":"blacklanternsecurity/red-run/windows-kernel-exploits","name":"Windows Kernel Exploits","publisher":"blacklanternsecurity/red-run","url":"https://skillfed.io/blacklanternsecurity/red-run/windows-kernel-exploits"},{"id":"blacklanternsecurity/red-run/windows-discovery","name":"Windows Discovery","publisher":"blacklanternsecurity/red-run","url":"https://skillfed.io/blacklanternsecurity/red-run/windows-discovery"}],"title":"Windows Token Impersonation by blacklanternsecurity \u2014 SkillFed","use":{"when":["Windows Token Impersonation teaches the process of impersonating user tokens by first identifying which privileges are available.","Windows Token Impersonation covers three primary exploitation tools: JuicyPotato, PrintSpoofer, and GodPotato."]},"what":{"lead":"Windows Token Impersonation exploits dangerous token privileges to escalate from service accounts to SYSTEM on Windows.","rest":"Windows Token Impersonation helps penetration testers escalate privileges on Windows systems by leveraging dangerous token privileges like SeImpersonate and SeDebug. The skill guides you through obtaining a service account shell, checking for exploitable privileges, and using tools like JuicyPotato, PrintSpoofer, and GodPotato to reach SYSTEM."}},"id":"blacklanternsecurity/red-run/windows-token-impersonation","install":{"mode":"external","repo":"https://github.com/blacklanternsecurity/red-run"},"links":{"html":"https://skillfed.io/blacklanternsecurity/red-run/windows-token-impersonation","md":"https://skillfed.io/blacklanternsecurity/red-run/windows-token-impersonation.md","repo":"https://github.com/blacklanternsecurity/red-run"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":34,"language":"Python","last_updated":"2026-04-01","license":"GPL-3.0","name":"Windows Token Impersonation","publisher":"blacklanternsecurity","stars":241},"relations":{"similar":[{"id":"yaklang/hack-skills/windows-privilege-escalation"},{"id":"zebbern/claude-code-guide/windows-privilege-escalation"},{"id":"hypnguyen1209/offensive-claude/privesc-windows"},{"id":"hypnguyen1209/offensive-claude/windows-boundaries"},{"id":"blacklanternsecurity/red-run/windows-kernel-exploits"},{"id":"hypnguyen1209/offensive-claude/red-team-ops"},{"id":"blacklanternsecurity/red-run/windows-service-dll-abuse"},{"id":"blacklanternsecurity/red-run/windows-uac-bypass"},{"id":"blacklanternsecurity/red-run/windows-discovery"},{"id":"blacklanternsecurity/red-run/av-edr-evasion"}]},"slug":{"owner":"blacklanternsecurity","repo":"red-run","skill":"windows-token-impersonation"},"version":"8dd0c137"}
