Process Token Dumper
by Vivek Ramachandran 02/21/2017
Process Token Dumper
%20-%20MindMeister_files/priority_01-7e8f0f98f69f4ccd61de86ec760e639982a74b32ba562553.png)
Privilege Check
SeDebugPrivilege
GetCurrentProcess()
OpenProcessToken()
GetTokenInformation()
AdjustTokenPrivileges()
%20-%20MindMeister_files/priority_02-98287828d2be20754cd87da961c68f3d22c73f45e3e0cd37.png)
Get Process Handle
OpenProcess()
Choose Minimal Access
MAXIMUM_ALLOWED
PROCESS_QUERY_LIMITED_INFORMATION
Protected Processes
Protected Processes
%20-%20MindMeister_files/8429494.png)
Finding Protected Processes
%20-%20MindMeister_files/priority_03-96b19010a5ee2e7d8cbbad81e3c39c0217b99bf5289a2109.png)
Get Process Token Handle
OpenProcessToken()
MAXIMUM_ALLOWED
%20-%20MindMeister_files/8429375.png)
%20-%20MindMeister_files/priority_04-9635b2cad50413d157b1e239deb3178a3e62fe87d2dfbd43.png)
Dump Token Information
GetTokenInformation()
%20-%20MindMeister_files/8429378.png)
TokenUser
%20-%20MindMeister_files/8429383.png)
SID_AND_ATTRIBUTES
%20-%20MindMeister_files/8429526.png)
Demo
%20-%20MindMeister_files/8429401.png)
TokenOwner
%20-%20MindMeister_files/8429523.png)
Demo
%20-%20MindMeister_files/8429403.png)
TokenPrimaryGroup
%20-%20MindMeister_files/8429528.png)
Demo
%20-%20MindMeister_files/8429406.png)
TokenGroups
%20-%20MindMeister_files/8429532.png)
Demo
%20-%20MindMeister_files/8429490.png)
TokenPrivileges
%20-%20MindMeister_files/8429501.png)
LUID_AND_ATTRIBUTES
%20-%20MindMeister_files/8429533.png)
Demo
%20-%20MindMeister_files/8429491.png)
TokenSource
%20-%20MindMeister_files/8429535.png)
Demo
%20-%20MindMeister_files/8429492.png)
TokenType
%20-%20MindMeister_files/8429536.png)
Demo
%20-%20MindMeister_files/8429493.png)
TokenElevation
%20-%20MindMeister_files/8429540.png)
Demo
... many others