Tater Tokens: Intro to Windows Access Tokens and Their Role in PrivEsc

Tater Tokens: Intro to Windows Access Tokens and Their Role in PrivEsc

Source: YouTube · SpecterOps · published Aug 25, 2025 · 41:25

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Windows access tokens govern resource access tied to login sessions, containing SIDs, privileges, and impersonation levels 02:45. Attackers exploit the SE_impersonate privilege via the "Potato" family—Rotten Potato NG, Juicy Potato, and Rogue Potato—to hijack tokens and escalate privileges to SYSTEM 08:12.

Key Takeaways:
• Access tokens are session-bound keys containing SIDs, privileges, and impersonation levels, distinct from user-only identities 02:45
• SE_impersonate privilege enables processes to impersonate client contexts, commonly held by service accounts and local admins 08:12
• Rotten Potato NG abuses COM objects and NTLM authentication to forge impersonation tokens for SYSTEM execution 12:30
• Juicy Potato expands exploitation by allowing attackers to select specific COM servers and Class IDs, bypassing Rotten Potato's BITS limitations 18:45
• Rogue Potato abuses the Oxid Resolver and RPCSS to force authentication through a controlled named pipe, achieving two-step escalation on patched systems 24:15

Understanding these token manipulation mechanics is critical for developing detection rules and mitigating privilege escalation risks in Windows environments.

Sources:

  • 02:45 Introduction to Windows access tokens and their structure
  • 08:12 Explanation of SE_impersonate privilege and COM servers
  • 12:30 Rotten Potato NG exploitation mechanics
  • 18:45 Juicy Potato

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, good afternoon everybody. We're just going to give it another minute or so, let people join in. Uh, and then we'll get started here in just a bit. All right. While everyone continues to join, just wanted to reiterate uh the message that was shared in the chat. Uh so the recording will be shared uh after the event is over. Uh so everybody that registered is going to have access to that recording. And then also if you happen to have any questions during uh the webinar uh feel free to use the Q&A uh option to send in your questions and I'll be happy to address them. Just give it one more minute before we get started. All right, we'll go ahead and kick it off. So, to everybody that's joined, welcome uh to today's webinar. We'll where we'll be covering Tater tokens. Uh this is going …