
Tater Tokens: Intro to Windows Access Tokens and Their Role in PrivEsc
Source: YouTube · SpecterOps · published Aug 25, 2025 · 41:25
Windows access tokens govern resource access tied to login sessions, containing SIDs, privileges, and impersonation levels 02:45. Attackers exploit the SE_impersonate privilege via the "Potato" family—Rotten Potato NG, Juicy Potato, and Rogue Potato—to hijack tokens and escalate privileges to SYSTEM 08:12.
Key Takeaways:
• Access tokens are session-bound keys containing SIDs, privileges, and impersonation levels, distinct from user-only identities 02:45
• SE_impersonate privilege enables processes to impersonate client contexts, commonly held by service accounts and local admins 08:12
• Rotten Potato NG abuses COM objects and NTLM authentication to forge impersonation tokens for SYSTEM execution 12:30
• Juicy Potato expands exploitation by allowing attackers to select specific COM servers and Class IDs, bypassing Rotten Potato's BITS limitations 18:45
• Rogue Potato abuses the Oxid Resolver and RPCSS to force authentication through a controlled named pipe, achieving two-step escalation on patched systems 24:15
Understanding these token manipulation mechanics is critical for developing detection rules and mitigating privilege escalation risks in Windows environments.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, good afternoon everybody. We're just going to give it another minute or so, let people join in. Uh, and then we'll get started here in just a bit. All right. While everyone continues to join, just wanted to reiterate uh the message that was shared in the chat. Uh so the recording will be shared uh after the event is over. Uh so everybody that registered is going to have access to that recording. And then also if you happen to have any questions during uh the webinar uh feel free to use the Q&A uh option to send in your questions and I'll be happy to address them. Just give it one more minute before we get started. All right, we'll go ahead and kick it off. So, to everybody that's joined, welcome uh to today's webinar. We'll where we'll be covering Tater tokens. Uh this is going …