Skip to content

This project is a Windows privilege escalation tool that allows a user to launch any application as NT AUTHORITY/SYSTEM by leveraging an existing SYSTEM process token.

License

Notifications You must be signed in to change notification settings

Austin-Hypes/RunasSystem

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

6 Commits
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

RunasSystem

Overview

This project is a Windows privilege escalation tool that allows a user to launch any application as NT AUTHORITY/SYSTEM by leveraging an existing SYSTEM process token.

Features ✨

βœ… Automatic Admin Elevation - Relaunches itself with Administrator privileges if not already running as admin. βœ… Process Scanning - Takes a snapshot of all running processes and identifies those running as NT AUTHORITY/SYSTEM. βœ… Token Duplication - Extracts and duplicates a SYSTEM token from an existing SYSTEM process. βœ… Execute as SYSTEM - Uses the duplicated token to launch a specified application with SYSTEM privileges.

How It Works πŸ”

Admin Check & Relaunch:

The program first checks if it is running as Administrator. If not, it restarts itself with elevated privileges using ShellExecuteExW(). Process Enumeration:

It captures a snapshot of all running processes. It loops through the processes and checks the user of each process. Finding a SYSTEM Process:

If it finds a process running as NT AUTHORITY/SYSTEM, it attempts to extract its access token. Launching an Application as SYSTEM:

It duplicates the SYSTEM token and launches a user-specified application under that token.

Disclaimer πŸ›‘

This tool is meant for educational and administrative use only. Misuse of privilege escalation techniques can lead to security vulnerabilities or violations of IT policies.

Notes πŸ“

Created In Visual Studio 2022 Using C++ Used Ctrl B to build

Proctected Under MIT License

About

This project is a Windows privilege escalation tool that allows a user to launch any application as NT AUTHORITY/SYSTEM by leveraging an existing SYSTEM process token.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages