Skip to content

Instantly share code, notes, and snippets.

@hacksysteam
Created May 7, 2015 08:13
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save hacksysteam/5de44c293c3eb54ebca9 to your computer and use it in GitHub Desktop.
Save hacksysteam/5de44c293c3eb54ebca9 to your computer and use it in GitHub Desktop.
Token Stealing Using WinDBG
PROCESS 8570b5e8 SessionId: 1 Cid: 025c Peb: 7ffdf000 ParentCid: 0704
DirBase: 3eea5340 ObjectTable: 953b8570 HandleCount: 21.
Image: cmd.exe
PROCESS 83dbb020 SessionId: none Cid: 0004 Peb: 00000000 ParentCid: 0000
DirBase: 00185000 ObjectTable: 87801c98 HandleCount: 481.
Image: System
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment