Skip to content

InJeCTrL/SysRun

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 
 
 

Repository files navigation

SysRun

Execute programs as system privilege

Preview

cmd

Usage

sysrun.exe FILEPATH

API call flow

API Goal
RtlAdjustPrivilege switch process to debug privilege
EnumProcesses & GetProcessImageFileName lookup pid by process name(winlogon.exe)
OpenProcess get process handle of winlogon
OpenProcessToken get privilege token
DuplicateTokenEx get duplicated privilege token
CreateProcessWithTokenW execute program with high privilege same as winlogon by using privilege token

About

Execute programs as system privilege

Resources

Stars

Watchers

Forks

Packages

No packages published

Languages