Uploaded June 2025 | Updated September 2026, 2 weeks ago
๐ Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences โ wildwesthackinfest.com
๐ Register for Infosec Webcasts, Anti-casts & Summits. โ poweredbybhis.com
In this presentation, I'll show you the inner mechanics of reverse shells and bind shells, Offensive Windows API use, and the basics of exploit coding in the C programming language all under the umbrella of my personal project, The Impersonator shell.
The Impersonator Shell started as a combination of two popular hacker tools: Netcat and Printspoofer. The exploit is named after the Windows privilege that Printspoofer uses to get administrative access to Windows machines, the SeImpersonate privilege.
This shell abuses the SeImpersonate privilege to create an administrative reverse or bind shell. Users running server software on Windows hosts will commonly have the SEImpersonate enabled. Security engineers who can obtain RCE on said servers can also obtain an administrative shell by abusing the SEImpersonate privilege.
Instead of uploading Netcat and the corresponding kernel exploit, security engineers can use the Impersonator shell. If the inbuilt exploit does not work, security engineers will be provided a non-administrative shell.
The Impersonator shell can connect to a Metasploit listener and be upgraded to a meterpreter shell.
The Impersonator Shell can also leverage native Windows API functions to grab a process and capture information about the token associated with the process.
00:00 - Whoami
00:15 - Overview/Agenda
01:07 - Inspiration/Guiding Ideas
02:14 - Why Impersonator Shell?
04:49 - Windows Token Basics
07:01 - Named Pipes and Process Spawning
08:25 - Impersonation
09:57 - What token permissions look like
11:54 - Sockets
13:06 - Next Steps
14:51 - DEMO
19:48 - Commands Available with Impersonator Shell
22:28 - Q&A - How do commands show up in the event log?
23:36 - Q&A - How do you impersonate System token if youโre not running as system?
24:17 - Q&A - What was the EDR reaction throughout the development?
25:15 - Q&A - What is a legitimate use for Impersonator privileges?
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) โ Wild West Hackin' Fest: wildwesthackinfest.com
๐ Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences โ wildwesthackinfest.com
๐ Register for Infosec Webcasts, Anti-casts & Summits. โ poweredbybhis.com
In this presentation, I'll show you the inner mechanics of reverse shells and bind shells, Offensive Windows API use, and the basics of exploit coding in the C programming language all under the umbrella of my personal project, The Impersonator shell.
The Impersonator Shell started as a combination of two popular hacker tools: Netcat and Printspoofer. The exploit is named after the Windows privilege that Printspoofer uses to get administrative access to Windows machines, the SeImpersonate privilege.
This shell abuses the SeImpersonate privilege to create an administrative reverse or bind shell. Users running server software on Windows hosts will commonly have the SEImpersonate enabled. Security engineers who can obtain RCE on said servers can also obtain an administrative shell by abusing the SEImpersonate privilege.
Instead of uploading Netcat and the corresponding kernel exploit, security engineers can use the Impersonator shell. If the inbuilt exploit does not work, security engineers will be provided a non-administrative shell.
The Impersonator shell can connect to a Metasploit listener and be upgraded to a meterpreter shell.
The Impersonator Shell can also leverage native Windows API functions to grab a process and capture information about the token associated with the process.
00:00 - Whoami
00:15 - Overview/Agenda
01:07 - Inspiration/Guiding Ideas
02:14 - Why Impersonator Shell?
04:49 - Windows Token Basics
07:01 - Named Pipes and Process Spawning
08:25 - Impersonation
09:57 - What token permissions look like
11:54 - Sockets
13:06 - Next Steps
14:51 - DEMO
19:48 - Commands Available with Impersonator Shell
22:28 - Q&A - How do commands show up in the event log?
23:36 - Q&A - How do you impersonate System token if youโre not running as system?
24:17 - Q&A - What was the EDR reaction throughout the development?
25:15 - Q&A - What is a legitimate use for Impersonator privileges?
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) โ Wild West Hackin' Fest: wildwesthackinfest.com




![Exfiltrate and Command Network Nodes Like a Ghost! | Momen Eldawakhly | WWHF 2023
๐ Join us in-person and virtually at our Wild West Hackin Fest: information security conferences โ https://wildwesthackinfest.com/
Our role as โred teamersโ is to try developing techniques that simulate these activities and to improve organisational security by training defensive security teams to check for every single bit (not literally)โฏof data and also anticipate the locations from which attackers may conduct their operations. The technique discussed in this research only shows the basic mindset that can be developed further with each engagement.
Momen Eldawakhly, also known as CyberGuy, is a senior penetration tester at Samurai Digital Security Ltd and red team engineer with a strong track record in security research and red teaming. He has been recognized by major companies such as Google, Yahoo, Microsoft, Yandex, Redhat, AT&T, Oneplus, SecureBug, Starbucks, Comcast, the United Nations, IBM, Nokia, and Sony for discovering critical and high severity vulnerabilities in their assets. Momen is also dedicated to sharing his knowledge with the cybersecurity community, and has given talks and sessions at various conferences and events. Honors: Some of Momenโs notable honors include being featured in conferences such as Black Hat, The Hack Summit, Wild West Hackinโ Fest, IEEE, Hacken, and GDSC. He has also discovered several zero days during his offensive security research, as listed in the publications section of his profile. Certifications: LPT [Master], CPENT ,OSWP, CRTO, CRTP ,eWAPTXv2.
///Black Hills Infosec Socials
Twitter: https://twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: https://www.linkedin.com/company/antisyphon-training
Discord: https://discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: https://www.blackhillsinfosec.com/services/active-soc/
Penetration Testing: https://www.blackhillsinfosec.com/services/
Incident Response: https://www.blackhillsinfosec.com/services/incident-response/
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: https://www.backdoorsandbreaches.com/
Play B&B Online: https://play.backdoorsandbreaches.com/
///Antisyphon Training
Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/
Live Training: https://www.antisyphontraining.com/course-catalog/
On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/
Antisyphon Discord: https://discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/
Wild West Hackin Fest YouTube: https://www.youtube.com/wildwesthackinfest
Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining
Active Countermeasures YouTube: https://youtube.com/activecountermeasures
Threat Hunter Community Discord: https://discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) โ Wild West Hackin Fest: https://wildwesthackinfest.com/ Exfiltrate and Command Network Nodes Like a Ghost! | Momen Eldawakhly | WWHF 2023](https://i.ytimg.com/vi/qCMGdzhJ6nY/mqdefault.jpg)





