← Back to hub

Windows Token Impersonation Tool Detection

Detects execution of Potato family tools and other Windows token impersonation utilities used to escalate privileges to SYSTEM via named pipe abuse and COM service exploitation

🔒

Premium Content

This query requires an active subscription to access the code.

Get Access