Files
Ares-mythic/documentation-payload/ares/commands/steal_token.md
Aryma 03d283cf49 refactor(payload): rename apollo to ares and update documentation
This commit renames the Apollo payload type to Ares, moving all associated files and updating documentation accordingly. The change includes:
- Renaming directories from `apollo` to `ares`
- Updating documentation image references
- Maintaining the same code functionality while changing the payload name
- Adding new Ares-specific documentation files
- Removing old Apollo documentation files

The rename is done to reflect the new payload name while preserving all existing functionality.
2026-04-14 14:02:44 +07:00

542 B

+++ title = "steal_token" chapter = false weight = 103 hidden = false +++

{{% notice info %}} Artifacts Generated: Process Open {{% /notice %}}

Summary

Steal the primary token from another process. If no target process is specified, winlogon.exe will be the default target.

Arguments (Positional)

pid

The process id to steal a primary access token from. This will default to winlogon.exe if no PID is provided.

Usage

steal_token [pid]

Example

steal_token 1234

MITRE ATT&CK Mapping

  • T1134
  • T1528