Skip to content

added sys.shell changes to allow token usage in its user context if a… - #2395

Merged
hulto merged 3 commits into
spellshift:mainfrom
KS-7250:token-shell
Sep 17, 2026
Merged

hulto merged 3 commits into
spellshift:mainfrom
KS-7250:token-shell

Conversation

@KS-7250

@KS-7250 KS-7250 commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

What type of PR is this?

/kind feature

What this PR does / why we need it:

Realm now has a global token store, but no way to use it. This PR allows the sys.shell() function to take permissions from the active token and apply it to the context of the command run.

In this example, let's say pid 700 is a SYSTEM process, and we impersonated it from Administrator:

$> sys.tokens()

| active | id | source              |
| ------ | -- | ------------------- |
| True   | 1  | impersonate:pid:700 |

$> sys.shell('whoami')['stdout']

nt authority\system

Which issue(s) this PR fixes:

N/A

Comment thread implants/lib/eldritch/stdlib/eldritch-libsys/src/std/shell_impl.rs
Comment thread docs/_docs/user-guide/eldritch.md
Comment thread implants/lib/eldritch/stdlib/eldritch-libsys/src/std/shell_impl.rs
@hulto
hulto added this pull request to the merge queue Sep 17, 2026
@hulto
hulto removed this pull request from the merge queue due to a manual request Sep 17, 2026
@hulto
hulto merged commit c8f9959 into spellshift:main Sep 17, 2026
25 of 26 checks passed
@KS-7250
KS-7250 deleted the token-shell branch September 17, 2026 23:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants