[COLOR=
"Blue"
]lkd> !process 0 1 windbg.exe[
/COLOR
]
PROCESS 89031da0 SessionId: 0 Cid: 0c68 Peb: 7ffdb000 ParentCid: 0530
DirBase: 09f602e0 ObjectTable: e1f25ba0 HandleCount: 86.
Image: windbg.exe
VadRoot 88c553c0 Vads 87 Clone 0 Private 2296. Modified 3959. Locked 1.
DeviceMap e20447c8
[COLOR=
"Red"
] Token e108d258[
/COLOR
]
ElapsedTime 02:26:28.813
UserTime 00:00:01.171
KernelTime 00:00:06.078
QuotaPoolUsage[PagedPool] 92740
QuotaPoolUsage[NonPagedPool] 3600
Working Set Sizes (now,min,max) (1803, 50, 345) (7212KB, 200KB, 1380KB)
PeakWorkingSetSize 3848
VirtualSize 60 Mb
PeakVirtualSize 61 Mb
PageFaultCount 7861
MemoryPriority BACKGROUND
BasePriority 8
CommitCharge 2704
[COLOR=
"Blue"
]lkd> !token e108d258[
/COLOR
]
_TOKEN e108d258
TS Session ID: 0
User: S-1-5-21-2025429265-1682526488-1801674531-1005
Groups:
00 S-1-5-21-2025429265-1682526488-1801674531-513
Attributes - Mandatory Default Enabled
01 S-1-1-0
Attributes - Mandatory Default Enabled
02 S-1-5-32-544
Attributes - Mandatory Default Enabled Owner
03 S-1-5-32-545
Attributes - Mandatory Default Enabled
04 S-1-5-4
Attributes - Mandatory Default Enabled
05 S-1-5-11
Attributes - Mandatory Default Enabled
06 S-1-5-5-0-5125624
Attributes - Mandatory Default Enabled LogonId
07 S-1-2-0
Attributes - Mandatory Default Enabled
Primary Group: S-1-5-21-2025429265-1682526488-1801674531-513
Privs:
00 0x000000017 SeChangeNotifyPrivilege Attributes - Enabled Default
01 0x000000008 SeSecurityPrivilege Attributes -
02 0x000000011 SeBackupPrivilege Attributes -
03 0x000000012 SeRestorePrivilege Attributes -
04 0x00000000c SeSystemtimePrivilege Attributes -
05 0x000000013 SeShutdownPrivilege Attributes -
06 0x000000018 SeRemoteShutdownPrivilege Attributes -
07 0x000000009 SeTakeOwnershipPrivilege Attributes -
08 0x000000014 SeDebugPrivilege Attributes - Enabled
09 0x000000016 SeSystemEnvironmentPrivilege Attributes -
10 0x00000000b SeSystemProfilePrivilege Attributes -
11 0x00000000d SeProfileSingleProcessPrivilege Attributes -
12 0x00000000e SeIncreaseBasePriorityPrivilege Attributes -
13 0x00000000a SeLoadDriverPrivilege Attributes - Enabled
14 0x00000000f SeCreatePagefilePrivilege Attributes -
15 0x000000005 SeIncreaseQuotaPrivilege Attributes -
16 0x000000019 SeUndockPrivilege Attributes - Enabled
17 0x00000001c SeManageVolumePrivilege Attributes -
18 0x00000001d SeImpersonatePrivilege Attributes - Enabled Default
19 0x00000001e SeCreateGlobalPrivilege Attributes - Enabled Default
Authentication ID: (0,4e3f87)
Impersonation Level: Anonymous
TokenType: Primary
Source: User32 TokenFlags: 0x89 ( Token
in
use )
Token ID: 4f3891 ParentToken ID: 0
Modified ID: (0, 4ffaa5)
RestrictedSidCount: 0 RestrictedSids: 00000000