Commonly Abused Windows Token Privileges: SeBackupPrivilege
SeBackupPrivilege — Back up files and directories Determines which users can bypass file and directory, registry, and other persistent object...
Henry Zhang
:
Updated on November 4, 2025
Determines which users can bypass file, directory, registry, and other persistent object permissions when they restore backed up files and directories, and it determines which users can set valid security principals as the owner of an object.
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment
Restore files and directories
SeRestorePrivilege
Privilege Escalation (TA0004), Defense Evasion (TA0005), Collection (TA0009), Impact (TA0040)
SeBackupPrivilege — Back up files and directories Determines which users can bypass file and directory, registry, and other persistent object...
SeTakeOwnershipPrivilege — Take ownership of files or other objects Determines which users can take ownership of any securable object in the device,...
SeImpersonatePrivilege — Impersonate a client after authentication Determines which programs are allowed to impersonate a user or another specified...