1 min read
Commonly Abused Windows Token Privileges: SeBackupPrivilege
SeBackupPrivilege — Back up files and directories Determines which users can bypass file and directory, registry, and other persistent object...
Henry Zhang
:
Updated on November 4, 2025
Determines which users can bypass file, directory, registry, and other persistent object permissions when they restore backed up files and directories, and it determines which users can set valid security principals as the owner of an object.
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment
Restore files and directories
SeRestorePrivilege
Privilege Escalation (TA0004), Defense Evasion (TA0005), Collection (TA0009), Impact (TA0040)
1 min read
SeBackupPrivilege — Back up files and directories Determines which users can bypass file and directory, registry, and other persistent object...
1 min read
SeTakeOwnershipPrivilege — Take ownership of files or other objects Determines which users can take ownership of any securable object in the device,...
1 min read
SeImpersonatePrivilege — Impersonate a client after authentication Determines which programs are allowed to impersonate a user or another specified...