TAKEOWN
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Windows Take Ownership Command. Take ownership of files and folders (requires admin).
BASIC USAGE#
takeown /f filename # Take ownership of file takeown /f foldername # Take ownership of folder takeown /f foldername /r # Recursive takeown /f foldername /r /d y # Skip prompts
SYNTAX#
takeown /f path [/a] [/r] [/d {Y|N}]
/f path # File or folder path
/a # Give ownership to Admins group
/r # Recursive (subdirectories)
/d Y|N # Default answer for prompts
TAKE OWNERSHIP OF FILE#
takeown /f C:\path\file.txt takeown /f C:\path\file.txt /a # Give to Administrators
TAKE OWNERSHIP OF FOLDER#
takeown /f C:\folder takeown /f C:\folder /r # Recursive takeown /f C:\folder /r /d y # Auto-yes to prompts takeown /f C:\folder /r /a /d y # Give to Admins, recursive
CURRENT USER VS ADMINISTRATORS#
takeown /f file.txt # Current user becomes owner takeown /f file.txt /a # Administrators group becomes owner
COMMON SCENARIOS#
SYSTEM FILES#
# Take ownership of system file takeown /f C:\Windows\System32\file.dll /a icacls C:\Windows\System32\file.dll /grant Administrators:F
PROTECTED FOLDERS#
takeown /f "C:\Windows\System32\config" /r /a /d y icacls "C:\Windows\System32\config" /grant Administrators:F /t
PROGRAM FILES#
takeown /f "C:\Program Files\App" /r /a /d y icacls "C:\Program Files\App" /grant Administrators:F /t
USER PROFILE#
# Take ownership of another user's profile takeown /f "C:\Users\OtherUser" /r /a /d y icacls "C:\Users\OtherUser" /grant Administrators:F /t
COMBINED WITH ICACLS#
# Typical workflow: take ownership, then grant permissions # For single file takeown /f file.txt icacls file.txt /grant %USERNAME%:F # For folder (recursive) takeown /f folder /r /d y icacls folder /grant %USERNAME%:F /t # Grant to Administrators takeown /f folder /r /a /d y icacls folder /grant Administrators:F /t
BATCH PROCESSING#
# Process multiple files
for %f in (C:\folder\*.dll) do takeown /f "%f"
# Process with icacls
for %f in (C:\folder\*.dll) do (
takeown /f "%f"
icacls "%f" /grant Administrators:F
)
SECURITY USE CASES#
INCIDENT RESPONSE#
# Access locked malware files takeown /f C:\Users\Public\malware.exe icacls C:\Users\Public\malware.exe /grant Administrators:F del /f C:\Users\Public\malware.exe # Access protected logs takeown /f C:\Windows\Temp\suspicious.log /a icacls C:\Windows\Temp\suspicious.log /grant Administrators:R
RECOVERY#
# Fix broken permissions takeown /f "C:\broken\folder" /r /a /d y icacls "C:\broken\folder" /reset /t # Access encrypted folders (EFS - needs cert) takeown /f "C:\encrypted" /r /a /d y
TRUSTED INSTALLER FILES#
# TrustedInstaller owns many system files # Even Administrators can't modify by default # Step 1: Take ownership takeown /f C:\Windows\System32\drivers\etc\hosts /a # Step 2: Grant permissions icacls C:\Windows\System32\drivers\etc\hosts /grant Administrators:F # Step 3: Make changes... # Step 4: Restore TrustedInstaller ownership icacls C:\Windows\System32\drivers\etc\hosts /setowner "NT SERVICE\TrustedInstaller"
NOTES#
# takeown requires admin privileges # Use with caution on system files # Always backup before modifying system files # Some files need TrustedInstaller ownership restored # takeown cannot: # - Change owner to arbitrary user (only self or Admins) # - Handle ACLs (use icacls for that)
POWERSHELL ALTERNATIVE#
# Take ownership
$acl = Get-Acl file.txt
$owner = New-Object System.Security.Principal.NTAccount("Administrators")
$acl.SetOwner($owner)
Set-Acl file.txt $acl
# Grant full control
$acl = Get-Acl file.txt
$rule = New-Object System.Security.AccessControl.FileSystemAccessRule("Administrators","FullControl","Allow")
$acl.SetAccessRule($rule)
Set-Acl file.txt $acl
QUICK REFERENCE#
# Take ownership takeown /f file.txt # Current user takeown /f file.txt /a # Administrators takeown /f folder /r /d y # Recursive takeown /f folder /r /a /d y # Recursive, Admins # Typical workflow takeown /f path /r /a /d y icacls path /grant Administrators:F /t # Options /f File or folder path /a Give to Administrators /r Recursive /d Y Default yes to prompts