Lateral Movement
WMI and WinRM
WMI (Windows Management Instrumentation)
WinRS
NOTE: In order for WinRS to work, the user has to be part of the Administrators or Remote Management Users group on the Target Machine
WinRM
PsExec
NOTE: For PsExec to be executed successfully three conditions must be met
The user that authenticates to target machine must be in Administrators local group
ADMIN$ share must be available (Default available)
File and Printer Sharing has to be turned on (Default on)
Pass the hash
NOTE: For Pass the Hash to be executed successfully three conditions must be met
SMB connection through the Firewall (Port 445)
Windows File and Printer Sharing feature to be enabled (Default enabled)
ADMIN$ share to be available (Default available) and Local Administrative Permission
Overpass the Hash
NOTE: For Overpass the Hash to work, must have the NTLM hash of the user
NOTE: Use this when want to access other service as another user
Pass the ticket
NOTE: Use this when want to access other service as another user
DCOM
Last updated