✍️
Red Teaming Experiments
Ctrlk
  • What is this iRed.team?
  • Pinned
    • Pentesting Cheatsheets
    • Active Directory & Kerberos Abuse
  • offensive security
    • Red Team Infrastructure
    • Initial Access
    • Code Execution
    • Code & Process Injection
    • Defense Evasion
    • Enumeration and Discovery
    • Privilege Escalation
    • Credential Access & Dumping
    • Lateral Movement
      • T1028: WinRM for Lateral Movement
      • WinRS for Lateral Movement
      • T1047: WMI for Lateral Movement
      • T1076: RDP Hijacking for Lateral Movement with tscon
      • T1051: Shared Webroot
      • T1175: Lateral Movement via DCOM
      • WMI + MSI Lateral Movement
      • Lateral Movement via Service Configuration Manager
      • Lateral Movement via SMB Relaying
      • WMI + NewScheduledTaskAction Lateral Movement
      • WMI + PowerShell Desired State Configuration Lateral Movement
      • Simple TCP Relaying with NetCat
      • Empire Shells with NetNLTMv2 Relaying
      • Lateral Movement with Psexec
      • From Beacon to Interactive RDP Session
      • SSH Tunnelling / Port Forwarding
      • Lateral Movement via WMI Event Subscription
      • Lateral Movement via DLL Hijacking
      • Lateral Movement over headless RDP with SharpRDP
      • ShadowMove: Lateral Movement by Duplicating Existing Sockets
    • Persistence
    • Exfiltration
  • reversing, forensics & misc
    • Windows Internals
    • Cloud
    • Neo4j
    • Dump Virtual Box Memory
    • AES Encryption Using Crypto++ .lib in Visual Studio C++
    • Reversing Password Checking Routine
Powered by GitBook
On this page

Was this helpful?

  1. offensive security

Lateral Movement

T1028: WinRM for Lateral MovementWinRS for Lateral MovementT1047: WMI for Lateral MovementT1076: RDP Hijacking for Lateral Movement with tsconT1051: Shared WebrootT1175: Lateral Movement via DCOMWMI + MSI Lateral MovementLateral Movement via Service Configuration ManagerLateral Movement via SMB RelayingWMI + NewScheduledTaskAction Lateral MovementWMI + PowerShell Desired State Configuration Lateral MovementSimple TCP Relaying with NetCatEmpire Shells with NetNLTMv2 RelayingLateral Movement with PsexecFrom Beacon to Interactive RDP SessionSSH Tunnelling / Port ForwardingLateral Movement via WMI Event SubscriptionLateral Movement via DLL HijackingLateral Movement over headless RDP with SharpRDPShadowMove: Lateral Movement by Duplicating Existing Sockets
PreviousCredentials Collection via CredUIPromptForCredentialsNextT1028: WinRM for Lateral Movement

Last updated 4 years ago

Was this helpful?