✍️
Red Teaming Experiments
search
⌘Ctrlk
✍️
Red Teaming Experiments
  • What is this iRed.team?
  • Pinned
    • Pentesting Cheatsheets
    • Active Directory & Kerberos Abuse
  • offensive security
    • Red Team Infrastructure
    • Initial Access
    • Code Execution
    • Code & Process Injection
    • Defense Evasion
    • Enumeration and Discovery
    • Privilege Escalation
    • Credential Access & Dumping
    • Lateral Movement
      • T1028: WinRM for Lateral Movement
      • WinRS for Lateral Movement
      • T1047: WMI for Lateral Movement
      • T1076: RDP Hijacking for Lateral Movement with tscon
      • T1051: Shared Webroot
      • T1175: Lateral Movement via DCOM
      • WMI + MSI Lateral Movement
      • Lateral Movement via Service Configuration Manager
      • Lateral Movement via SMB Relaying
      • WMI + NewScheduledTaskAction Lateral Movement
      • WMI + PowerShell Desired State Configuration Lateral Movement
      • Simple TCP Relaying with NetCat
      • Empire Shells with NetNLTMv2 Relaying
      • Lateral Movement with Psexec
      • From Beacon to Interactive RDP Session
      • SSH Tunnelling / Port Forwarding
      • Lateral Movement via WMI Event Subscription
      • Lateral Movement via DLL Hijacking
      • Lateral Movement over headless RDP with SharpRDP
      • ShadowMove: Lateral Movement by Duplicating Existing Sockets
    • Persistence
    • Exfiltration
  • reversing, forensics & misc
    • Windows Internals
    • Cloud
    • Neo4j
    • Dump Virtual Box Memory
    • AES Encryption Using Crypto++ .lib in Visual Studio C++
    • Reversing Password Checking Routine
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. offensive security

Lateral Movement

T1028: WinRM for Lateral Movementchevron-rightWinRS for Lateral Movementchevron-rightT1047: WMI for Lateral Movementchevron-rightT1076: RDP Hijacking for Lateral Movement with tsconchevron-rightT1051: Shared Webrootchevron-rightT1175: Lateral Movement via DCOMchevron-rightWMI + MSI Lateral Movementchevron-rightLateral Movement via Service Configuration Managerchevron-rightLateral Movement via SMB Relayingchevron-rightWMI + NewScheduledTaskAction Lateral Movementchevron-rightWMI + PowerShell Desired State Configuration Lateral Movementchevron-rightSimple TCP Relaying with NetCatchevron-rightEmpire Shells with NetNLTMv2 Relayingchevron-rightLateral Movement with Psexecchevron-rightFrom Beacon to Interactive RDP Sessionchevron-rightSSH Tunnelling / Port Forwardingchevron-rightLateral Movement via WMI Event Subscriptionchevron-rightLateral Movement via DLL Hijackingchevron-rightLateral Movement over headless RDP with SharpRDPchevron-rightShadowMove: Lateral Movement by Duplicating Existing Socketschevron-right
PreviousCredentials Collection via CredUIPromptForCredentialschevron-leftNextT1028: WinRM for Lateral Movementchevron-right

Last updated 4 years ago