Windows Remote Execution: The Techniques Attackers Use to Move Laterally
Lateral movement in a Windows environment rarely involves an exploit. An attacker with valid credentials uses the same remote execution mechanisms administrators use, which is why it looks like legitimate activity and why detection has to be based on pattern rather than on the mechanism itself. How the credentials are obtained is covered under pass-the-hash ; this is what is done with them. Service creation The oldest and most reliable. Connect to the target's administrative share, copy an executable, create a service pointing at it remotely, start the service, then delete it afterwards. The service runs as SYSTEM. It is noisy by modern standards, and it still works everywhere, which is why it remains common. The detection is straightforward: event 7045 records a service installation, and a service created remotely with a random or short name, running from a temporary path, and removed minutes later is not an administrator doing maintenance. WMI Windows Management Instrume...