Lateral Movement
The Double Hop Problem
# After WinRM lateral movement
powershell-import C:\Tools\PowerSploit\Recon\PowerView.ps1
powerpick Get-DomainTrust
ERROR: Exception calling "FindOne" with "0" argument(s): "An operations error occurred."Cached Tickets: (1)
#0> Client: tmorgan @ INLANEFREIGHT.LOCAL
Server: HTTP/ilf-ws-1 @ INLANEFREIGHT.LOCAL
KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96WinRM
PsExec
SCShell (Quieter PsExec)
WMI
MavInject (OPSEC Warning)
SOCKS Proxy
Start SOCKS Proxy
Add Targets to Hosts File
Proxifier (Windows)
AD Enumeration via SOCKS
Kerberos Authentication via SOCKS
Reverse Port Forwards
Example: Forward HTTP to Team Server
Cleanup
Quick Reference
Technique
Runs As
OPSEC
Use Case
Last updated