Case 66357B · Network · L3 Applied
Lateral Movement over SMB/RDP
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- SMB admin shares (C$, ADMIN$) plus service creation (PsExec, Event 7045) give remote execution with admin creds
- Pass-the-hash authenticates over NTLM with the NT hash; shows as Event 4624 logon type 3 with NTLM package
- RDP logons show as 4624 type 10; RDP from workstation to workstation is a strong anomaly signal
- Other paths: WMI (wmiprvse spawning processes), WinRM on 5985/5986, DCOM, and scheduled tasks
- Controls: block SMB/RDP between workstations, LAPS, tiered admin model, Credential Guard, restrict NTLM
If the interviewer pushes back
- How would you distinguish legitimate IT admin PsExec use from attacker use in your SIEM?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.