Open cardosec

Case 66357B · Network · L3 Applied

Lateral Movement over SMB/RDP

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. SMB admin shares (C$, ADMIN$) plus service creation (PsExec, Event 7045) give remote execution with admin creds
  2. Pass-the-hash authenticates over NTLM with the NT hash; shows as Event 4624 logon type 3 with NTLM package
  3. RDP logons show as 4624 type 10; RDP from workstation to workstation is a strong anomaly signal
  4. Other paths: WMI (wmiprvse spawning processes), WinRM on 5985/5986, DCOM, and scheduled tasks
  5. Controls: block SMB/RDP between workstations, LAPS, tiered admin model, Credential Guard, restrict NTLM

If the interviewer pushes back

  • How would you distinguish legitimate IT admin PsExec use from attacker use in your SIEM?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.