Files
iimp0ster-detection-chokepo…/chokepoints/lateral-movement/remote-execution-tools.yml
T
imposterandClaude Sonnet 4.6 4a836cfa0d feat(detection-tests): add raw log samples and emulation scripts for all chokepoints
Adds RawLogs and EmulationScript fields to all 6 remaining chokepoints and
creates PowerShell emulation scripts that generate real Sysmon/WEL telemetry
for detection validation without requiring live malware.

Chokepoints covered:
- clickfix-techniques: 3 log samples (Sysmon EID 1/3/22), VBScript→PowerShell shim
- renamed-rmm-tools: 3 log samples (Sysmon EID 11/1/3), binary rename + metadata mismatch
- edr-bypass-techniques: 4 log samples (Sysmon EID 6/10, WEL 7036/7040), process handle + service stop
- ransomware-service-manipulation: 5 log samples (Sysmon EID 1, WEL 7036/7040), bulk service kill pattern
- remote-execution-tools: 4 log samples (WEL 4624/5145/7045, Sysmon EID 1), IPC$+random service pattern
- web-shells: 4 log samples (Sysmon EID 11/1/3), w3wp.exe→cmd.exe parent chain

Each emulation script:
- Generates authentic Sysmon/WEL telemetry matching Research/Hunt/Analyst rule logic
- Documents exactly which sigma rule tier each step triggers
- Is safe for isolated lab use (no real malware, no credentials exfiltrated)
- Includes cleanup, verbose mode, and selective skip flags

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-08 20:42:32 -06:00

304 lines
17 KiB
YAML

---
Name: Remote Execution Tools (HackTools)
Id: d4e6f8a0-2b3c-5d7e-9f1a-4c6b8d0e2f4a
MitreIds:
- T1021.002
- T1021.003
- T1021.006
- T1047
- T1053.005
- T1569.002
Tactics:
- Lateral Movement
- Execution
Techniques:
- "Remote Services: SMB/Windows Admin Shares"
- "Remote Services: Distributed Component Object Model"
- "Remote Services: Windows Remote Management"
- "Windows Management Instrumentation"
- "Scheduled Task/Job: Scheduled Task"
- "System Services: Service Execution"
DetectionPriority: HIGH
ThreatPrevalence: HIGH
DetectionDifficulty: MEDIUM
Description: >
Offensive security tools (Impacket, NetExec, CrackMapExec, Evil-WinRM) used for
remote code execution across Windows environments. These frameworks wrap legitimate
Windows protocols (SMB, WMI, WinRM, RPC) to execute code on remote systems using
valid admin credentials. Despite tool diversity, the chokepoint is invariant: valid
admin credentials, network access to target ports, and a remote execution primitive
(service creation, WMI process, scheduled task) are always required.
LastUpdated: "2026-03-07"
Author: "@iimp0ster"
Variations:
- Name: Impacket
FirstSeen: "2015"
Status: Active
Notes: >
Python suite with multiple execution modules:
psexec.py (SMB service creation), smbexec.py (SMB + scheduled tasks),
wmiexec.py (WMI process creation), atexec.py (Task Scheduler),
dcomexec.py (DCOM), rdp_shadow.py (RDP session hijacking, added 2025-01)
- Name: CrackMapExec
FirstSeen: "2016"
Status: Archived
Notes: "Multi-protocol framework covering SMB, WMI, WinRM, MSSQL; original repository archived by maintainer on December 6, 2023 (read-only); superseded by NetExec — defenders should not expect CME-specific signatures to receive community updates"
- Name: NetExec
FirstSeen: "2023"
Status: Active
Notes: Active CrackMapExec fork; adds LDAP, SSH, improved OPSEC features
- Name: Evil-WinRM
FirstSeen: "2019"
Status: Active
Notes: Dedicated WinRM exploitation tool; targets port 5985/5986
- Name: Metasploit psexec
FirstSeen: "2007"
Status: Active
Notes: Original PsExec-style SMB execution via Metasploit framework
- Name: Sliver
FirstSeen: "2020"
Status: Active
Notes: "Open-source C2 framework widely adopted by nation-state and ransomware actors as a Cobalt Strike alternative; built-in lateral movement over SMB/WMI using the same execution primitives this chokepoint detects; used by threat actors following Fortra's crackdown on pirated Cobalt Strike licenses"
- Name: Havoc
FirstSeen: "2022"
Status: Active
Notes: "Modern open-source C2 framework with strong EDR bypass features and lateral movement capabilities; described as 'entry-level C2 for serious criminals'; increasingly observed in intrusions alongside or replacing Impacket; uses the same underlying Windows execution primitives (service creation, WMI, WinRM)"
Prerequisites:
- Valid admin credentials for target system (local or domain)
- Network access to target on required protocol ports (SMB 445, WMI 135, WinRM 5985/5986, RPC 135/139)
- Remote execution capability on target (service creation, WMI, scheduled task, WinRM endpoint enabled)
- Target services must be running (Server service for SMB, WinRM service, etc.)
EvolutionTimeline:
- Date: "2016-Q1"
Event: CrackMapExec released as multi-protocol framework
Change: Combined reconnaissance and lateral movement in one tool; SMB, WMI, WinRM in single interface
DetectionImpact: Detection must cover multiple protocols, not just SMB
TheConstant: "Admin creds + network access + remote execution primitive"
- Date: "2019-Q2"
Event: Evil-WinRM released as dedicated WinRM exploitation tool
Change: Simplified WinRM-specific lateral movement; requires WinRM enabled on target
DetectionImpact: WinRM authentication spike detection becomes important
TheConstant: "Admin creds + network access + remote execution primitive"
- Date: "2023-Q3"
Event: NetExec forked from CrackMapExec
Change: Active development, LDAP/SSH support, improved operational security features
DetectionImpact: No fundamental change to underlying Windows API behaviors
TheConstant: "Admin creds + network access + remote execution primitive"
- Date: "2023-Q4"
Event: CrackMapExec officially archived
Change: Original CME repository archived December 6, 2023; NetExec becomes the de facto community standard; CME-specific binary signatures and detection rules stop receiving community updates
DetectionImpact: Behavioral detection remains valid; tool-specific hash/signature-based detection for CME becomes stale
TheConstant: "Admin creds + network access + remote execution primitive"
- Date: "2025-01"
Event: Impacket adds rdp_shadow.py (PR#2064)
Change: Native RDP session hijacking capability added to Impacket suite
DetectionImpact: Existing RDP session manipulation detection (Event ID 4624 LogonType 10) applies
TheConstant: "Admin creds + network access + remote execution primitive"
Detections:
- Level: Research
Description: Identify network logon events followed by service creation or remote process execution
LogSources:
- "Windows Security Event ID 4624 (Successful Logon)"
- "Windows Security Event ID 4688 (Process Creation)"
- "Windows System Event ID 7045 (Service Installed)"
Logic: >
Event ID: 4624
LogonType: 3 (Network)
Account: Member of local Administrators or Domain Admins
Within 60 seconds: Service creation (7045) OR process creation with elevated token
ExpectedFPRate: High
UseCase: Baseline normal admin activity; understand legitimate remote administration patterns
SigmaRule: sigma-rules/remote-execution/research.yml
- Level: Hunt
Description: Network logon with suspicious service creation (random name or unusual path) or WMI parent process
LogSources:
- "Sysmon Event ID 1 (Process Creation)"
- "Windows Security Event ID 4624 (Logon)"
- "Windows Security Event ID 4697 (Service Installed)"
- "Windows System Event ID 7045 (Service Installed)"
Logic: >
Network Logon (4624, LogonType 3)
AND one of:
Service Created with:
- Name: matches random pattern (8-10 char alpha-numeric)
- Binary Path: \Windows\Temp\ OR \Users\Public\ OR \ProgramData\
OR Process Created with:
- Parent: wmiprvse.exe OR services.exe
- Image: cmd.exe OR powershell.exe
- Path: unusual system paths
ExpectedFPRate: Medium
UseCase: Active hunt for lateral movement campaigns; identifies PsExec-style and WMI execution
SigmaRule: sigma-rules/remote-execution/hunt.yml
- Level: Analyst
Description: Network logon + IPC$ access + suspicious service or multiple hosts in spray pattern
LogSources:
- "Sysmon Event ID 1 (Process Creation)"
- "Sysmon Event ID 3 (Network Connection)"
- "Windows Security Event ID 4624 (Logon)"
- "Windows Security Event ID 4697/7045 (Service)"
- "Windows Security Event ID 5145 (Detailed File Share)"
Logic: >
Network Logon (4624, LogonType 3)
+ IPC$ share access (5145, ShareName = IPC$)
+ Service creation with suspicious characteristics:
Name: 8-10 random alphanumeric characters
Binary: runs from \Windows\Temp\ OR \Users\Public\ OR command is cmd.exe/powershell.exe
OR + Pattern: same source IP accessing 3+ hosts within 10 minutes (spray)
Source IP: internal lateral movement (RFC1918 source to RFC1918 destination)
ExpectedFPRate: Low
UseCase: SOC alerting for active lateral movement; direct IR escalation trigger
SigmaRule: sigma-rules/remote-execution/analyst.yml
Intel:
- Name: MITRE ATT&CK — Impacket Software S0357
URL: https://attack.mitre.org/software/S0357/
Description: Lists every known threat actor (APT groups, ransomware operators) documented using Impacket; far more useful to a defender than the raw GitHub repo for understanding real-world prevalence
- Name: MITRE ATT&CK — T1021.003 DCOM
URL: https://attack.mitre.org/techniques/T1021/003/
Description: Technique definition for DCOM-based lateral movement; covers dcomexec.py usage and detection guidance
- Name: MITRE ATT&CK — T1569.002 Service Execution
URL: https://attack.mitre.org/techniques/T1569/002/
Description: Technique definition for service-based remote execution (psexec/smbexec pattern); the primary detection signal in this chokepoint's hunt and analyst rules
- Name: Microsoft — Storm-0501 Ransomware Hybrid Cloud Attacks
URL: https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/
Description: Documents Storm-0501 using Impacket SecretsDump for lateral movement in hybrid cloud environments; concrete example of Impacket use in a 2024 ransomware campaign
- Name: ThreatLocker — Top 10 Post-Exploitation Tools Threat Actors Use
URL: https://www.threatlocker.com/blog/top-post-exploitation-tools-threat-actors-use
Description: Real-world prevalence data for post-exploitation tooling including Impacket, NetExec, and C2 frameworks observed across actual intrusions
- Name: Impacket GitHub
URL: https://github.com/fortra/impacket
Description: Monitor releases and PRs for new execution modules; source of truth for what capabilities the suite currently covers
- Name: NetExec GitHub
URL: https://github.com/Pennyw0rth/NetExec
Description: Active successor to CrackMapExec; track new protocol support and OPSEC improvements that affect detection
- Name: SOC Investigation — Event ID 5145 Threat Hunting
URL: https://www.socinvestigation.com/threat-hunting-with-eventid-5145-object-access-detailed-file-share/
Description: Detailed guidance on using Event ID 5145 (Detailed File Share) for lateral movement detection; covers IPC$ access correlation
RelatedChokepoints:
- ransomware-service-manipulation
OsintSources:
- Platform: Shodan
Query: 'port:5985 product:"Microsoft HTTPAPI"'
URL: "https://www.shodan.io/search?query=port%3A5985+product%3A%22Microsoft+HTTPAPI%22"
Notes: "Finds internet-exposed WinRM endpoints (Evil-WinRM targets). Use as an exposure audit to identify unintentionally exposed WinRM in your own IP ranges (narrow with 'org:' or 'net:' filters). Port 5986 is the HTTPS variant — run a second query substituting 5986. Note: searching for exposed ports finds your attack surface, not attacker infrastructure — for hunting attacker C2, use the JARM query below."
- Platform: Shodan
Query: 'ssl.jarm:07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5 port:443'
URL: "https://www.shodan.io/search?query=ssl.jarm%3A07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5"
Notes: "Default Cobalt Strike JARM fingerprint. Clusters of hosts sharing this fingerprint are likely Cobalt Strike team servers — the most common C2 framework used alongside Impacket/NetExec in lateral movement chains. JARM fingerprints are more resilient to infrastructure rotation than IP/domain blocklists. Also search for Sliver C2 (ssl.jarm:29d29d00029d29d00042d41d00041d2aa5ce6a70de7ba95aef77a77b00a0af) and check hunt.io for current Havoc signatures."
- Platform: GitHub Code Search
Query: '"wmiexec" OR "smbexec" OR "atexec" path:*.py'
URL: "https://github.com/search?q=%22wmiexec%22+OR+%22smbexec%22+OR+%22atexec%22+path%3A*.py&type=code"
Notes: "Finds community tools and forks built on Impacket execution primitives. Monitor for new modules that extend the execution surface beyond the known chokepoint. This is a tool-tracking query (defender awareness), not infrastructure hunting — results are researcher repos, not attacker infrastructure."
- Platform: hunt.io
URL: "https://hunt.io"
Notes: "Specialized threat hunting platform that maps active C2 infrastructure in real time. Use to search for Cobalt Strike, Sliver, Havoc, and Metasploit infrastructure — the C2 frameworks most commonly paired with Impacket/NetExec lateral movement. The AttackCapture feed tags servers by framework based on banner, certificate, and behavioral fingerprints."
KnownBypasses:
- Bypass: Using legitimate service names that blend in with existing services
Mitigation: Maintain baseline of approved services; alert on new service creation
Detection: Correlate service creation with the binary path and network logon context
- Bypass: Delayed execution after service creation
Mitigation: N/A
Detection: Extend correlation window; focus on IPC$ + service creation regardless of timing
- Bypass: NTLM relay attacks instead of direct credential use
Mitigation: Enable SMB signing and LDAP signing; disable NTLM where possible
Detection: Detect relay patterns (source relays to destination within seconds of receiving auth)
- Bypass: Using legitimate admin tools (psexec.exe from Sysinternals)
Mitigation: Software allowlisting; monitor hash for known-good vs. impersonated versions
Detection: Same IPC$ + service creation pattern applies; tool-agnostic detection covers this
- Bypass: Living Off the Land (LOTL) — built-in Windows admin tools (winrs.exe, wmic /node:, Enter-PSSession, Invoke-Command)
Mitigation: Restrict WinRM and WMI access via Windows Firewall; require PAW (Privileged Access Workstation) for remote admin; log and alert on PowerShell remoting to non-standard targets
Detection: "These tools produce identical event telemetry to Impacket/NetExec (4624 LogonType 3, 4688 wmiprvse.exe child, 7045 service install) but with signed Microsoft binaries — no tool signature to match. Detection must be purely behavioral: network logon + protocol + execution primitive, regardless of which binary produced it. A 2024 analysis found 84% of high-severity attacks now use LOTL techniques."
- Bypass: Kerberos-based lateral movement (Overpass-the-Hash, Pass-the-Ticket, Silver/Golden Tickets)
Mitigation: Enable AES encryption for Kerberos; protect krbtgt account; monitor for anomalous TGS requests
Detection: "Bypasses NTLM-relay mitigations and NTLM-focused detection entirely. Detect via Kerberos anomalies: Event ID 4769 (TGS request) with RC4 encryption when AES is expected; Event ID 4768 (TGT request) from non-DC hosts; unusual ticket lifetime or service name patterns. Impacket's getST.py and Rubeus are common tools for ticket forging."
YaraRules:
- yara-rules/impacket-indicators.yar
RawLogs:
- Type: Windows Event Log
EventId: 4624
Source: Microsoft-Windows-Security-Auditing
Description: Network logon (Type 3) from attacker IP before remote execution
MatchedRules: [Research, Analyst]
Sample: |
EventID: 4624 (An account was successfully logged on)
TimeCreated: 2024-07-09T01:33:47.2284110Z
Channel: Security
LogonType: 3
NewLogonUserName: Administrator
NewLogonDomain: CORP
AuthenticationPackageName: NTLM
LogonProcessName: NtLmSsp
IpAddress: 10.10.50.5
IpPort: 49221
# LogonType=3 (Network) from internal IP — pre-execution authentication
- Type: Windows Event Log
EventId: 5145
Source: Microsoft-Windows-Security-Auditing
Description: IPC$ share access — PsExec/Impacket opens IPC$/svcctl before service creation
MatchedRules: [Analyst]
Sample: |
EventID: 5145 (A network share object was checked for access)
TimeCreated: 2024-07-09T01:33:47.4418230Z
Channel: Security
SubjectUserName: Administrator
ShareName: \\*\IPC$
RelativeTargetName: svcctl
AccessList: %%4416 (ReadData)
IpAddress: 10.10.50.5
# IPC$/svcctl access = opening service control manager over SMB (PsExec/Impacket pattern)
- Type: Windows Event Log
EventId: 7045
Source: Service Control Manager
Description: Random-named service installed from TEMP path — classic PsExec/Impacket signature
MatchedRules: [Research, Hunt, Analyst]
Sample: |
EventID: 7045 (A new service was installed in the system)
TimeCreated: 2024-07-09T01:33:47.8834120Z
Channel: System
ServiceName: xvkbmrfe
ServiceFileName: C:\Windows\Temp\xvkbmrfe.exe
ServiceType: user mode service
ServiceStartType: demand start
ServiceAccount: LocalSystem
# 8-char random name + TEMP binary path = PsExec/Impacket/CrackMapExec pattern
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: cmd.exe spawned from services.exe — service binary executing attacker commands
MatchedRules: [Hunt, Analyst]
Sample: |
EventID: 1 (Process Create)
UtcTime: 2024-07-09 01:33:48.227
ProcessId: 4096
Image: C:\Windows\System32\cmd.exe
CommandLine: cmd.exe /Q /c whoami 1>\\127.0.0.1\ADMIN$\__1720488827.18 2>&1
ParentProcessId: 612
ParentImage: C:\Windows\System32\services.exe
# services.exe → cmd.exe is the canonical PsExec parent chain
# Output redirected to ADMIN$ share — PsExec output capture pattern
EmulationScript:
File: emulation/remote-execution-tools/emulate.ps1
Language: powershell
Description: Simulates network logon, IPC$ access, random-named service creation, and cmd.exe execution
SafetyNotes: Requires Administrator. All activity targets localhost only. Run in isolated lab VM.
AtomicRef: T1021.002