Windows:
Lateral Movement
Hash, ticket, SMB, WMI, WinRM, RDP, and token lateral moves
Pass-the-Hash and Pass-the-Ticket
PsExec and SMB Lateral Movement
Covers PsExec-based lateral movement over SMB, including remote execution techniques, admin share abuse, and detection of suspicious PSEXESVC artifacts.
RDP Hijacking and Credential Reuse
Exploits RDP sessions and reused credentials to move laterally across Windows environments, hijacking active sessions without requiring plaintext passwords.
WinRM and PowerShell Remoting Lateral Movement
Exploiting WinRM and PowerShell Remoting to move laterally across Windows environments using Enter-PSSession, Invoke-Command, and evil-winrm.
WMI Remote Execution for Lateral Movement
Leverages WMI to execute commands on remote Windows hosts for lateral movement, covering WMIC, PowerShell invoke methods, and evading common detections.