Skip to content
HackIndex logo

HackIndex

Windows:

Lateral Movement

Hash, ticket, SMB, WMI, WinRM, RDP, and token lateral moves

6 guides Updated Apr 4, 2026
6 guides

PsExec and SMB Lateral Movement

Covers PsExec-based lateral movement over SMB, including remote execution techniques, admin share abuse, and detection of suspicious PSEXESVC artifacts.

RDP Hijacking and Credential Reuse

Exploits RDP sessions and reused credentials to move laterally across Windows environments, hijacking active sessions without requiring plaintext passwords.

WinRM and PowerShell Remoting Lateral Movement

Exploiting WinRM and PowerShell Remoting to move laterally across Windows environments using Enter-PSSession, Invoke-Command, and evil-winrm.

WMI Remote Execution for Lateral Movement

Leverages WMI to execute commands on remote Windows hosts for lateral movement, covering WMIC, PowerShell invoke methods, and evading common detections.