Lateral Movement — SCM and DLL Hijacking Primer
ID: efd5f999-33ef-5ef6-b479-c5ac31b4a9f3
STIX ID: report--efd5f999-33ef-5ef6-b479-c5ac31b4a9f3
Feed Name: SpecterOps Blog
This report analyzes two Windows service DLL hijacks—IKEEXT (wlbsctrl.dll) and SessionEnv (TSMSISrv.dll/TSVIPSrv.dll)—that enable lateral movement by placing malicious DLLs in System32 and restarting services via the Service Control Manager; it details discovery using Procmon and reverse engineering, references proof-of-concept code, and outlines host- and network-based detections and mitigations (e.g., service auditing, Exploit Guard Event ID 11, and RPC/SMB SVCCTL telemetry).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
