logo

Lateral Movement — SCM and DLL Hijacking Primer

ID: efd5f999-33ef-5ef6-b479-c5ac31b4a9f3

STIX ID: report--efd5f999-33ef-5ef6-b479-c5ac31b4a9f3

Feed Name: SpecterOps Blog

Date Published: 2019-04-18

Date Updated: 2026-04-30

Author: Dwight Hohnstein

...
...

This report analyzes two Windows service DLL hijacks—IKEEXT (wlbsctrl.dll) and SessionEnv (TSMSISrv.dll/TSVIPSrv.dll)—that enable lateral movement by placing malicious DLLs in System32 and restarting services via the Service Control Manager; it details discovery using Procmon and reverse engineering, references proof-of-concept code, and outlines host- and network-based detections and mitigations (e.g., service auditing, Exploit Guard Event ID 11, and RPC/SMB SVCCTL telemetry).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.