We Don't Need No Stinkin' PSExec
ID: 239e22b1-048e-5777-b2dd-6a5bb7a05f19
STIX ID: report--239e22b1-048e-5777-b2dd-6a5bb7a05f19
Feed Name: TrustedSec blog
This report is a technical walkthrough showing how attackers or pentesters can use WMI and related tools (impacket wmiexec, pth-wmis/pth-wmic, Metasploit web_delivery) to perform remote, diskless code execution and lateral movement on Windows systems using either plaintext credentials or hashed credentials (pass-the-hash). It demonstrates command examples, base64-encoded PowerShell payload delivery, and notes AV detection issues with PSExec-style approaches while emphasizing WMI/RPC as a stealthier alternative for remote administration and compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
