logo

WMI Post Exploitation

ID: f89d13cc-054e-5eae-8096-9e540ca6406c

STIX ID: report--f89d13cc-054e-5eae-8096-9e540ca6406c

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

This report demonstrates CrackMapExec usage for post-exploitation: performing multi-threaded WMI remote execution to find valid credentials, dump SAM hashes, run Mimikatz to recover plaintext credentials, and extract NTDS.dit via DRSUAPI — illustrating techniques for credential theft and lateral movement rather than describing a specific incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.