Pivoting Between Corporate IT and OT Networks with Network Shell
ID: 5b800f16-8068-532b-8d3b-ec22fe7ec8f2
STIX ID: report--5b800f16-8068-532b-8d3b-ec22fe7ec8f2
Feed Name: Dragos Blog
Threat Score
This report demonstrates how the native Windows Netsh utility can be abused to create port-proxy rules that forward RDP from a compromised corporate host into OT/SCADA DMZ assets, enabling lateral movement and potential operational impact; it walks through a penetration-test scenario, persistence and obfuscation considerations, methods to detect such misuse (netstat -b, PowerShell registry queries, network monitoring), and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
