logo

Pivoting Between Corporate IT and OT Networks with Network Shell

ID: 5b800f16-8068-532b-8d3b-ec22fe7ec8f2

STIX ID: report--5b800f16-8068-532b-8d3b-ec22fe7ec8f2

Feed Name: Dragos Blog

Threat Score
55/100

Date Published: 2022-03-10

Date Updated: 2026-04-27

...
...

This report demonstrates how the native Windows Netsh utility can be abused to create port-proxy rules that forward RDP from a compromised corporate host into OT/SCADA DMZ assets, enabling lateral movement and potential operational impact; it walks through a penetration-test scenario, persistence and obfuscation considerations, methods to detect such misuse (netstat -b, PowerShell registry queries, network monitoring), and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.