Breaking Out of Citrix and other Restricted Desktop Environments
ID: 1291c1b4-99cc-5d79-b4c0-0e146ea317e8
STIX ID: report--1291c1b4-99cc-5d79-b4c0-0e146ea317e8
Feed Name: Pen Test Partners Blog
A comprehensive guide to Windows breakout techniques in Citrix/VDI/kiosk environments, detailing methods to pivot from dialogs, obtain shells (cmd/PowerShell), use Task Scheduler and built-in admin tools, exploit Microsoft Edge features (downloads, file dialogs, DevTools, extensions), transfer data via multiple channels, abuse default/weak credentials, and perform binary planting/DLL hijacking. It emphasizes common misconfigurations, highlights risky surfaces (file pickers, print dialogs, device pass-through), and notes relevant policy controls (WDAC/AppLocker, Edge enterprise settings, Citrix policies) to mitigate breakout risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
