logo

Exploring WinRM plugins for lateral movement

ID: 114f5fba-9abd-5f79-80c0-a0ae6624df90

STIX ID: report--114f5fba-9abd-5f79-80c0-a0ae6624df90

Feed Name: FalconForce

Threat Score
70/100

Date Published: 2025-01-20

Date Updated: 2026-06-15

Author: Arnau Ortega

...
...

This report describes a proof-of-concept technique for stealthy lateral movement using custom WinRM plugins: it details building and registering a plugin DLL, invoking its Put method remotely via WinRM/COM to execute payloads, and installation/uninstallation steps (including registry and service manipulation). The author provides code snippets, BOF commands for operator use, observations about the hosting process (winprovhost.exe), and notes on detection by Defender.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.