Exploring WinRM plugins for lateral movement
ID: 4996befc-142c-5341-b1a9-b0cee64e34a8
STIX ID: report--4996befc-142c-5341-b1a9-b0cee64e34a8
Feed Name: FalconForce
Threat Score
This report demonstrates a proof-of-concept technique for stealthy lateral movement on Windows by installing a custom WinRM plugin DLL into System32, registering it via a manifest, invoking its Put method through COM (WSMan) from a Beacon Object File, and later uninstalling it; the write-up includes full code examples for the DLL and the BOF, operational steps for install/call/uninstall, and notes that Defender detected the technique during testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
