logo

Exploring WinRM plugins for lateral movement

ID: 4996befc-142c-5341-b1a9-b0cee64e34a8

STIX ID: report--4996befc-142c-5341-b1a9-b0cee64e34a8

Feed Name: FalconForce

Threat Score
70/100

Date Published: 2025-01-20

Date Updated: 2026-04-27

Author: Arnau Ortega

...
...

This report demonstrates a proof-of-concept technique for stealthy lateral movement on Windows by installing a custom WinRM plugin DLL into System32, registering it via a manifest, invoking its Put method through COM (WSMan) from a Beacon Object File, and later uninstalling it; the write-up includes full code examples for the DLL and the BOF, operational steps for install/call/uninstall, and notes that Defender detected the technique during testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.