Lateral Movement in Windows Environments - WMIExec
Preview unavailable
You must log in or sign up to view this lesson.
Login
Sign up
Constructing Defense
Buy now
Learn more
🚨Important Changes Coming to Constructing Defense - Please Read ⚠️
3
Welcome to Constructing Defense!
Welcome & Introduction
Changelog
Lab Overview
Lab Overview
4
General Lab Build Approach
2
Lab Construction
ISO Downloads - Windows Server 2019
2
ISO Downloads - Windows 11
ISO Downloads - Ubuntu
2
ISO Downloads - PCAP
3
Lab Construction - AWS Version
Terraform Setup
9
Domain Controller
Windows 11 A & V
Certer
Linux A & Linux V
2
[Splunk] - Lab Construction & Provisioning - Ludus Version
[Splunk] - Ludus Overview
5
[Splunk] - Ludus Deploy
4
[Splunk] - Ludus Post Deploy Setup
Lab Construction & Provisioning - Ludus Version
Ludus Overview
Ludus Setup
10
Ludus Post Deploy Setup
4
Lab Provisioning
Domain Controller
6
Windows 11 A & V
7
Certer
Linux A & Linux V
4
PCAP
15
PCAP - New Malcolm Version
10
Cloud Accounts - Azure
1
Cloud Accounts - Amazon Web Services (AWS)
1
Kubernetes Setup
Sysmon Setup
7
Telemetry Setup & Miscellaneous Lab Configuration
Section Intro
Windows Auditing and GPO Setup
Disabling Defender
Certificate Enrollment
Linux Auditd + Laurel
19
Sumo Logic SIEM Account
[Sumo Logic] - Windows Event Collection
3
[Sumo Logic] - Linux Event Collection
3
[Legacy] - Kubernetes Monitoring
[Sumo Logic] - Kubernetes Monitoring
5
[Sumo Logic] - Cloud Collection - AWS
5
[Sumo Logic] - Cloud Collection - Azure
5
[Splunk] - Splunk Setup
[Splunk] - Forwarder Setup (Windows)
5
[Splunk] - Forwarder Setup (Linux)
3
[Splunk] - Kubernetes Monitoring
9
[Splunk] - Cloud Collection - AWS
5
[Splunk] - Cloud Collection - Azure/Entra
Lab Executions
Section Intro
Getting to Know Ourselves
3
Our First Shell
1
First Shell - Detection 1
First Shell - Detection 2
Our Second Shell - Exploring the Network Layer
5
Second Shell - Bonus Round
Credential Access on Windows Hosts - LSASS
Credential Access on Windows Hosts - File Shares
1
Credential Access on Windows Hosts - Kerberoasting
Credential Access on Windows Hosts - DCSync
Lateral Movement in Windows Environments - WMIExec
5
Lateral Movement in Windows Environments - PSExec
Discovery/Recon Detection on Windows Hosts
Profiling Rundll32 Executions on Windows Hosts
LOLBAS / LOLBINs
Active Directory Certificate Services
3
Authentication Anomalies on Windows Hosts - The Classic Brute Force
Authentication Anomalies on Windows Hosts - The Kerberos Approach
Credential Access on Linux Hosts - The Shadow File
Credential Access on Linux Hosts - Through a C2 Framework
Lateral Movement on Linux Hosts - Interactive Bash Prompts
Web Shell Detections on Linux Hosts
Kubernetes Threat Detection - Dipping our Toes
Kubernetes Threat Detection - The Host Layer
Kubernetes Threat Detection - The Host Layer - Enumeration
Kubernetes Threat Detection - Tunneling & Exposed Services
Kubernetes Goat 🐐
Kubernetes Threat Detection - Poisoned Pod
Azure - Password Sprays
Azure - MFA Madness
Azure - Wrangling Applications
[Legacy] - Azure - Bad to the Bone
3
[Updated] - Azure - Bad to the Bone
Azure - AzureHound
2
Azure/Entra Session Hijacking via Browser Cookie Theft 🍪
Azure Session Hijack via HAR File
AWS - Account Set Up and CLI Access
2
AWS - CloudTrail - IAM User Creation
AWS - CloudTrail - IAM User Enumeration
AWS - CloudTrail - Pacu - IAM Brute Force
AWS - CloudTrail - Pacu - S3 Bucket Exfil
Adding a bit of Purple
Endpoint Analysis with Hayabusa and Langchain
Kerberos Attacks & Defenses - Pass the Ticket
Kerberos Attacks & Defenses - Golden Ticket
Web Sockets & .NET Assemblies
DPAPI at the Host and Network Layer
Purple Teaming Memory Forensics with MemProcFS
Lab Executions - Splunk
[Splunk] - Getting to Know Ourselves
[Splunk] - Our First Shell
3
[Splunk] First Shell - Detection 1
2
[Splunk] - First Shell - Detection 2
[Splunk] - Our Second Shell - Exploring the Network Layer
2
[Splunk] - Second Shell - Bonus Round
[Splunk] - Credential Access on Windows Hosts - LSASS
[Splunk] - Credential Access on Windows Hosts - File Shares
[Splunk] - Credential Access on Windows Hosts - Kerberoasting
[Splunk] - Credential Access on Windows Hosts - DCSync
[Splunk] - Lateral Movement in Windows Environments - WMIExec
[Splunk] - Lateral Movement in Windows Environments - PSExec
[Splunk] - Discovery/Recon Detection on Windows Hosts
[Splunk] - Profiling Rundll32 Executions on Windows Hosts
[Splunk] - LOLBAS / LOLBINs
[Splunk] - Active Directory Certificate Services
[Splunk] - Authentication Anomalies on Windows Hosts - The Classic Brute Force
[Splunk] - Authentication Anomalies on Windows Hosts - The Kerberos Approach
[Splunk] - Credential Access on Linux Hosts - The Shadow File
[Splunk] - Credential Access on Linux Hosts - Through a C2 Framework
[Splunk] - Lateral Movement on Linux Hosts - Interactive Bash Prompts
[Splunk] - Web Shell Detections on Linux Hosts
[Splunk] - Kubernetes Threat Detection - Dipping our Toes
[Splunk] - Kubernetes Threat Detection - The Host Layer
[Splunk] - Kubernetes Threat Detection - The Host Layer - Enumeration
[Splunk] - Kubernetes Threat Detection - Tunneling & Exposed Services
[Splunk] - Kubernetes Goat 🐐
[Splunk] - Kubernetes Threat Detection - Poisoned Pod
[Splunk] - Azure - Password Sprays
[Splunk] - Azure - MFA Madness
[Splunk] - Azure - Wrangling Applications
[Legacy] - Azure - Bad to the Bone
[Updated] - Azure - Bad to the Bone
[Splunk] - Azure - AzureHound
[Splunk] - Azure/Entra Session Hijacking via Browser Cookie Theft 🍪
[Splunk] - Azure Session Hijack via HAR File
[Splunk] - AWS - Account Set Up and CLI Access
[Splunk] - AWS - CloudTrail - IAM User Creation
[Splunk] - AWS - CloudTrail - IAM User Enumeration
[Splunk] - AWS - CloudTrail - Pacu - IAM Brute Force
[Splunk] - AWS - CloudTrail - Pacu - S3 Bucket Exfil
[Splunk] - Adding a bit of Purple
[Splunk] - Endpoint Analysis with Hayabusa and Langchain
[Splunk] - Kerberos Attacks & Defenses - Pass the Ticket
[Splunk] - Kerberos Attacks & Defenses - Golden Ticket
[Splunk] - Web Sockets & .NET Assemblies
[Splunk] - Purple Teaming Memory Forensics with MemProcFS
Saying Goodbye 👋
Outro
4