No Win32_Process Needed Expanding the WMI Lateral Movement Arsenal

No ratings

Presented at HackinParis2018 2018 by

For quite some time now, WMI has resided in the main roster of techniques used by threat actors to perform lateral movement between endpoints. Despite the vast scope of classes and methods available through WMI, attackers moving laterally seem to rely almost exclusively on the "Create" method of the "Win32_Process" class , diving further into the depths of the WMI model only to perform reconnaissance and establish persistence.