Technique.View on attack.mitre.org
Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.
An adversary may need to determine if the remote system is in a vulnerable state, which may be done through Network Service Discovery or other Discovery methods looking for common, vulnerable software that may be deployed in the network, the lack of certain patches that may indicate vulnerabilities, or security software that may be used to detect or contain remote exploitation. Servers are likely a high value target for lateral movement exploitation, but endpoint systems may also be at risk if they provide an advantage or access to additional resources.
There are several well-known vulnerabilities that exist in common services such as SMB and RDP as well as applications that may be used within internal networks such as MySQL and web server services. Additionally, there have been a number of vulnerabilities in VMware vCenter installations, which may enable threat actors to move laterally from the compromised vCenter server to virtual machines or even to ESXi hypervisors.
Depending on the permissions level of the vulnerable remote service an adversary may achieve Exploitation for Privilege Escalation as a result of lateral movement exploitation as well.
Rules on DetectionCode tagged with T1210.
| Rule | Level | Log source |
|---|---|---|
| Audit CVE Event | critical | windows / NULL |
| Zerologon Exploitation Using Well-known Tools | critical | windows / NULL |
| HackTool - SharpWSUS/WSUSpendu Execution | high | windows / process_creation |
| OMIGOD HTTP No Authentication RCE | high | zeek / NULL |
| Scanner PoC for CVE-2019-0708 RDP RCE Vuln | high | windows / NULL |
| Terminal Service Process Spawn | high | windows / process_creation |
| Apache Threading Error | medium | NULL / NULL |
| Potential RDP Exploit CVE-2019-0708 | medium | windows / NULL |
| Suspicious SysAidServer Child | medium | windows / process_creation |
| DNS Query Request By QuickAssist.EXE | low | windows / dns_query |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Active Directory Lateral Movement Identified | Correlation | NULL | |
| Cisco Secure Firewall - Lumma Stealer Activity | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - Static Tundra Smart Install Abuse | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Detect Computer Changed with Anonymous Account | Hunting | NULL | Windows Event Log Security 4742 |
| Linux Suspicious Redis Activity | TTP | NULL | Sysmon for Linux EventID 1 |
| Splunk RCE Through Arbitrary File Write to Windows System Root | Hunting | NULL | Splunk |
| Splunk RCE via User XSLT | Hunting | NULL | |
| VMWare Aria Operations Exploit Attempt | TTP | NULL | Palo Alto Network Threat |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement. |
| GroupDragonfly | Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers. |
| GroupEarth Lusca | Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472). |
| GroupEmber Bear | Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations. |
| GroupFIN7 | FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers. |
| GroupFox Kitten | Fox Kitten has exploited known vulnerabilities in remote services including RDP. |
| GroupmenuPass | menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472). |
| GroupMuddyWater | MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472). |
| Used by | Procedure example |
|---|---|
| MalwareBad Rabbit | Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks. |
| MalwareConficker | Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request. |
| MalwareEmotet | Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation. |
| ToolEmpire | Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers. |
| MalwareFlame | Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally. |
| MalwareInvisiMole | InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively. |
| MalwareLucifer | Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144). |
| MalwareNotPetya | NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.