← Back to list

Intro to AD Lateral Movement | TryHackMe

Explore AD lateral movement and pivoting using PsExec, WinRM, PtH, and SSH tunnels.

Ryca · 2026-06-04 09:17 · 1 claps · 1.3 min read
#tryhackme #pentesting #cybersecurity #active-directory
Open on Medium ↗
Wiki topics: STP · Startups & Venture 🔒 · Cybersecurity 🎬 · Film & Television 🏛️ · Politics

Intro to AD Lateral Movement | TryHackMe

Explore AD lateral movement and pivoting using PsExec, WinRM, PtH, and SSH tunnels.

Learning Objectives

In this room, we will cover the following lateral movement techniques:

  • Executing commands on remote hosts using PsExec and Evil-WinRM
  • Performing Pass-the-Hash attacks to authenticate with NTLM hashes directly — no plaintext password needed
  • Understanding how Kerberos ticket reuse and Overpass-the-Hash extend lateral movement options
  • Tunnelling through compromised hosts to reach otherwise inaccessible network segments using SSH SOCKS proxies
  • Defensive measures that detect and prevent lateral movement

Answer the questions below

I’m ready to move laterally!

  • What technique allows you to authenticate using an NTLM hash without knowing the plaintext password?

Pass-the-Hash

  • What Windows group, other than Administrators, permits WinRM access to a host?

Remote Management Users

  • What Event ID in the System log is the primary indicator of PsExec-based lateral movement?

7045

  • What is the flag found in flag3a.txt on WRK?

THM{ps3x3c_syst3m_sh3ll}

  • What is the NT hash found in the loot file on WRK?

fa0af7f6a73316dd59f0be812dbf3c12

  • What is the flag found in flag3b.txt on SERVER1?

THM{w1nrm_r3m0t3_sh3ll}

  • What flag is used with NetExec to authenticate against the local SAM database instead of the domain?

— local-auth

  • What is the flag found in flag4.txt on SERVER1?

THM{p4ss_th3_h4sh_ftw}

  • What is the NT hash of the Domain Administrator account found on SERVER1?

2508e1ce9cfcfe1011a74c34297b05ea

  • What Nmap flag must you use instead of -sS when scanning through a SOCKS proxy?

-sT

  • What is the flag found in flag5.txt on the Domain Controller?

THM{d0m41n_c0mpr0m1s3d_v1a_p1v0t}

  • What built-in Windows feature automatically generates unique local admin passwords for each domain-joined machine?

Windows LAPS

  • Windows LAPS

7045


메타데이터
post_id
71b9d5d691fc
slug
intro-to-ad-lateral-movement-tryhackme-71b9d5d691fc
url
https://medium.com/@elaris/intro-to-ad-lateral-movement-tryhackme-71b9d5d691fc
canonical_url
https://medium.com/@elaris/intro-to-ad-lateral-movement-tryhackme-71b9d5d691fc
author_url
https://medium.com/@elaris
status
ok
fetched_at
2026-06-11 05:11:55