Talk With an Expert

Attacking a Domain with Speed: PowerShell Remoting Versus GPO

Attacking a Domain with Speed: PowerShell Remoting Versus GPO (PDF, 1.21MB)Published: 09 Feb, 2023
Created by:
Justin Weis

An organization sends a mass notification, "We are under attack. Disconnect all devices from the network." By removing any device before the malicious payload executes, the attacker fails to maximize their attack. In a Windows environment, multiple ways exist to execute commands remotely throughout the domain. This paper reviews various attacker techniques and identifies which technique achieves the attacker's objective the fastest. It also demonstrates how defenders can continue the defense once a domain controller is compromised.

Attacking a Domain with Speed: PowerShell Remoting Versus GPO