Exploitation of Remote Services

T1210

Technique.View on attack.mitre.org

About this technique

Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.

An adversary may need to determine if the remote system is in a vulnerable state, which may be done through Network Service Discovery or other Discovery methods looking for common, vulnerable software that may be deployed in the network, the lack of certain patches that may indicate vulnerabilities, or security software that may be used to detect or contain remote exploitation. Servers are likely a high value target for lateral movement exploitation, but endpoint systems may also be at risk if they provide an advantage or access to additional resources.

There are several well-known vulnerabilities that exist in common services such as SMB and RDP as well as applications that may be used within internal networks such as MySQL and web server services. Additionally, there have been a number of vulnerabilities in VMware vCenter installations, which may enable threat actors to move laterally from the compromised vCenter server to virtual machines or even to ESXi hypervisors.

Depending on the permissions level of the vulnerable remote service an adversary may achieve Exploitation for Privilege Escalation as a result of lateral movement exploitation as well.

Detection rules19

Rules on DetectionCode tagged with T1210.

Sigma10

RuleLevelLog source
Audit CVE Eventcriticalwindows / NULL
Zerologon Exploitation Using Well-known Toolscriticalwindows / NULL
HackTool - SharpWSUS/WSUSpendu Executionhighwindows / process_creation
OMIGOD HTTP No Authentication RCEhighzeek / NULL
Scanner PoC for CVE-2019-0708 RDP RCE Vulnhighwindows / NULL
Terminal Service Process Spawnhighwindows / process_creation
Apache Threading ErrormediumNULL / NULL
Potential RDP Exploit CVE-2019-0708mediumwindows / NULL
Suspicious SysAidServer Childmediumwindows / process_creation
DNS Query Request By QuickAssist.EXElowwindows / dns_query

Splunk9

RuleTypeRiskData source
Active Directory Lateral Movement IdentifiedCorrelationNULL
Cisco Secure Firewall - Lumma Stealer ActivityTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Static Tundra Smart Install AbuseTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation ActivityTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
Detect Computer Changed with Anonymous AccountHuntingNULLWindows Event Log Security 4742
Linux Suspicious Redis ActivityTTPNULLSysmon for Linux EventID 1
Splunk RCE Through Arbitrary File Write to Windows System RootHuntingNULLSplunk
Splunk RCE via User XSLTHuntingNULL
VMWare Aria Operations Exploit AttemptTTPNULLPalo Alto Network Threat

Groups12

Software13

Campaigns0

None recorded.

Procedure examples25

Groups12

Used byProcedure example
GroupAPT28

APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement.

GroupDragonfly

Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers.

GroupEarth Lusca

Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).

GroupEmber Bear

Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations.

GroupFIN7

FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers.

GroupFox Kitten

Fox Kitten has exploited known vulnerabilities in remote services including RDP.

GroupmenuPass

menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472).

GroupMuddyWater

MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472).

View all 12 groups examples

Software13

Used byProcedure example
MalwareBad Rabbit

Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.

MalwareConficker

Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request.

MalwareEmotet

Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation.

ToolEmpire

Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers.

MalwareFlame

Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally.

MalwareInvisiMole

InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively.

MalwareLucifer

Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144).

MalwareNotPetya

NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.

View all 13 software examples

References6

  1. Ars Technica VMWare Code Execution Vulnerability 2021 Open source
    Dan Goodin . (2021, February 25). Code-execution flaw in VMware has a severity rating of 9.8 out of 10. Retrieved April 8, 2025.
  2. Broadcom VMSA-2024-0019 Open source
    Broadcom. (2024, September 17). VMSA-2024-0019: Questions & Answers. Retrieved April 8, 2025.
  3. CIS Multiple SMB Vulnerabilities Open source
    CIS. (2017, May 15). Multiple Vulnerabilities in Microsoft Windows SMB Server Could Allow for Remote Code Execution. Retrieved April 3, 2018.
  4. NVD CVE-2014-7169 Open source
    National Vulnerability Database. (2017, September 24). CVE-2014-7169 Detail. Retrieved April 3, 2018.
  5. NVD CVE-2016-6662 Open source
    National Vulnerability Database. (2017, February 2). CVE-2016-6662 Detail. Retrieved April 3, 2018.
  6. NVD CVE-2017-0176 Open source
    National Vulnerability Database. (2017, June 22). CVE-2017-0176 Detail. Retrieved April 3, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.