Academy

Module 5 Β· SSH, RDP, SMB, WinRM β€” The Lateral Movement Highway πŸ”’

Manish Garg
Manish Garg Associate CISSP Β· RingSafe
April 22, 2026
5 min read

SSH, SMB, RDP, WinRM, WMI, and iLO/iDRAC are management protocols β€” designed for administrators to do their jobs. Attackers love them because they’re everywhere, always allowed between admin endpoints and targets, and every organization has weak or reused credentials that reach through them. This module is about why management protocols are the main rails of lateral movement in 2026.

Why this happens

Management protocols are the backbone of IT operations. Admin needs to log into 500 servers. SSH to 500 Linux boxes. RDP to 200 Windows. PowerShell Remoting (WinRM) to automate. WMI for inventory. SCCM agents call home. iLO/iDRAC for out-of-band. Every one of these is an authenticated channel that, once the attacker has the right credentials, gives full control of the target.

Three things make these high-value:

πŸ” Intermediate Module Β· Basic Tier

Continue reading with Basic tier (β‚Ή499/month)

You've read 27% of this module. Unlock the remaining deep-dive, quiz, and every other Intermediate module.

99+ modulesAll levels up to this tier
20-question quizzesUnlimited retries with explanations
Completion certificatesShareable on LinkedIn
5 more sections locked below