Crossing the Line: Advanced Techniques to Breach the OT DMZ

Christopher Nourrie

DEF CON 33 · Day 1 · Main Stage

Overview

This talk, presented by Christopher Nourrie at DEF CON, delves into advanced penetration testing techniques specifically designed to breach the Operational Technology (OT) Demilitarized Zone (DMZ) from a compromised enterprise IT network. Nourrie, an experienced OT pentester, outlines a series of methods that attackers can leverage, even when faced with seemingly robust security controls like multifactor authentication (MFA). The core objective is to demonstrate how initial access within the IT domain can be escalated to gain control over critical OT systems, often by exploiting common misconfigurations and human factors in remote access architectures.

Watch on YouTube

Visual summary for Crossing the Line: Advanced Techniques to Breach the OT DMZ by Christopher Nourrie
Visual summary for Crossing the Line: Advanced Techniques to Breach the OT DMZ by Christopher Nourrie

Key moments

  1. 0:00 Initial approach: Compromising enterprise and remote access types
  2. 0:50 Harvesting RDP saved credentials from user workstations
  3. 2:00 Leveraging group membership to gain OT network access
  4. 2:40 Seth RDP: Man-in-the-middle attack for RDP credentials
  5. 3:25 Most common technique: RDP Session Hijacking (TSCON)
  6. 6:00 Remote Desktop Shadowing: Stealthy monitoring of user sessions
  7. 7:20 Highly OPSec: Hidden Desktop (HBNC) for stealthy access

Crossing the Line: Advanced Techniques to Breach the OT DMZ

Speakers: Christopher Nourrie

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=Qf7oNWKGL2I

Overview

This talk, presented by Christopher Nourrie at DEF CON, delves into advanced penetration testing techniques specifically designed to breach the Operational Technology (OT) Demilitarized Zone (DMZ) from a compromised enterprise IT network. Nourrie, an experienced OT pentester, outlines a series of methods that attackers can leverage, even when faced with seemingly robust security controls like multifactor authentication (MFA). The core objective is to demonstrate how initial access within the IT domain can be escalated to gain control over critical OT systems, often by exploiting common misconfigurations and human factors in remote access architectures.

The presentation systematically dissects various attack vectors, ranging from low-level credential harvesting and group manipulation to sophisticated session hijacking and hidden desktop techniques. It highlights the critical vulnerabilities that arise from implicit trust relationships between IT and OT environments, misconfigured jump servers, and inadequate network segmentation. Understanding these methods is paramount for organizations striving to secure their industrial control systems (ICS) and critical infrastructure, as it provides a red team perspective on how determined adversaries can circumvent typical defenses and pivot into sensitive operational networks.

The talk underscores the persistent challenge of securing the IT/OT boundary, revealing that even with substantial investments in IT security, specific architectural and operational oversights can leave the OT environment exposed. By detailing the practical steps and tools involved in these attacks, Nourrie equips defenders with the knowledge necessary to anticipate, detect, and mitigate real-world threats to their industrial environments.

Background

▶ Watch: Initial approach: Compromising enterprise and remote access types (0:00)

The premise of the talk assumes an attacker has already achieved initial compromise within the enterprise IT network, typically gaining domain admin privileges. While domain admin simplifies many subsequent steps, the speaker emphasizes that it is not always a prerequisite for success. The central challenge addressed is the pivot from this compromised IT environment into the more sensitive OT DMZ, which often houses critical control systems, SCADA (Supervisory Control and Data Acquisition) components, and other industrial assets.

The existence of an OT DMZ itself is a recognition of the need to segment IT and OT networks, creating a buffer zone. However, the methods by which IT users and third-party vendors access the OT DMZ often introduce vulnerabilities. Common remote access architectures include RDP jump servers, remote access proxies, and VPN gateways. Operators frequently connect to these systems daily, and convenience can lead to security shortcuts, such as saving RDP credentials or leveraging implicit trust.

Historically, IT and OT networks have evolved with differing priorities—IT focused on confidentiality and integrity, OT on availability and safety. This divergence can lead to architectural inconsistencies, where IT-managed infrastructure within or bordering the OT DMZ may not adhere to the same stringent security standards as the OT components themselves. Furthermore, the reliance on external IT teams or third-party vendors to manage network infrastructure can introduce misconfigurations, such as overly permissive firewall rules or default services left exposed on critical jump servers, inadvertently creating pathways for attackers to "cross the line." The problem is exacerbated by the common practice of sharing identity stores (like Active Directory) between IT and OT, meaning an IT compromise can directly lead to OT access.

Key Findings

▶ Watch: Leveraging group membership to gain OT network access (2:00)

Christopher Nourrie's talk illuminates several critical findings regarding the breach of OT DMZs:

  1. MFA Bypass is Achievable: Despite the widespread adoption of multifactor authentication, several techniques allow attackers to bypass or circumvent MFA mechanisms designed to protect remote access to the OT DMZ. These methods often exploit the underlying session management or network configurations rather than directly cracking MFA.
  2. Session-Based Attacks are Highly Effective: Hijacking or shadowing existing, authenticated user sessions (which have already completed MFA) is a primary and highly effective method for gaining access to the OT network. This includes techniques like Remote Desktop Session Hijacking and Hidden Desktop (HBNC).
  3. Misconfigurations Create Critical Exposure: Implicit firewall rules, default open ports (e.g., WinRM, SMB) on jump servers, and the exposure of management interfaces (e.g., for BMCs, UPS devices) from the enterprise network directly into the OT DMZ are frequently observed and provide straightforward bypasses.
  4. Operational Convenience Overrides Security: The need for operators and engineers to easily access OT systems often leads to practices like saving RDP credentials, weak group assignments, and less stringent security on remote access components, which attackers readily exploit.
  5. Stealth Varies Significantly: While some attacks (like session hijacking) are noisy and noticeable to the user, highly OpSec (operational security) techniques like Hidden Desktop allow attackers to operate within the OT environment without detection by the legitimate user.
  6. Identity Store Separation is Crucial: The lack of separate identity stores (e.g., Active Directory domains) between IT and OT environments means that a compromise of IT credentials often grants direct access to OT resources, highlighting a fundamental architectural flaw.
  7. Dual-Homed Jump Servers are a Major Risk: Jump servers configured with network interfaces in both the IT and OT networks provide attackers with an immediate foothold for enumerating and scanning the OT environment, significantly simplifying lateral movement.

Technical Deep Dive

▶ Watch: Seth RDP: Man-in-the-middle attack for RDP credentials (2:40)

The technical content of Nourrie's presentation details a progression of attack techniques, starting from simpler methods and moving towards more sophisticated and stealthy approaches, all predicated on an initial compromise of the enterprise IT network, typically with domain administrator privileges.

  1. RDP Saved Credentials and Group Membership:
  • RDP Saved Credentials: Attackers target user workstations that frequently remote into the OT DMZ. Operators often save their credentials in Remote Desktop Protocol (RDP) files to avoid repeatedly typing them. Tools like Shar DB API or Mimikats can be used to harvest these clear-text credentials from .rdp files or memory. While MFA would prevent direct masquerading, these credentials are often reused within the OT network, making them valuable for post-MFA lateral movement.
  • Group Membership: With domain admin, attackers identify groups associated with OT users and simply add themselves to these groups. This can grant access to the same OT resources without further authentication, though MFA can still be a barrier for initial access.
  1. Seth RDP:
  • This is a Man-in-the-Middle (MITM) attack designed to intercept RDP credentials. It works by placing the attacker in the same subnet as the target workstation and the RDP jump server. While effective for capturing clear-text credentials, its practical application is limited to smaller, flat networks (e.g., wastewater treatment plants) due to the subnet requirement. MFA would prevent immediate pivot, but captured credentials could be reused.
  1. Remote Desktop Session Hijacking (tscon.exe):
  • This is a highly common and effective technique. It requires an NT AUTHORITY\SYSTEM level shell on the target jump server or operator workstation (easily achieved via tools like psexec or Task Manager).
  • The attacker first uses query user to list all active RDP sessions on the host, identifying the target user's session ID.
  • Then, tscon.exe <session_ID> is executed. This command detaches the legitimate user's session and reattaches it to the attacker's shell, effectively "bumping" the user off and taking over their already authenticated RDP session into the OT DMZ.
  • Key Advantage: It bypasses MFA entirely as the user has already completed it.
  • Disadvantage: It is not OpSec; the legitimate user is disconnected and will notice. Collaboration with the user is often required in penetration tests to avoid disruption.
  1. Remote Desktop Shadowing (mstsc.exe / shadow.exe):
  • Similar to session hijacking but requires only local administrator privileges, not NT AUTHORITY\SYSTEM.
  • Requires a minor registry edit to enable shadowing without consent.
  • The attacker uses mstsc.exe /shadow:<session_ID> /control /noConsentPrompt or shadow.exe <session_ID> /noConsentPrompt.
  • Key Advantage: The /noConsentPrompt flag means the user is unaware their session is being viewed. This is more OpSec than full session hijacking for passive monitoring.
  • Disadvantage: While the attacker can view the desktop, interactive control (moving the mouse, typing) will be visible to the legitimate user, limiting its stealth for active manipulation.
  1. Hidden Desktop (HBNC - Hidden Backdoor New Console):
  • This is presented as a highly OpSec technique.
  • After pivoting to an end-user workstation that is already connected to the OT DMZ, the attacker launches a "hidden desktop" tool.
  • Tools mentioned include an open-source solution by White Knight Labs, commercial tools from OST and Fortra, and Cobalt Strike's hidden_desktop functionality.
  • Mechanism: The tool creates a separate, invisible desktop session that piggybacks on the user's existing authenticated connection. The attacker gains a graphical user interface (GUI) view of the user's desktop but can interact with it (run commands, open prompts) without the legitimate user seeing any activity on their screen.
  • Key Advantage: Completely bypasses MFA and is extremely stealthy, allowing attackers to operate undetected within the OT environment.
  1. Implicit Firewall Rules and Misconfigured Management Interfaces:
  • Often found in larger organizations or where third-party IT manages infrastructure.
  • Problem: Firewalls between the enterprise and OT DMZ have implicit rules allowing broad access from the IT network to management interfaces within the OT DMZ.
  • Targets: Network switches, routers, firewalls, BMC devices (e.g., Dell iDRAC, HP iLO), and UPS devices.
  • Access: Via protocols like SSH, Telnet, or web interfaces.
  • Exploitation: Attackers can discover these exposed interfaces, often combine this with default credentials, and then use SSH tunneling to pivot deeper into the OT DMZ, completely circumventing the intended remote access design. The speaker provided an example of accessing a UPS interface over Telnet, enabling SSH, and then using SSH tunneling.
  1. Jump Server Misconfigurations (WinRM/SMB Bypass):
  • Even when jump servers enforce MFA for RDP, they frequently have other services enabled by default, such as Windows Remote Management (WinRM) or Server Message Block (SMB).
  • Exploitation: Attackers with domain admin can use tools like Evo WinRM or PS Remoting to execute commands on the jump server via these alternative ports (e.g., 5985 for WinRM, 445 for SMB) without needing to satisfy the RDP-specific MFA.
  • Once command execution is achieved on the jump server, the attacker can then perform any of the session hijacking, shadowing, or hidden desktop attacks from the jump server itself, effectively bypassing the MFA protecting the RDP login.
  • This highlights the critical importance of hardening jump servers by closing all unnecessary ports and placing them securely behind firewalls.

Demo / Proof of Concept

▶ Watch: Remote Desktop Shadowing: Stealthy monitoring of user sessions (6:00)

While the talk did not feature a live, interactive demonstration of each attack, Christopher Nourrie thoroughly described the practical execution of each technique, detailing the specific commands and tools used. For instance, he explicitly mentioned tscon.exe for session hijacking, query user to enumerate sessions, mstsc.exe or shadow.exe with the /noConsentPrompt flag for RDP shadowing, and Cobalt Strike's hidden_desktop for the highly stealthy hidden desktop attack.

The speaker presented screenshots of command-line outputs, such as a query user result showing multiple active sessions on a jump server and a UPS interface accessed over Telnet, illustrating the initial steps an attacker would take. He also discussed the scenarios and conditions under which each attack would be viable, drawing from his experience as an OT pentester. The detailed descriptions provide a clear understanding of the proof-of-concept for each method, allowing the audience to grasp how these vulnerabilities are exploited in real-world engagements.

Defensive Implications

▶ Watch: Highly OPSec: Hidden Desktop (HBNC) for stealthy access (7:20)

The talk provides crucial insights for defenders aiming to secure their OT DMZs against sophisticated attacks. The primary defensive strategies revolve around hardening remote access paths, strengthening segmentation, enhancing detection, and implementing robust identity management.

  1. Detection Opportunities:
  • Remote Desktop Session Hijacking (tscon.exe): Relatively easy to detect. Defenders should monitor for the execution of tscon.exe on jump servers or user workstations. This command is not typically used by legitimate users for routine operations.
  • RDP Shadowing (shadow.exe): Monitor for shadow.exe execution, especially with the /noConsentPrompt flag. While IT support may use shadowing, they usually seek consent. An unconsented shadow session is a high-fidelity indicator of malicious activity.
  • Hidden Desktop (HBNC): This is significantly more difficult to detect. It requires monitoring low-level API calls related to desktop switching or creation (e.g., SwitchDesktop, CreateDesktop). This can be resource-intensive, requiring advanced endpoint detection and response (EDR) capabilities or specialized tools. Detection might also rely on identifying the command and control (C2) beacon associated with tools like Cobalt Strike, potentially using YARA rules, though this also presents scalability challenges in large environments.
  • Windows Event Logs: Monitor for specific Windows Event IDs:
  • 4624: Successful logon events. Look for unusual logon patterns or sources.
  • 4634: Logoff events. Correlate with tscon.exe usage, as hijacking will cause a logoff for the legitimate user.
  • 4778: A session was reconnected to a Window Station. This can indicate session hijacking or legitimate reconnections, requiring context.
  • Suspicious SMB Pipes: Monitoring for unusual SMB pipe activity can also be an indicator of lateral movement or tool usage, though this can be noisy in large organizations.
  1. Hardening the OT DMZ:
  • Secure Remote Access Paths:
  • Implement Multifactor Authentication (MFA) for all remote access to the OT DMZ, not just for initial RDP logins. This includes VPNs, remote access proxies, and any management interfaces.
  • Separate Protocols: Where possible, separate remote access methods by protocol. For example, using standard RDP for one type of access and RDP over Web (HTTPS) for another. This can hinder session hijacking, as attacks like tscon.exe may not work across different protocol implementations (e.g., port 3389 vs. 80/443).
  • Strengthen Segmentation Points:
  • Firewall Jump Servers: Critical jump servers must be placed behind a firewall. Do not expose them directly to the enterprise network.
  • Network Address Translation (NAT): Implement NAT for jump servers to further obfuscate their internal IP addresses and add a layer of segmentation.
  • Strict Port Hardening: On jump servers, close all unnecessary ports. If a jump server is intended only for RDP, then only port 3389 (or the custom RDP port) should be accessible. Services like WinRM (port 5985/5986) and SMB (port 445) should be disabled or strictly firewalled if not explicitly required, as they can provide bypasses for MFA.
  • Review Implicit Firewall Rules: Conduct thorough audits of firewall rules between IT and OT, especially looking for broad "allow all" or overly permissive rules that grant enterprise-wide access to OT management interfaces (e.g., network switches, BMCs, UPS devices).
  • Separate Identity Stores:
  • Crucially, implement separate identity stores (e.g., distinct Active Directory domains) for the IT enterprise and the OT DMZ. This prevents an IT domain compromise from automatically granting access to OT resources. The speaker noted seeing OT DMZs running in a workgroup, which, while complex for management, inherently provides this separation.
  • Avoid Dual-Homed Jump Servers: Jump servers should not have network interfaces in both the IT and OT networks simultaneously. This configuration provides an immediate and easy path for attackers to enumerate and scan the OT network from a compromised jump server. Instead, enforce a strict one-leg-in-one-leg-out policy, typically requiring a separate hop or specific routing through a firewall.
  • Enhance Detection and Visibility: Beyond specific event IDs, implement comprehensive logging and monitoring across the IT/OT boundary. Leverage security information and event management (SIEM) systems to correlate events and detect anomalous behavior.

Key Takeaways

  • MFA is Not a Panacea: Multifactor authentication, while essential, can be bypassed by exploiting underlying remote access mechanisms, session management flaws, or misconfigured services on jump servers.
  • Session Hijacking and Hidden Desktops are Potent: Techniques like Remote Desktop Session Hijacking (tscon.exe) and especially Hidden Desktop (HBNC) allow attackers to leverage existing authenticated user sessions to gain stealthy access to the OT DMZ, bypassing MFA.
  • Misconfigurations Create Easy Bypasses: Implicit firewall rules, exposed management interfaces (BMC, UPS), and default services like WinRM or SMB left open on jump servers are frequently overlooked vulnerabilities that provide direct pathways into the OT DMZ.
  • Strict Segmentation is Paramount: Hardening jump servers by closing unnecessary ports, placing them behind firewalls, and avoiding dual-homed configurations is critical. Separate identity stores between IT and OT are fundamental to prevent IT compromises from spilling into OT.
  • Detection Requires Deep Visibility: Detecting advanced attacks like Hidden Desktop necessitates monitoring low-level API calls for desktop manipulation or robust C2 beacon detection, which can be resource-intensive but vital.
  • Operational Security (OpSec) Varies: Attackers can choose between "noisy" attacks that disrupt users (session hijacking) and highly stealthy methods (Hidden Desktop) depending on their objectives and risk tolerance.

About the Speaker(s)

Christopher Nourrie is an experienced OT pentester. Throughout his talk, he frequently refers to "we" and "our" tactics, clearly indicating his professional background in performing penetration tests against Operational Technology environments. His insights are drawn directly from practical experience in evaluating the security posture of industrial control systems and critical infrastructure, providing a red team perspective on how adversaries can breach the IT/OT boundary.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent OT pentest tradecraft talk covering the IT-to-OT pivot problem with solid practitioner credibility and clear defensive takeaways. Nothing here is novel for anyone who's done this work, but the systematic treatment of bypass techniques against RDP-centric remote access architectures is well-organized and grounded in real engagements.

Heather Calloway (CISO) — WEAK

Technically competent OT red team content with real defender utility at the practitioner level, but it doesn't reach the institutional audience that actually owns this risk. The governance gap — why these misconfigurations persist, who is accountable for the IT/OT boundary, and what decisions need to change at the program or board level — goes unaddressed.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33