PsExec and SMB-based execution - WMI and WinRM remoting - RDP with harvested credentials - Pass-the-hash and pass-the-ticket - DCOM-based execution