WinRM 5985 5986
1. Metasploit - WinRM Login Scanner
2. Activate Remotely Using WMIC
3. Bruteforce with CrackMapExec
Bruteforce WinRM with a Username and Password List:
Check Credentials (Username + Password) and Execute CMD Command:
Pass-the-Hash Authentication with PowerShell Command Execution:
4. EvilWinRM
Using EvilWinRM with Username and Password:
Upload/Download Files:
Upload a file to the target:
Download a file from the target:
List All Services:
Load Local PowerShell Scripts:
Menu Listing Loaded Modules: Once inside EvilWinRM, you can view the available modules:
Last updated