WinRM
Connect
Using evil-winrm
# Basic connection
evil-winrm -i target.com -u administrator -p 'password'
# With domain
evil-winrm -i target.com -u 'DOMAIN\username' -p 'password'
# Using hash (Pass-the-Hash)
evil-winrm -i target.com -u administrator -H 'NTHASH'
# Using SSL (port 5986)
evil-winrm -i target.com -u administrator -p 'password' -S
# With custom port
evil-winrm -i target.com -u administrator -p 'password' -P 5985Using PowerShell (from Windows)
Using winrs (Windows Remote Shell)
Using Ruby WinRM Library
Recon
Service Detection with Nmap
Banner Grabbing
Configuration Check
Enumeration
User Enumeration
System Information
Network Enumeration
Process and Service Enumeration
Share Enumeration
Attack Vectors
Brute Force Attack
Pass-the-Hash
Command Execution
Privilege Escalation
Lateral Movement
Post-Exploitation
Persistence
Credential Harvesting
File Operations
Data Exfiltration
Reverse Shell
Domain Reconnaissance
Lateral Movement
Common evil-winrm Commands
Command
Description
Usage
PowerShell Remoting Cmdlets
Cmdlet
Description
Example
Useful Tools
Tool
Description
Primary Use Case
Security Misconfigurations to Test
Last updated