Impacket WMI Query

Execute WMI queries on a remote host to enumerate processes, services, and system info

Tool
impacket-wmiquery
Category
Post-Exploitation / AD Object Manipulation
Platform
linux
Requires
password
Protocols
WMI

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-wmiquery '<domain>/<user>:<password>'@'<ip>' -namespace 'root\cimv2' -query 'SELECT * FROM Win32_Process'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-wmiquery -hashes ':<hash>' '<domain>/<user>'@'<ip>' -namespace 'root\cimv2' -query 'SELECT * FROM Win32_Process'

Kerberos Ticket requires Kerberos ticket

impacket-wmiquery -k -no-pass '<domain>/<user>'@'<ip>' -namespace 'root\cimv2' -query 'SELECT * FROM Win32_Process'

Examples

impacket-wmiquery 'CORP.LOCAL/user:password'@192.168.1.100 -namespace 'root\cimv2' -query 'SELECT * FROM Win32_Process'

Tags

impacket wmi query enumeration processes