NetExec WinRM Auth Check

Validate credentials against the WinRM (PowerShell Remoting) service. A successful login with the (Pwn3d!) marker means you can execute commands.

Tool
nxc
Category
Authentication / Credential Testing
Platform
linux
Requires
password
Protocols
WINRM

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc winrm <ip> -u <user> -p <password>

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

nxc winrm <ip> -u <user> -H <hash>

Kerberos (ccache) requires Kerberos ticket

KRB5CCNAME=<ccache> nxc winrm <ip> -u <user> -k --use-kcache

Local Auth requires password

nxc winrm <ip> -u <user> -p <password> --local-auth

Examples

nxc winrm 10.10.10.10 -u administrator -p 'Password123!'
nxc winrm 10.10.10.0/24 -u admin -H aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42

Tags

nxc netexec winrm auth credential-validation

References