NetExec WinRM Auth Check
Validate credentials against the WinRM (PowerShell Remoting) service. A successful login with the (Pwn3d!) marker means you can execute commands.
- Tool
- nxc
- Category
- Authentication / Credential Testing
- Platform
- linux
- Requires
- password
- Protocols
- WINRM
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc winrm <ip> -u <user> -p <password>
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
nxc winrm <ip> -u <user> -H <hash>
Kerberos (ccache) requires Kerberos ticket
KRB5CCNAME=<ccache> nxc winrm <ip> -u <user> -k --use-kcache
Local Auth requires password
nxc winrm <ip> -u <user> -p <password> --local-auth
Examples
nxc winrm 10.10.10.10 -u administrator -p 'Password123!'
nxc winrm 10.10.10.0/24 -u admin -H aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42
Tags
References
Related commands
- NetExec FTP Auth & Listing Validate FTP credentials and check anonymous access. Combine with --ls to list the root…
- NetExec RDP Auth Check Validate credentials against the RDP service (TCP/3389) without opening a graphical…
- NetExec SMB Auth Test Test SMB authentication with various credential types
- NetExec SMB with Kerberos Auth Authenticate to SMB using a Kerberos ticket from a ccache file instead of NTLM. Required…
- NetExec SSH Auth & Spray Validate credentials against SSH. Supports password, key file, and spraying across…