NetExec WinRM User Enum
Enumerate domain users via WinRM after a successful auth. Equivalent to the SMB --users flag but uses WS-Management transport, which is sometimes the only protocol left exposed on hardened hosts.
- Tool
- nxc
- Category
- Enumeration / WinRM
- Platform
- linux
- Requires
- password
- Protocols
- WINRM
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc winrm <target> -u '<user>' -p '<password>' --users
Credential variants
The same attack using a different authentication material.
Groups requires password
nxc winrm <target> -u '<user>' -p '<password>' --groups
Logged On Users requires password
nxc winrm <target> -u '<user>' -p '<password>' --loggedon-users
Examples
nxc winrm 10.10.10.10 -u jdoe -p 'Password123!' --users
Tags
Related commands
- NetExec WMI Query Run an arbitrary WQL query over WMI without dropping into wmic / Get-WmiObject. Useful…