NetExec WinRM User Enum

Enumerate domain users via WinRM after a successful auth. Equivalent to the SMB --users flag but uses WS-Management transport, which is sometimes the only protocol left exposed on hardened hosts.

Tool
nxc
Category
Enumeration / WinRM
Platform
linux
Requires
password
Protocols
WINRM

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc winrm <target> -u '<user>' -p '<password>' --users

Credential variants

The same attack using a different authentication material.

Groups requires password

nxc winrm <target> -u '<user>' -p '<password>' --groups

Logged On Users requires password

nxc winrm <target> -u '<user>' -p '<password>' --loggedon-users

Examples

nxc winrm 10.10.10.10 -u jdoe -p 'Password123!' --users

Tags

netexec nxc winrm enumeration