NetExec WMI Query
Run an arbitrary WQL query over WMI without dropping into wmic / Get-WmiObject. Useful for live process listing, service enumeration, and registry reads against hosts where WinRM is disabled but WMI/DCOM is exposed.
- Tool
- nxc
- Category
- Enumeration / WinRM
- Platform
- linux
- Requires
- password
- Protocols
- WMI
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc wmi <target> -u '<user>' -p '<password>' --query '<wql-query>'
Credential variants
The same attack using a different authentication material.
List Processes requires password
nxc wmi <target> -u '<user>' -p '<password>' --query 'SELECT Name,ProcessId FROM Win32_Process'
Hash Auth requires NTLM hash
nxc wmi <target> -u '<user>' -H <nt-hash> --query '<wql-query>'
Examples
nxc wmi 10.10.10.10 -u jdoe -p 'Password123!' --query 'SELECT * FROM Win32_Process'
Tags
Related commands
- NetExec WinRM User Enum Enumerate domain users via WinRM after a successful auth. Equivalent to the SMB --users…