NetExec WMI Query

Run an arbitrary WQL query over WMI without dropping into wmic / Get-WmiObject. Useful for live process listing, service enumeration, and registry reads against hosts where WinRM is disabled but WMI/DCOM is exposed.

Tool
nxc
Category
Enumeration / WinRM
Platform
linux
Requires
password
Protocols
WMI

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc wmi <target> -u '<user>' -p '<password>' --query '<wql-query>'

Credential variants

The same attack using a different authentication material.

List Processes requires password

nxc wmi <target> -u '<user>' -p '<password>' --query 'SELECT Name,ProcessId FROM Win32_Process'

Hash Auth requires NTLM hash

nxc wmi <target> -u '<user>' -H <nt-hash> --query '<wql-query>'

Examples

nxc wmi 10.10.10.10 -u jdoe -p 'Password123!' --query 'SELECT * FROM Win32_Process'

Tags

netexec nxc wmi wql query