WinRM

WinRM (Windows Remote Management) is Microsoft's implementation of the WS-Management protocol, listening on TCP 5985 (HTTP) and 5986 (HTTPS), and it is the transport behind PowerShell Remoting. It is a prime lateral-movement and remote-execution target on Windows networks: with valid credentials (or an NT hash, since WinRM supports NTLM authentication and therefore pass-the-hash) for a member of the Remote Management Users group or a local admin, an attacker gets an interactive PowerShell session on the host, usually with administrative privileges. The surface is enumerating the service, obtaining and using credentials or hashes, and the command execution itself.

bash
nmap -p5985,5986 -sV <target>
nxc winrm <target> -u user -p 'pass'           # validates creds and flags Pwn3d! (admin)

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more