WinRM (Windows Remote Management) is Microsoft's implementation of the WS-Management protocol, listening on TCP 5985 (HTTP) and 5986 (HTTPS), and it is the transport behind PowerShell Remoting. It is a prime lateral-movement and remote-execution target on Windows networks: with valid credentials (or an NT hash, since WinRM supports NTLM authentication and therefore pass-the-hash) for a member of the Remote Management Users group or a local admin, an attacker gets an interactive PowerShell session on the host, usually with administrative privileges. The surface is enumerating the service, obtaining and using credentials or hashes, and the command execution itself.
nmap -p5985,5986 -sV <target>
nxc winrm <target> -u user -p 'pass' # validates creds and flags Pwn3d! (admin)
Subtopics#
- Enumeration: detecting WinRM and its configuration.
- Authentication: passwords, NTLM, and pass-the-hash.
- Command execution: obtaining a shell with Evil-WinRM and PowerShell Remoting.