3 techniquesLinux · Windows · ActiveDirectoryWADComsGPL-3.0
Evil-WinRM-PTH
ExecutionLinuxWindowsActiveDirectory
Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Evil-WinRM supports passing the victim's NT hash for authorization.
Command Reference:
Target IP: 10.10.10.1
Username: john
NT Hash: c23b2e293fa0d312de6f59fd6d58eae3
Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.
Command Reference:
Target IP: 10.10.10.1
Username: john
Password: password123
Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Winrm Supports PKINIT, meaning if you have a computers PFX file, you can authenticate and get a shell. Note that the command requires a public and a private key in PEM format, that can be extracted by converting the PFX to PEM format. Take a look at the references for more info on that. Password protected PFX files can be cracked with JohnTheRipper.
Command Reference:
Target IP: 10.10.10.1
PFX File: cert.pfx
Domain: EVILCORP