All tools

Post-Exploitation

Evil-WinRM

WinRM shell for pentesting Windows remote management.

beginner
Linux
Post-Exploitation
Lateral Movement

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

You have credentials and WinRM (5985/5986) is open.

How

evil-winrm -i IP -u user -p pass; upload tools; run commands.

Why

Comfortable post-ex shell on modern Windows.

Commands & usage

evil-winrm -i 192.168.1.20 -u administrator -p 'Pass'
evil-winrm -i 192.168.1.20 -u user -H NTLMHASH

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

winrm
windows
shell

Related in Post-Exploitation