WinRM [5985, 5986]
The Windows Remote Management (WinRM) is a simple Windows integrated remote management protocol based on the command line.
Footprinting the Service
Nmap WinRM
nmap -sV -sC 10.129.201.248 -p5985,5986 --disable-arp-ping -nEvilwinRM
z3tssu@htb[/htb]$ evil-winrm -i 10.129.201.248 -u Cry0l1t3 -p P455w0rD!
Evil-WinRM shell v3.3
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
Data: For more information, check Evil-WinRM Github: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Cry0l1t3\Documents>Last updated