evil-winrm

Installation
SKILL.md

evil-winrm

Goal: Execute commands and obtain interactive sessions on Windows machines over WinRM (Ports 5985 HTTP / 5986 HTTPS).

Agent Constraints & Execution

When an AI Agent executes evil-winrm, standard PTY interactive prompts usually fail or capture nothing via piping (echo whoami | evil-winrm). Do not attempt to pipe into it if the session hangs.

Instead, when obtaining output programmatically through a shell:

  1. Locate the absolute path of the gem (e.g., gem contents evil-winrm, or find / -name "evil-winrm" -type f).
  2. Use an interactive shell controller, OR pass commands directly through single execution modes if supported.
  3. If evil-winrm hangs or drops output, switch to Impacket's wmiexec.py or psexec.py as fallbacks for initial command execution. Caveat: those use NTLM — against Kerberos-only or Protected Users targets they fail; there, drive WinRM PSRP over Kerberos non-interactively (pypsrp Client(...).execute_ps()). See offensive-techniques/active-directory-technique/references/lateral-movement-ad.md.

The Domain/Realm Trap

A common failure when attacking Active Directory via WinRM is attempting to pass the domain with the -d flag. Modern versions of evil-winrm do not use -d for basic domain routing.

  • If you are NOT using Kerberos tickets, do not pass a domain flag. Simply pass -u <user> and -p <password>. WinRM will automatically negotiate the domain if the host is a Domain Controller or joined to it.
  • If you ARE using Kerberos tickets (-K), you must specify the realm using -r <realm>. Note that Kerberos requires the FQDN to be passed to -i (e.g., -i dc01.contoso.com), not just the IP address, and the KDC must be configured in /etc/krb5.conf.
Installs
5
GitHub Stars
22
First Seen
Apr 16, 2026
evil-winrm — aeondave/malskill