Evil Winrm

Build, extend, and operate Evil-WinRM — a WinRM shell designed for pentesting Windows environments. Use when the user asks about Evil-WinRM, Windows remote management shells, pass-the-hash over WinRM, uploading/downloading files to Windows targets, loading PowerShell scripts or C# DLLs in memory, bypassing AMSI, or post-exploitation workflows on Windows hosts. Covers installation, basic and advanced connection options, pass-the-hash, SSL mode, file transfer, script/DLL loading, AMSI bypass, logging, Docker usage, proxychains, and full post-exploitation workflow.

jperezduerto b2e7b0b 11.8 KB Updated

File contents

jperezduerto/redhound-arsenal/tree/main/evil-winrm commit b2e7b0b7a4

Frequently asked questions

npx skillmds@latest add jperezduerto/evil-winrm