Skip to content
HackIndex logo

HackIndex

WinRM
Service

WinRM

WinRM is Windows remote management over HTTP/HTTPS. Attackers probe auth, brute force creds, gain remote shells, bypass CLM, escape JEA, and move laterally across Windows environments

:5985 :5986 15 guides 5 phases
1 min read Updated: Jul 14, 2026

What is WinRM?

Windows Remote Management lets admins execute commands on Windows machines remotely. It’s the Windows implementation of WS-Management.

Common security issues

  • Weak domain or local credentials.

  • NTLM relay attacks.

  • Credential replay.

  • Over-privileged users.

  • Misconfigured Kerberos.

Default ports

  • 5985 – HTTP

  • 5986 – HTTPS

Enumeration

WinRM discovery, auth probing, cred validation, and config enum

5

Vulnerability Discovery

Guides for finding WinRM misconfigs, weak TLS, and auth flaws

4

Exploitation

Brute force, shell access, CLM bypass, and JEA escape guides

3

Privilege Escalation

Bypass CLM and escape JEA endpoints over WinRM sessions

2

Lateral Movement

Move across accounts or systems to expand reach. Use trust paths to access new assets.

1

WinRM Lateral Movement

Exploiting Windows Remote Management (WinRM) for lateral movement using tools like Evil-WinRM, CrackMapExec, and PowerShell remoting.

May 6, 2026 4 min read