What is WinRM?
Windows Remote Management lets admins execute commands on Windows machines remotely. It’s the Windows implementation of WS-Management.
Common security issues
Weak domain or local credentials.
NTLM relay attacks.
Credential replay.
Over-privileged users.
Misconfigured Kerberos.
Default ports
5985 – HTTP
5986 – HTTPS
Enumeration
WinRM discovery, auth probing, cred validation, and config enum
WinRM Credential Validation
WinRM Endpoint Probing
WinRM Interactive Shell Access
WinRM Service Discovery with NTLM Info
Vulnerability Discovery
Guides for finding WinRM misconfigs, weak TLS, and auth flaws
WinRM Basic Auth Detection
WinRM Endpoint Exposure Check
WinRM HTTPS TLS Validation
WinRM Low-Privilege Access Check
Exploitation
Brute force, shell access, CLM bypass, and JEA escape guides
WinRM Brute Force and Password Spraying
WinRM Cleartext Credential Capture – HTTP Traffic Interception
evil-winrm – Full WinRM Shell Usage Guide
Exploit WinRM with evil-winrm for interactive PowerShell shells using credentials, hashes, SSL, file transfer, and in-memory script/assembly loading.
Privilege Escalation
Bypass CLM and escape JEA endpoints over WinRM sessions
WinRM CLM Bypass – PowerShell Constrained Language Mode Escape
JEA Endpoint Escape – Breaking Out of Just Enough Administration
Lateral Movement
Move across accounts or systems to expand reach. Use trust paths to access new assets.
WinRM Lateral Movement
Exploiting Windows Remote Management (WinRM) for lateral movement using tools like Evil-WinRM, CrackMapExec, and PowerShell remoting.