Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
nimrm — Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting | Kitploit
Tools/GitHubGitHub/blue0x1/nimrm
Payload GenerationLateral MovementInformation GatheringPost-ExploitationPenetration TestingCommand and ControlAuthenticationRed TeamingRemote Access Tool
GitHubblue0x1/nimrm

nimrm

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

52218 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View RepositoryWebsite
Share

nimrm

Release Downloads

Native WinRM shell client written in Nim

Version 1.2.0 · Author Chokri Hammedi (blue0x1) · License MIT

NTLM Kerberos PowerShell File Transfer In-Memory Helpers Multi-Session

Documentation WinRM Library


image

Legal Notice

nimrm is intended for lawful administration, security testing, and research on systems you own or have explicit permission to access. The author is not responsible for misuse or damage caused by this tool.

Table of Contents

  • Overview
  • Features
  • Requirements
  • Installation
  • Build
  • Performance
  • Usage
  • Options
  • Interactive Commands
  • Session Management
  • Examples
  • Notes
  • License

Overview

nimrm provides a compact and fast WinRM shell with practical authentication, command execution, transfer, and reporting helpers. It is built as a native Nim binary with no Nim package dependencies.

Features

AreaSupport
AuthenticationNTLM password, NTLM hash, Kerberos via KRB5CCNAME
WinRM transportHTTP, HTTPS/TLS, custom port
ShellInteractive PowerShell, CMD prefix, one-shot command mode, command and local path autocomplete
TransfersFile upload/download, recursive directory transfer, remote session-to-session file and directory relay
In-memoryPowerShell script import, managed .NET assembly execution
ReportingAD/domain context, logging and auditing posture
ReliabilityKerberos message wrapping, transport reset/retry handling

Requirements

ComponentRequirement
BuildNim >= 1.6.0
Kerberoslibgssapi_krb5.so.2 on Linux or libgssapi_krb5.dylib on macOS
TLS buildOpenSSL and -d:ssl
TargetWinRM reachable on the selected port

Installation

Nimble:

nimble install nimrm

Download the latest release:

curl -L -o nimrm https://github.com/blue0x1/nimrm/releases/latest/download/nimrm
chmod +x nimrm

Windows release binary:

Invoke-WebRequest -Uri https://github.com/blue0x1/nimrm/releases/latest/download/nimrm.exe -OutFile nimrm.exe

Debian package:

curl -L -o nimrm_1.2.0_amd64.deb https://github.com/blue0x1/nimrm/releases/latest/download/nimrm_1.2.0_amd64.deb
sudo dpkg -i nimrm_1.2.0_amd64.deb

BlackArch:

sudo pacman -S nimrm

The BlackArch PKGBUILD tracks the latest upstream git commit, so new releases reach BlackArch users on their next system update. If nimrm is already installed, upgrade it with:

sudo pacman -Syu nimrm

Build from source:

git clone https://github.com/blue0x1/nimrm.git
cd nimrm
make linux

Build

make linux
make ssl
make windows

Manual build:

nim c -d:release --opt:speed -o:nimrm nimrm.nim

Performance

nimrm is designed to stay fast by using a native Nim binary, persistent WinRM runspace, chunked transfer logic, and compact progress rendering.

OperationImplementation
UploadChunked Base64 writes with adaptive retry on large envelopes
DownloadStreamed Base64 chunks with progress tracking and a fast path for small files
Remote session relayReads from one WinRM session and writes to another through controller memory without writing the file to local disk
Directory transferRecursive file enumeration using the same chunked transfer path
Command executionReuses the active WinRM shell/runspace instead of reconnecting per command

Usage

NTLM password:

./nimrm -T 192.168.1.10 -A 'CORP\administrator' -P 'Password123'

NTLM pass-the-hash:

./nimrm -T 192.168.1.10 -A 'CORP\user' -N aad3b435b51404eeaad3b435b51404ee:0123456789abcdef0123456789abcdef

Kerberos:

KRB5CCNAME=FILE:/tmp/user.ccache ./nimrm -k -T dc01.corp.local -Z CORP.LOCAL

Force NTLM message encryption over HTTP:

./nimrm -T 192.168.1.10 -A 'CORP\user' -P 'Password123' --seal

Custom port:

./nimrm -T 192.168.1.10 -A 'CORP\user' -P 'Password123' -p 5985

One-shot command:

./nimrm -T 192.168.1.10 -A 'CORP\user' -P 'Password123' -c 'whoami'

Skip TLS certificate verification (self-signed certs):

./nimrm -T 192.168.1.10 -A 'CORP\user' -P 'Password123' --tls --insecure

Options

OptionDescription
-T, --targetTarget IP or hostname
-A, --accountUsername: user, user@domain, or DOMAIN\user
-P, --secretNTLM password
-p, --portWinRM port
-N, --nt-proofNT hash or LM:NT hash
-Z, --krb-zoneKerberos realm override
-K, --kerb-spnKerberos SPN override
-k, --kerbUse Kerberos authentication
-c, --commandExecute one command and exit
--tlsUse HTTPS/TLS
--insecureSkip TLS certificate verification
-h, --helpShow help

Interactive Commands

CommandDescription
/helpShow help
exit, quitClose shell
!<cmd>Run through cmd.exe
upload <local> [remote]Upload one file
download <remote> [local]Download one file
rupload <remote> <session> [dest]Copy a remote file from the active session to another session through memory
rdownload <session> <remote> [dest]Copy a remote file from another session to the active session through memory
rupload-dir <remote> <session> [dest]Copy a remote directory from the active session to another session through memory
rdownload-dir <session> <remote> [dest]Copy a remote directory from another session to the active session through memory
upload-dir <local> [remote]Upload a directory
download-dir <remote> [local]Download a directory
invoke-script <ps1> [args]Import local PowerShell from memory
execute-assembly <exe> [args]Run managed .NET from memory
ad-infoShow AD/domain context
opsec-checkShow logging and auditing posture
sessionsList all active sessions
session <opts>Create a new session
use <name|id>Switch to a session
kill <name|id>Close and remove a session

Session Management

Download Tool