
Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting
Native WinRM shell client written in Nim
Version 1.2.0 · Author Chokri Hammedi (blue0x1) · License MIT
nimrm is intended for lawful administration, security testing, and research on systems you own or have explicit permission to access. The author is not responsible for misuse or damage caused by this tool.
nimrm provides a compact and fast WinRM shell with practical authentication, command execution, transfer, and reporting helpers. It is built as a native Nim binary with no Nim package dependencies.
| Area | Support |
|---|---|
| Authentication | NTLM password, NTLM hash, Kerberos via KRB5CCNAME |
| WinRM transport | HTTP, HTTPS/TLS, custom port |
| Shell | Interactive PowerShell, CMD prefix, one-shot command mode, command and local path autocomplete |
| Transfers | File upload/download, recursive directory transfer, remote session-to-session file and directory relay |
| In-memory | PowerShell script import, managed .NET assembly execution |
| Reporting | AD/domain context, logging and auditing posture |
| Reliability | Kerberos message wrapping, transport reset/retry handling |
| Component | Requirement |
|---|---|
| Build | Nim >= 1.6.0 |
| Kerberos | libgssapi_krb5.so.2 on Linux or libgssapi_krb5.dylib on macOS |
| TLS build | OpenSSL and -d:ssl |
| Target | WinRM reachable on the selected port |
Nimble:
nimble install nimrm
Download the latest release:
curl -L -o nimrm https://github.com/blue0x1/nimrm/releases/latest/download/nimrm
chmod +x nimrm
Windows release binary:
Invoke-WebRequest -Uri https://github.com/blue0x1/nimrm/releases/latest/download/nimrm.exe -OutFile nimrm.exe
Debian package:
curl -L -o nimrm_1.2.0_amd64.deb https://github.com/blue0x1/nimrm/releases/latest/download/nimrm_1.2.0_amd64.deb
sudo dpkg -i nimrm_1.2.0_amd64.deb
BlackArch:
sudo pacman -S nimrm
The BlackArch PKGBUILD tracks the latest upstream git commit, so new releases reach BlackArch users on their next system update. If nimrm is already installed, upgrade it with:
sudo pacman -Syu nimrm
Build from source:
git clone https://github.com/blue0x1/nimrm.git
cd nimrm
make linux
make linux
make ssl
make windows
Manual build:
nim c -d:release --opt:speed -o:nimrm nimrm.nim
nimrm is designed to stay fast by using a native Nim binary, persistent WinRM runspace, chunked transfer logic, and compact progress rendering.
| Operation | Implementation |
|---|---|
| Upload | Chunked Base64 writes with adaptive retry on large envelopes |
| Download | Streamed Base64 chunks with progress tracking and a fast path for small files |
| Remote session relay | Reads from one WinRM session and writes to another through controller memory without writing the file to local disk |
| Directory transfer | Recursive file enumeration using the same chunked transfer path |
| Command execution | Reuses the active WinRM shell/runspace instead of reconnecting per command |
NTLM password:
./nimrm -T 192.168.1.10 -A 'CORP\administrator' -P 'Password123'
NTLM pass-the-hash:
./nimrm -T 192.168.1.10 -A 'CORP\user' -N aad3b435b51404eeaad3b435b51404ee:0123456789abcdef0123456789abcdef
Kerberos:
KRB5CCNAME=FILE:/tmp/user.ccache ./nimrm -k -T dc01.corp.local -Z CORP.LOCAL
Force NTLM message encryption over HTTP:
./nimrm -T 192.168.1.10 -A 'CORP\user' -P 'Password123' --seal
Custom port:
./nimrm -T 192.168.1.10 -A 'CORP\user' -P 'Password123' -p 5985
One-shot command:
./nimrm -T 192.168.1.10 -A 'CORP\user' -P 'Password123' -c 'whoami'
Skip TLS certificate verification (self-signed certs):
./nimrm -T 192.168.1.10 -A 'CORP\user' -P 'Password123' --tls --insecure
| Option | Description |
|---|---|
-T, --target | Target IP or hostname |
-A, --account | Username: user, user@domain, or DOMAIN\user |
-P, --secret | NTLM password |
-p, --port | WinRM port |
-N, --nt-proof | NT hash or LM:NT hash |
-Z, --krb-zone | Kerberos realm override |
-K, --kerb-spn | Kerberos SPN override |
-k, --kerb | Use Kerberos authentication |
-c, --command | Execute one command and exit |
--tls | Use HTTPS/TLS |
--insecure | Skip TLS certificate verification |
-h, --help | Show help |
| Command | Description |
|---|---|
/help | Show help |
exit, quit | Close shell |
!<cmd> | Run through cmd.exe |
upload <local> [remote] | Upload one file |
download <remote> [local] | Download one file |
rupload <remote> <session> [dest] | Copy a remote file from the active session to another session through memory |
rdownload <session> <remote> [dest] | Copy a remote file from another session to the active session through memory |
rupload-dir <remote> <session> [dest] | Copy a remote directory from the active session to another session through memory |
rdownload-dir <session> <remote> [dest] | Copy a remote directory from another session to the active session through memory |
upload-dir <local> [remote] | Upload a directory |
download-dir <remote> [local] | Download a directory |
invoke-script <ps1> [args] | Import local PowerShell from memory |
execute-assembly <exe> [args] | Run managed .NET from memory |
ad-info | Show AD/domain context |
opsec-check | Show logging and auditing posture |
sessions | List all active sessions |
session <opts> | Create a new session |
use <name|id> | Switch to a session |
kill <name|id> | Close and remove a session |