This module uses valid credentials to login to the WinRM service and execute a payload. It has two available methods for payload delivery: Powershell 2.0 and VBS CmdStager. The module will check if Powershell 2.0 is available, and if so uses that method. Otherwise it falls back to the VBS CmdStager which is less stealthy. IMPORTANT: If targeting an x64 system with the Powershell method you MUST select an x64 payload. An x86 payload will never return.


  thelightcosine




msf > use exploit/windows/winrm/winrm_script_exec
msf exploit(winrm_script_exec) > show targets
msf exploit(winrm_script_exec) > set TARGET < target-id >
msf exploit(winrm_script_exec) > show options
    ...show and set options...
msf exploit(winrm_script_exec) > exploit

