WinRM exec

WinRM exec

TL;DR: PowerShell remoting / evil-winrm; cleanest lateral when 5985/5986 is open.

Stub — to be filled in.

What it is

TODO

Preconditions / where it applies

TODO

Technique

TODO

Detection and defence

TODO

References

  • TODO