> For the complete documentation index, see [llms.txt](https://staphysec.gitbook.io/staphysec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://staphysec.gitbook.io/staphysec/pentesting/5985-5986-winrm.md).

# 5985,5986 - WinRm

[Hacktricks](https://book.hacktricks.xyz/pentesting/5985-5986-pentesting-winrm)

The Windows Remote Management (WinRM) is a simple Windows integrated remote management protocol based on the command line. WinRM uses the Simple Object Access Protocol (SOAP) to establish connections to remote hosts and their applications.

* 5985 HTTP
* 5986 HTTPS

## FootPrinting

```
nmap -sV -sC <IP> -p5985,5986 --disable-arp-ping -n
```

If we want to find out whether one or more remote servers can be reached via WinRM, we can easily do this with the help of PowerShell. The [Test-WsMan](https://docs.microsoft.com/en-us/powershell/module/microsoft.wsman.management/test-wsman?view=powershell-7.2) cmdlet is responsible for this, and the host's name in question is passed to it.

In Linux-based environments, we can use the tool called [evil-winrm](https://github.com/Hackplayers/evil-winrm).

```
evil-winrm -i <IP> -u USER -p PASSWORD
```
