Releases: XiaoliChan/wmiexec-Pro
Releases · XiaoliChan/wmiexec-Pro
wmiexec-Pro v0.2.7
Changelog:
- Default is using VBS obfuscate in command execution
- Bypass windows defender in
semi-interactive shell
mode
Screenshot:
data:image/s3,"s3://crabby-images/8764f/8764f1c61e1df10ccae504a7f5a16e09cd678e3b" alt="image"
wmiexec-Pro v0.2.6
Changelog:
- Bugs fixed in
exec-command
wmiexec-Pro v0.2.5
Changelog:
- Add
lognuke
, history
, clear
, upload
, download
builtin commands in semi-interactive shell
Demonstrate:
data:image/s3,"s3://crabby-images/bb3e3/bb3e3c5f5c03ef988394a6a2736c38299edad7af" alt="asciicast"
wmiexec-Pro v0.2.4
Changelog:
- Use VBScript to invoke
SetSecurityDescriptor
method to grant access permissions instead of executing cmd. (Only works on system versions which is higher than NT6)
Screenshots:
data:image/s3,"s3://crabby-images/b7b34/b7b346eb0e8df5739455e69d84f6f65446116068" alt="image"
🎉 Special thanks @422926799 🎉
wmiexec-Pro v0.2.3
Changelog:
- Add codec functions in semi-interactive shell mode
wmiexec-Pro v0.2.2
Changelog:
- Add deep clean function in execute VBS
Screenshots:
-
In this demonstration, I break the command execution after creating wmi event, which means this command will never stop if we forget the event id.
data:image/s3,"s3://crabby-images/4db76/4db76d1d5acf2664a6e3a18e7e4897d0a1ca3a87" alt="image"
-
So, with -deep-clean (
clearin
exec-commandmodule also is invoke the
depp-clean` function), we can stop the wmi event even forget the event id.
data:image/s3,"s3://crabby-images/1876a/1876a1dc9cf6c5fe4c5e9a02bec1e2b172cc016c" alt="image"
wmiexec-Pro v0.2.1-fixed
Changelog:
- Add 'Try except' when getting command results
wmiexec-Pro v0.2.1
Changelog:
- Add logging / delay functions in semi-interactive shell mode
Screenshots:
wmiexec-Pro v0.2.0-fixed
Changelog:
- Base64 encode cwd path to avoid latin-1 encode error.
Screenshots:
-
Before
data:image/s3,"s3://crabby-images/35362/35362e99c4f70f3a5f8ce8556abd3ed8cd998fa8" alt="image"
-
After
data:image/s3,"s3://crabby-images/0c9ba/0c9ba64d6d5bca219fab22dc96882cb2d6725075" alt="image"
wmiexec-Pro v0.2.0
Changelog:
- Add semi-interactive shell mode. (only work with system version higher than NT6)
Screenshots: