winexe - Windows的远程执行命令
root@kali:~# winexe --help
winexe version 1.1
This program may be freely redistributed under the terms of the GNU GPLv3
Usage: winexe [OPTION]... //HOST COMMAND
  -?, --help                                  Display help message,
  -U, --user=[DOMAIN/]USERNAME[%PASSWORD]     Set the network username,
  -A, --authentication-file=FILE              Get the credentials from a file,
  -k, --kerberos=STRING                       Use Kerberos, -k [yes|no],
  -d, --debuglevel=DEBUGLEVEL                 Set debug level,
      --uninstall                             Uninstall winexe service after remote
      --reinstall                             Reinstall winexe service before remote
      --system                                Use SYSTEM account,
      --profile                               Load user profile,
      --convert                               Try to convert characters between local
                                              and remote code-pages,
      --runas=[DOMAIN\]USERNAME%PASSWORD      Run as user (BEWARE: password is sent
                                              in cleartext over net),
      --runas-file=FILE                       Run as user options defined in a file
      --interactive=0|1                       Desktop interaction: 0-disallow,                                                     1-allow. If you allow use,
                                              also --system switch (Win requirement). Vista do not support
                                              this option,
      --ostype=0|1|2                          OS type:0-32-bit, 1-64-bit,2-winexe,
                                              will decide. Determines which version,
                                            (32/64-bit) of service will be installed,

winexe 用法示例

在指定的凭据(-U ‘Administrator%s3cr3t’),连接到远程服务器(//,并执行命令(‘cmd.exe /c echo “this is running on windows”‘):

root@kali:~# winexe -U 'Administrator%s3cr3t' // 'cmd.exe /c echo "this is running on windows"'

"this is running on windows"