Ross ROSS = Recommend OSS · open-source software intelligence for agents

XiaoliChan/wmiexec-Pro

New generation of wmiexec.py observed · 2026-08-28

github.com/XiaoliChan/wmiexec-Pro · Python · BSD-2-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

67/100

  • Activity 79
  • Release rhythm 40
  • Longevity 89
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 73.0
  • age_days: 1247
  • days_rel: 320
  • days_push: 129
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

1295 stars · 150 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

wmiexec-Pro is a Python CLI tool built on Impacket that provides an enhanced version of wmiexec.py for remote command execution on Windows hosts via WMI, requiring only port 135. It includes modules for AV evasion, AMSI bypass, file transfer, RDP/WinRM enabling, firewall abuse, event log cleaning, and RID hijacking for lateral movement.

Use cases

  • execute commands on remote windows hosts via wmi without smb
  • bypass antivirus during lateral movement
  • remotely enable rdp or winrm via wmi
  • clean windows event logs on a target machine
  • get a semi-interactive shell on a windows box with only port 135 open
  • hijack RID on a remote windows host
  • transfer files to a windows target over wmi

When to choose

  • you need remote command execution on Windows where only port 135 is reachable
  • you want to evade Windows Defender or other AV during red team operations
  • you need post-exploitation modules like AMSI bypass, firewall abuse, or log cleaning in one tool

When to avoid

  • you need a general-purpose C2 framework with persistent agents
  • the target is not Windows or WMI is blocked
  • you only have SMB access and no DCOM/WMI connectivity

Facets

cli-tool · maturity active

security penetration-testing cli security penetration-testing windows python cli windows wmi lateral-movement impacket av-evasion red-team post-exploitation remote-execution

1 source

Member repositories

RepositoryRoleHealth v2
XiaoliChan/wmiexec-Promain67

For agents

markdown · JSON · MCP: product_card(name="XiaoliChan/wmiexec-Pro")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem