内网渗透中有诸多的渗透利器,wmic 绝对排的上号,这里记录一下,备忘 C:\Windows\System32\wbem

    ★★连接远程的电脑,不过好象对要开 RPC 服务

    1. wmic /node:"" /password:"password" /user:"administrator"


    1. wmic bios get Manufacturer,Name


    1. wmic computersystem get domain


    1. wmic computersystem where "name='abc'" call rename 123


    1. wmic cpu get name

    DATAFILE - DataFile 管理

    1. wmic datafile where "drive='e:' and path='\\test\\' and FileName='cc' and Extension='cmd'" list


    1. wmic datafile where "drive='e:' and FileName='cc' and Extension='cmd' and FileSize>'1000'" list


    1. wmic datafile where "drive='e:' and Extension='cmd' and FileSize>'10000000'" call delete


    1. wmic datafile where "drive='e:' and Extension<>'cmd' and path='test'" call delete


    1. wmic datafile where "drive='e:' and path='\\test\\' and FileName='cc' and Extension='cmd'" call copy "e:\aa.bat"


    1. wmic datafile "c:\\hello.txt" call rename c:\test.txt


    1. wmic datafile where "drive='h:' and extension='txt' and path like '%\\test\\%' and filename like '%perl%'" get name


    1. wmic ENVIRONMENT where "name='temp'" get UserName,VariableValue


    1. wmic ENVIRONMENT where "name='path' and username='<system>'" set VariableValue="%path%;e:\tools"


    1. wmic ENVIRONMENT create name="home",username="<system>",VariableValue="%HOMEDRIVE%%HOMEPATH%"


    1. wmic ENVIRONMENT where "name='home'" delete

    FSDIR - 文件目录系统项目管理

    1. wmic FSDIR where "drive='e:' and filename='test'" list


    1. wmic FSDIR where "drive='e:' and path='\\test\\' and filename<>'abc'" call delete


    1. wmic fsdir "c:\\good" call delete


    1. wmic fsdir "c:\\good" rename "c:\abb"

    LOGICALDISK - 本地储存设备管理

    1. wmic LOGICALDISK get name,Description,filesystem,size,freespace

    PROCESS - 进程管理

    1. wmic process list brief
    2. (wmic startup list brief插播一条)


    1. wmic process where "name='svchost.exe' and ExecutablePath<>'C:\\WINDOWS\\system32\\svchost.exe'" call Terminate


    1. wmic process call create notepad

    ★★wmic 获取进程名称以及可执行路径:

    1. wmic process get name,executablepath

    ★★wmic 删除指定进程(根据进程名称):

    1. wmic process where name="qq.exe" call terminate 或者用 wmic process where name="qq.exe" delete

    ★★wmic 删除指定进程(根据进程PID):

    1. wmic process where pid="123" delete

    SERVICE - 服务程序管理

    1. wmic service list brief


    1. wmic SERVICE where name="Spooler" call startservice


    1. wmic SERVICE where name="Spooler" call stopservice


    1. wmic SERVICE where name="Spooler" call PauseService

    ★★更改spooler服务启动类型[auto|Disabled|Manual] 释[自动|禁用|手动]

    1. wmic SERVICE where name="Spooler" set StartMode="auto"


    1. wmic SERVICE where name="test123" call delete

    SHARE - 共享资源管理

    1. wmic SHARE where name="e$" call delete


    1. WMIC SHARE CALL Create "","test","3","TestShareName","","c:\test",0

    STARTUP - 用户登录到计算机系统时自动运行命令的管理

    1. wmic STARTUP list

    SYSDRIVER - 基本服务的系统驱动程序管理

    1. wmic SYSDRIVER list


    1. wmic process call create shutdown.exe


    1. wmic /node: /password:123456 process call create "shutdown.exe -r -f -m"


    1. wmic nteventlog get path,filename,writeable


    1. wevtutil cl "windows powershell"
    2. wevtutil cl "security"
    3. wevtutil cl "system"


    1. wmic product get name,version
    2. wmic product list brief


    1. wmic process where name="chrome.exe" list full


    1. REG query HKCU /v "pwd" /s


    1. netsh wlan show profiles
    2. netsh wlan show profiles name="profiles的名字" key=clear


    1. wmic bios list full | find /i "vmware"

    参考 http://www.jb51.net/article/49987.htm https://blog.csdn.net/qq_20307987/article/details/73222038 ```