Path: blob/master/payloads/library/remote_access/win_winrm-backdoor/README.md
3018 views
"Microsoft Windows" WinRM Backdoor
Title: "Microsoft Windows" WinRM Backdoor
Author: TW-D
Version: 1.0
Target: Microsoft Windows
Category: Remote Access
Description
Adds a user account (RD_User:RD_P@ssW0rD).
Adds this local user to local administrator group.
Enables "Windows Remote Management" with default settings.
Adds a rule to the firewall.
Sets a value to "LocalAccountTokenFilterPolicy" to disable "UAC" remote restrictions.
Hides this user account.
Exploitation
The connection identifiers will be those defined by the values : RD_User and RD_P@ssW0rD.