Windows Remote Management
Uses the Python pywinrm library and commands to execute either a process or using Powershell scripts.
Endpoint · Windows Remote Management
Details
| ID | Windows Remote Management |
|---|---|
| Provider | Microsoft |
| Category | Endpoint |
| From Version | 5.0.0 |
| Docker Image | demisto/auth-utils:1.0.0.3562326 |
| Supported Modules | Agentix XSIAM |
README
Uses the Python pywinrm library and commands to execute either a process or using Powershell scripts.
This integration was integrated and tested with Windows Remote Management
Configure Windows Remote Management in Cortex
| Parameter | Description | Required |
|---|---|---|
| Credentials | True | |
| Default Host | True | |
| Authentication Type | True | |
| Realm | Default realm to use for Kerberos based authentication | False |
| Decode codec (default is utf_8) | Decode codec to use when decoding command outputs (defaults to ‘utf_8’) | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
winrm-run-process
Executes a command on the host
Base Command
winrm-run-process
Input
| Argument Name | Description | Required |
|---|---|---|
| hostname | The hostname to run the command on. This will override the default hostname specified in the instance. | Optional |
| command | Command to execute. | Required |
| arguments | Comma separate list of arguments. | Optional |
| decode | Decode codec to use when decoding command outputs (overrides value set in the instance). Possible values are: ascii, big5, big5hkscs, cp037, cp424, cp437, cp500, cp737, cp775, cp850, cp852, cp855, cp856, cp857, cp860, cp861, cp862, cp863, cp864, cp865, cp866, cp869, cp874, cp875, cp932, cp949, cp950, cp1006, cp1026, cp1140, cp1250, cp1251, cp1252, cp1253, cp1254, cp1255, cp1256, cp1257, cp1258, euc_jp, euc_jis_2004, euc_jisx0213, euc_kr, gb2312, gbk, gb18030, hz, iso2022_jp, iso2022_jp_1, iso2022_jp_2, iso2022_jp_2004, iso2022_jp_3, iso2022_jp_ext, iso2022_kr, latin_1, iso8859_2, iso8859_3, iso8859_4, iso8859_5, iso8859_6, iso8859_7, iso8859_8, iso8859_9, iso8859_10, iso8859_13, iso8859_14, iso8859_15, johab, koi8_r, koi8_u, mac_cyrillic, mac_greek, mac_iceland, mac_latin2, mac_roman, mac_turkish, ptcp154, shift_jis, shift_jis_2004, shift_jisx0213, utf_16, utf_16_be, utf_16_le, utf_7, utf_8. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| WinRM.Process | unknown | Process object of the WinRM command |
| WinRM.Process.Output | unknown | STDOUT of the WinRM command |
| WinRM.Process.Error | unknown | STDERR of the WinRM command |
| WinRM.Process.Status | unknown | Status code of the WInRM command |
Context Example
"WinRM": {
"Process": {
"Error": "#SomeError",
"Output": "Hello DBot!",
"Status": 0
}
}
Command Example
!winrm-run-process command=`HelloWorldProcess` arguments="DBot"
Human Readable Output
“Hello DBot!”
winrm-run-powershell
Executes a Powershell script on the endpoint
Base Command
winrm-run-powershell
Input
| Argument Name | Description | Required |
|---|---|---|
| hostname | The hostname to run the command on. This will override the default hostname specified in the instance. | Optional |
| entryID | The entry ID of the powershell script to run (overrides scriptname and script). | Optional |
| script | The powershell script to execute (requires code, not a file input). | Optional |
| scriptname | Name of the script (optional). | Optional |
| decode | Decode codec to use when decoding command outputs (overrides value set in the instance). Possible values are: ascii, big5, big5hkscs, cp037, cp424, cp437, cp500, cp737, cp775, cp850, cp852, cp855, cp856, cp857, cp860, cp861, cp862, cp863, cp864, cp865, cp866, cp869, cp874, cp875, cp932, cp949, cp950, cp1006, cp1026, cp1140, cp1250, cp1251, cp1252, cp1253, cp1254, cp1255, cp1256, cp1257, cp1258, euc_jp, euc_jis_2004, euc_jisx0213, euc_kr, gb2312, gbk, gb18030, hz, iso2022_jp, iso2022_jp_1, iso2022_jp_2, iso2022_jp_2004, iso2022_jp_3, iso2022_jp_ext, iso2022_kr, latin_1, iso8859_2, iso8859_3, iso8859_4, iso8859_5, iso8859_6, iso8859_7, iso8859_8, iso8859_9, iso8859_10, iso8859_13, iso8859_14, iso8859_15, johab, koi8_r, koi8_u, mac_cyrillic, mac_greek, mac_iceland, mac_latin2, mac_roman, mac_turkish, ptcp154, shift_jis, shift_jis_2004, shift_jisx0213, utf_16, utf_16_be, utf_16_le, utf_7, utf_8. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| WinRM.Powershell.Output | unknown | STDOUT of the WinRM command |
| WinRM.Powershell.Error | unknown | STDERR of the WinRM command |
| WinRM.Powershell.Status | unknown | Status code of the WInRM command |
Context Example
"WinRM": {
"Script": {
"error": "#SomeError",
"hostname": 8.8.8.8,
"output": "Hello, World!"
}
"script": "Hello",
"status": 0
}
Command Example
!winrm-run-powershell script=`Write-Host "Hello, World!"` scriptname="Hello"
Human Readable Output
Hello, World!
Configuration parameters
credentials— Credentials (required)default_host— Default Host (required)auth_type— Authentication Type (required)realm— Realmdecode— Decode codec (default is utf_8)
Commands (2)
-
winrm-run-powershellExecutes a Powershell script on the endpoint.
-
winrm-run-processExecutes a command on the host.
import demistomock as demisto import winrm from CommonServerPython import * from winrm import Session from CommonServerUserPython import * """ Helper functions """ class Client: def __init__(self, username, password, auth_type, realm, default_host, decode): self.username = username self.password = password self.auth = auth_type self.realm = realm if realm else None self.hostname = default_host self.decode = decode self.runType = None self.command = None self.script = None self.arguments = None self.res = None def run(self): s: Session if self.auth == "ntlm": s = winrm.Session(target=self.hostname, auth=(self.username, self.password), transport=self.auth) else: # self.auth == "kerberos": demisto.debug(f"{self.auth=}. Should be kerberos") s = winrm.Session(target=self.hostname, auth=(self.username, self.password), transport=self.auth, realm=self.realm) if self.runType == "Process": self.res = s.run_cmd(self.command, self.arguments) # type: ignore[arg-type] elif self.runType == "Script": self.res = s.run_ps(self.script) # type: ignore[arg-type] def output(self): entry_context = None if self.res is None: raise ValueError("Failed to get the response from the executed command.") if self.runType == "Process": data = { "hostname": self.hostname, "process": self.command, "output": self.res.std_out.decode(self.decode) if self.res.std_out else None, "error": self.res.std_err.decode(self.decode) if self.res.std_err else None, "status": self.res.status_code, } entry_context = {"WinRM.Process(val.hostname == obj.hostname && val.process == obj.process)": data} elif self.runType == "Script": data = { "hostname": self.hostname, "script": self.command, "output": self.res.std_out.decode(self.decode) if self.res.std_out else None, "error": self.res.std_err.decode(self.decode) if self.res.std_err else None, "status": self.res.status_code, } entry_context = {"WinRM.Script(val.hostname && val.hostname == obj.hostname && val.script == obj.script)": data} if self.res.status_code == 0: this_out = self.res.std_out else: this_out = self.res.std_err demisto.results( { "Type": entryTypes["note"], "Contents": data, "ContentsFormat": formats["json"], "HumanReadable": this_out.decode(encoding=self.decode), "ReadableContentsFormat": formats["text"], "EntryContext": entry_context, } ) def test_command(client): client.hostname = demisto.params().get("default_host", None) if not client.hostname: return_error("You must provide a value for Default Host for the test button") client.runType = "Process" client.command = "cd" try: client.run() demisto.results("ok") except Exception as err: demisto.results(err) def run_command(client, run_type): args = demisto.args() client.hostname = args.get("hostname", client.hostname) client.decode = args.get("decode", client.decode) client.runType = run_type if run_type == "Process": client.command = args.get("command") client.arguments = args.get("arguments", None) elif run_type == "Script": entry_id = args.get("entryID", None) if entry_id: file_path = demisto.getFilePath(entry_id) client.command = file_path["name"] data = open(file_path["path"]).read() client.script = data else: client.script = args.get("script", None) client.command = args.get("scriptname", None) if not client.script and not client.command: return_error("You must provide an entryID or script and script name") client.run() client.output() def main(): params = demisto.params() username = params.get("credentials").get("identifier") password = params.get("credentials").get("password") auth_type = params.get("auth_type") realm = demisto.params().get("realm") default_host = params.get("default_host") decode = params.get("decode", "utf_8") try: client = Client(username, password, auth_type, realm, default_host, decode) if demisto.command() == "test-module": test_command(client) if demisto.command() == "winrm-run-process": run_command(client, "Process") if demisto.command() == "winrm-run-powershell": run_command(client, "Script") except Exception as e: return_error(str(e)) if __name__ in ["__builtin__", "builtins"]: main()