Windows Remote Management
Uses the Python pywinrm library and commands to execute either a process or using Powershell scripts.
Endpoint · Windows Remote Management
Details
| ID | Windows Remote Management |
|---|---|
| Provider | Microsoft |
| Category | Endpoint |
| From Version | 5.0.0 |
| Docker Image | demisto/auth-utils:1.0.0.3562326 |
| Supported Modules | Agentix XSIAM |
README
Uses the Python pywinrm library and commands to execute either a process or using Powershell scripts.
This integration was integrated and tested with Windows Remote Management
Configure Windows Remote Management in Cortex
| Parameter | Description | Required |
|---|---|---|
| Credentials | True | |
| Default Host | True | |
| Authentication Type | True | |
| Realm | Default realm to use for Kerberos based authentication | False |
| Decode codec (default is utf_8) | Decode codec to use when decoding command outputs (defaults to ‘utf_8’) | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
winrm-run-process
Executes a command on the host
Base Command
winrm-run-process
Input
| Argument Name | Description | Required |
|---|---|---|
| hostname | The hostname to run the command on. This will override the default hostname specified in the instance. | Optional |
| command | Command to execute. | Required |
| arguments | Comma separate list of arguments. | Optional |
| decode | Decode codec to use when decoding command outputs (overrides value set in the instance). Possible values are: ascii, big5, big5hkscs, cp037, cp424, cp437, cp500, cp737, cp775, cp850, cp852, cp855, cp856, cp857, cp860, cp861, cp862, cp863, cp864, cp865, cp866, cp869, cp874, cp875, cp932, cp949, cp950, cp1006, cp1026, cp1140, cp1250, cp1251, cp1252, cp1253, cp1254, cp1255, cp1256, cp1257, cp1258, euc_jp, euc_jis_2004, euc_jisx0213, euc_kr, gb2312, gbk, gb18030, hz, iso2022_jp, iso2022_jp_1, iso2022_jp_2, iso2022_jp_2004, iso2022_jp_3, iso2022_jp_ext, iso2022_kr, latin_1, iso8859_2, iso8859_3, iso8859_4, iso8859_5, iso8859_6, iso8859_7, iso8859_8, iso8859_9, iso8859_10, iso8859_13, iso8859_14, iso8859_15, johab, koi8_r, koi8_u, mac_cyrillic, mac_greek, mac_iceland, mac_latin2, mac_roman, mac_turkish, ptcp154, shift_jis, shift_jis_2004, shift_jisx0213, utf_16, utf_16_be, utf_16_le, utf_7, utf_8. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| WinRM.Process | unknown | Process object of the WinRM command |
| WinRM.Process.Output | unknown | STDOUT of the WinRM command |
| WinRM.Process.Error | unknown | STDERR of the WinRM command |
| WinRM.Process.Status | unknown | Status code of the WInRM command |
Context Example
"WinRM": {
"Process": {
"Error": "#SomeError",
"Output": "Hello DBot!",
"Status": 0
}
}
Command Example
!winrm-run-process command=`HelloWorldProcess` arguments="DBot"
Human Readable Output
“Hello DBot!”
winrm-run-powershell
Executes a Powershell script on the endpoint
Base Command
winrm-run-powershell
Input
| Argument Name | Description | Required |
|---|---|---|
| hostname | The hostname to run the command on. This will override the default hostname specified in the instance. | Optional |
| entryID | The entry ID of the powershell script to run (overrides scriptname and script). | Optional |
| script | The powershell script to execute (requires code, not a file input). | Optional |
| scriptname | Name of the script (optional). | Optional |
| decode | Decode codec to use when decoding command outputs (overrides value set in the instance). Possible values are: ascii, big5, big5hkscs, cp037, cp424, cp437, cp500, cp737, cp775, cp850, cp852, cp855, cp856, cp857, cp860, cp861, cp862, cp863, cp864, cp865, cp866, cp869, cp874, cp875, cp932, cp949, cp950, cp1006, cp1026, cp1140, cp1250, cp1251, cp1252, cp1253, cp1254, cp1255, cp1256, cp1257, cp1258, euc_jp, euc_jis_2004, euc_jisx0213, euc_kr, gb2312, gbk, gb18030, hz, iso2022_jp, iso2022_jp_1, iso2022_jp_2, iso2022_jp_2004, iso2022_jp_3, iso2022_jp_ext, iso2022_kr, latin_1, iso8859_2, iso8859_3, iso8859_4, iso8859_5, iso8859_6, iso8859_7, iso8859_8, iso8859_9, iso8859_10, iso8859_13, iso8859_14, iso8859_15, johab, koi8_r, koi8_u, mac_cyrillic, mac_greek, mac_iceland, mac_latin2, mac_roman, mac_turkish, ptcp154, shift_jis, shift_jis_2004, shift_jisx0213, utf_16, utf_16_be, utf_16_le, utf_7, utf_8. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| WinRM.Powershell.Output | unknown | STDOUT of the WinRM command |
| WinRM.Powershell.Error | unknown | STDERR of the WinRM command |
| WinRM.Powershell.Status | unknown | Status code of the WInRM command |
Context Example
"WinRM": {
"Script": {
"error": "#SomeError",
"hostname": 8.8.8.8,
"output": "Hello, World!"
}
"script": "Hello",
"status": 0
}
Command Example
!winrm-run-powershell script=`Write-Host "Hello, World!"` scriptname="Hello"
Human Readable Output
Hello, World!
Configuration parameters
credentials— Credentials (required)default_host— Default Host (required)auth_type— Authentication Type (required)realm— Realmdecode— Decode codec (default is utf_8)
Commands (2)
-
winrm-run-powershellExecutes a Powershell script on the endpoint.
-
winrm-run-processExecutes a command on the host.
commonfields: id: Windows Remote Management version: -1 name: Windows Remote Management display: Windows Remote Management (Beta) category: Endpoint provider: Microsoft description: Uses the Python pywinrm library and commands to execute either a process or using Powershell scripts. configuration: - display: Credentials name: credentials type: 9 required: true - display: Default Host name: default_host type: 0 required: true - display: Authentication Type name: auth_type defaultvalue: ntlm type: 15 required: true options: - ntlm - display: Realm name: realm type: 0 additionalinfo: Default realm to use for Kerberos based authentication required: false - display: Decode codec (default is utf_8) name: decode defaultvalue: utf_8 type: 15 options: - ascii - big5 - big5hkscs - cp037 - cp424 - cp437 - cp500 - cp737 - cp775 - cp850 - cp852 - cp855 - cp856 - cp857 - cp860 - cp861 - cp862 - cp863 - cp864 - cp865 - cp866 - cp869 - cp874 - cp875 - cp932 - cp949 - cp950 - cp1006 - cp1026 - cp1140 - cp1250 - cp1251 - cp1252 - cp1253 - cp1254 - cp1255 - cp1256 - cp1257 - cp1258 - euc_jp - euc_jis_2004 - euc_jisx0213 - euc_kr - gb2312 - gbk - gb18030 - hz - iso2022_jp - iso2022_jp_1 - iso2022_jp_2 - iso2022_jp_2004 - iso2022_jp_3 - iso2022_jp_ext - iso2022_kr - latin_1 - iso8859_2 - iso8859_3 - iso8859_4 - iso8859_5 - iso8859_6 - iso8859_7 - iso8859_8 - iso8859_9 - iso8859_10 - iso8859_13 - iso8859_14 - iso8859_15 - johab - koi8_r - koi8_u - mac_cyrillic - mac_greek - mac_iceland - mac_latin2 - mac_roman - mac_turkish - ptcp154 - shift_jis - shift_jis_2004 - shift_jisx0213 - utf_16 - utf_16_be - utf_16_le - utf_7 - utf_8 additionalinfo: Decode codec to use when decoding command outputs (defaults to 'utf_8') required: false script: script: '' type: python commands: - name: winrm-run-process arguments: - name: hostname description: The hostname to run the command on. This will override the default hostname specified in the instance. - name: command required: true description: Command to execute. - name: arguments description: Comma separate list of arguments. - name: decode auto: PREDEFINED predefined: - ascii - big5 - big5hkscs - cp037 - cp424 - cp437 - cp500 - cp737 - cp775 - cp850 - cp852 - cp855 - cp856 - cp857 - cp860 - cp861 - cp862 - cp863 - cp864 - cp865 - cp866 - cp869 - cp874 - cp875 - cp932 - cp949 - cp950 - cp1006 - cp1026 - cp1140 - cp1250 - cp1251 - cp1252 - cp1253 - cp1254 - cp1255 - cp1256 - cp1257 - cp1258 - euc_jp - euc_jis_2004 - euc_jisx0213 - euc_kr - gb2312 - gbk - gb18030 - hz - iso2022_jp - iso2022_jp_1 - iso2022_jp_2 - iso2022_jp_2004 - iso2022_jp_3 - iso2022_jp_ext - iso2022_kr - latin_1 - iso8859_2 - iso8859_3 - iso8859_4 - iso8859_5 - iso8859_6 - iso8859_7 - iso8859_8 - iso8859_9 - iso8859_10 - iso8859_13 - iso8859_14 - iso8859_15 - johab - koi8_r - koi8_u - mac_cyrillic - mac_greek - mac_iceland - mac_latin2 - mac_roman - mac_turkish - ptcp154 - shift_jis - shift_jis_2004 - shift_jisx0213 - utf_16 - utf_16_be - utf_16_le - utf_7 - utf_8 description: Decode codec to use when decoding command outputs (overrides value set in the instance). outputs: - contextPath: WinRM.Process description: Process object of the WinRM command. - contextPath: WinRM.Process.Output description: STDOUT of the WinRM command. - contextPath: WinRM.Process.Error description: STDERR of the WinRM command. - contextPath: WinRM.Process.Status description: Status code of the WInRM command. description: Executes a command on the host. execution: true - name: winrm-run-powershell arguments: - name: hostname description: The hostname to run the command on. This will override the default hostname specified in the instance. - name: entryID description: The entry ID of the powershell script to run (overrides scriptname and script). - name: script description: The powershell script to execute (requires code, not a file input). - name: scriptname description: Name of the script (optional). - name: decode auto: PREDEFINED predefined: - ascii - big5 - big5hkscs - cp037 - cp424 - cp437 - cp500 - cp737 - cp775 - cp850 - cp852 - cp855 - cp856 - cp857 - cp860 - cp861 - cp862 - cp863 - cp864 - cp865 - cp866 - cp869 - cp874 - cp875 - cp932 - cp949 - cp950 - cp1006 - cp1026 - cp1140 - cp1250 - cp1251 - cp1252 - cp1253 - cp1254 - cp1255 - cp1256 - cp1257 - cp1258 - euc_jp - euc_jis_2004 - euc_jisx0213 - euc_kr - gb2312 - gbk - gb18030 - hz - iso2022_jp - iso2022_jp_1 - iso2022_jp_2 - iso2022_jp_2004 - iso2022_jp_3 - iso2022_jp_ext - iso2022_kr - latin_1 - iso8859_2 - iso8859_3 - iso8859_4 - iso8859_5 - iso8859_6 - iso8859_7 - iso8859_8 - iso8859_9 - iso8859_10 - iso8859_13 - iso8859_14 - iso8859_15 - johab - koi8_r - koi8_u - mac_cyrillic - mac_greek - mac_iceland - mac_latin2 - mac_roman - mac_turkish - ptcp154 - shift_jis - shift_jis_2004 - shift_jisx0213 - utf_16 - utf_16_be - utf_16_le - utf_7 - utf_8 description: Decode codec to use when decoding command outputs (overrides value set in the instance). outputs: - contextPath: WinRM.Powershell.Output description: STDOUT of the WinRM command. - contextPath: WinRM.Powershell.Error description: STDERR of the WinRM command. - contextPath: WinRM.Powershell.Status description: Status code of the WInRM command. description: Executes a Powershell script on the endpoint. dockerimage: demisto/auth-utils:1.0.0.3562326 subtype: python3 fromversion: 5.0.0 tests: - No tests (auto formatted) beta: true