> For the complete documentation index, see [llms.txt](https://ad-lab.gitbook.io/building-a-windows-ad-lab/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ad-lab.gitbook.io/building-a-windows-ad-lab/lab-setup/building-the-lab/creating-bank.local/creating-amsterdam.bank.local/creating-w10-client-ws01/psremoting.md).

# PSRemoting

PSRemoting allows you to run commands on remote computers just as if you were sitting in front of them. You could see it as the Windows SSH service.

## Enabling PSRemoting

1. Login to `WS01` as the `Administrator` user with password `Welcome01!`.
2. Start PowerShell as administrator and run the following command:

```
Enable-PSRemoting
```

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2FOwBwqHi6DXySbxq79DoE%2Fimage.png?alt=media&amp;token=4c965760-0dc2-4903-9ee9-40e9ae23f170" alt=""></div>

> The `Enable-PSRemoting` cmdlet performs the following operations:
>
> * Runs the [Set-WSManQuickConfig](https://docs.microsoft.com/en-us/powershell/module/microsoft.wsman.management/set-wsmanquickconfig?view=powershell-7.2) cmdlet, which performs the following tasks:
>   * Starts the WinRM service.
>   * Sets the startup type on the WinRM service to Automatic.
>   * Creates a listener to accept requests on any IP address.
>   * Enables a firewall exception for WS-Management communications.
>   * Creates the simple and long name session endpoint configurations if needed.
>   * Enables all session configurations.
>   * Changes the security descriptor of all session configurations to allow remote access.
> * Restarts the WinRM service to make the preceding changes effective.\
>   Source: <https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/enable-psremoting?view=powershell-7.2>

Users of the local `Administrators` or `Remote Management Users` groups can connect to the machine.

### Giving a normal user access to the service

Local admin acces is not required, it is possible as a normal user if its part of the `Remote Management Group`.

1. Add `John` to the `Remote Management Users` on `WS01` by executing the following command:

```
net localgroup "Remote Management Users" john /add
```

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2F9Bfv8gQwxFK6bkqlx7gr%2Fimage.png?alt=media&amp;token=bac7b6d8-861c-4186-ab8c-4bf491d0210b" alt=""></div>

## Testing

1. Login to `DC01` as the `Administrator` user with password `Welcome01!`
2. Start PowerShell and run the following command to connect to `WS01` as `Administrator`:

```
Enter-PSSession ws01
```

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2FMiXBedVkEgyKNKcs9p1n%2Fimage.png?alt=media&amp;token=e49294f5-1b30-4976-8158-16ad95794fb2" alt=""></div>

3\. Create a PSCredential for the user `John` with the password `Welcome2022!` using the `Get-Credential` command.

```
$creds = Get-Credential
```

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2Fg3ctga3ebGZ3l0p9Cyfs%2Fimage.png?alt=media&amp;token=5a91657b-c937-42ba-a39a-81b4e8574e73" alt=""></div>

4\. Run the following command to connect to `WS01` as `John`:

```
Enter-PSSession WS01 -Credential $creds
```

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2FKxVigjlGQl9rAXkvL1uV%2Fimage.png?alt=media&amp;token=936a3800-78fd-48d4-a2b6-725b0f1d6ce1" alt=""></div>

Read more about PSRemoting and lateral movement:

{% content-ref url="/pages/C5v204Xxo20vM0Haa90A" %}
[PSRemoting](/building-a-windows-ad-lab/vulnerabilities-and-misconfigurations-and-attacks/misc/lateral-movement/psremoting.md)
{% endcontent-ref %}
