Why does an operator prefer WMI or a WS-Man shell over creating a service on the ADMIN$ share to run code on a target?
answer
- reuse what already runs
- already listening, nothing new
- service-create writes and registers
- fewer steps, nothing on disk
basics
~20 sWMI and a WS-Man shell invoke a management service already running and listening on the target, so nothing new must be written or installed. Service creation over the admin share requires writing an executable to the host and standing up a new service — more steps and more footprint.
solid answer
~40 sThe channels differ in how much the operator has to build on the target. Service creation over the admin share means copying an executable to the host's disk and registering a new service to run it — extra steps, a file on disk, and a service that persists until removed. WMI and a WS-Man remote shell reach a management service that is already running and listening on the host, so the operator invokes something already present and can run the payload in memory. Fewer round trips, nothing new installed, nothing dropped to disk. Given the choice, an operator reuses the infrastructure operations already runs rather than standing up their own — it is quieter and cheaper — though it still requires admin rights on the destination.
go deeper
Know that some channels reuse a service already running on the host while service creation stands up a new one.
Explain that WMI and WS-Man invoke an already-listening management service, so there is no new service to register and often nothing written to disk.
Reason about why an operator optimises for the lowest-footprint channel and how 'already listening' still requires admin rights and reachability.
Consider that these management services exist for legitimate remote administration, so the trade-off is operability versus exposure of the listening endpoints, owned with the hardening decision.
## Same goal, different cost on the target All of these channels run code on a remote host with a valid admin credential. What separates them is **how much the operator has to construct on the destination**, and that cost is what an experienced operator optimises. ## What service creation over the admin share costs To run code by creating a service, the operator typically: 1. Writes an executable to the target — for example copying it to a path under the administrative share. 2. Registers a **new service** that points at that executable. 3. Starts the service so the code runs. That is a file placed on the target's disk plus a newly created service. Both persist until removed, and both are things that did not exist on the host a moment earlier. It works, but it leaves the operator with more to build and more to clean up. ## What WMI and WS-Man cost instead WMI and a WS-Man remote shell reach a **management service that is already running and listening** on the host. The operator invokes an existing capability rather than installing one: no new service to register, and often nothing written to disk because the payload can be run in memory. That means fewer round trips and a smaller footprint on the target for the same result. The general principle is: **reuse what operations already runs.** The estate keeps these management services listening precisely so administrators can drive them remotely — which is exactly why they are attractive to an intruder holding the right credential. ## Already-listening changes effort, not authority A crucial qualifier: choosing an already-listening channel lowers the operator's *effort and footprint*, not the *authorisation bar*. WMI and a WS-Man shell still require: - **Administrative authority on the destination host** — the credential must be privileged on the target. - **Network reachability to the listening service's port** — the management endpoint must be reachable from the source. So 'already listening' is not 'no permission needed'. It means the operator does not have to create the mechanism, only to authenticate to one that is already there. ## Why interviewers ask it The wrong instinct is that dropping and running your own service is stealthier or more reliable than using a built-in one. In practice it is the opposite: writing a binary and registering a service is more to do and more to remove, while a running management service lets code execute with nothing new stood up. Understanding this is understanding why operators gravitate to WMI and WS-Man over service creation when they have the choice.
- Does 'already listening' change who is allowed to use the channel?No. The precondition is still administrative authority on the target plus network reachability to the listening service's port. Already-listening lowers the operator's effort and footprint, not the authorisation bar — WMI and a WS-Man shell both still require admin rights on the destination.
- What specifically does service creation cost that WMI avoids?Writing an executable to the target's disk and registering a new service to run it — two extra steps and something that persists until removed. WMI executes through a service already present, so there is no new service, and if the payload runs in memory there is nothing dropped to disk.
saying these in an interview costs you the question
- Thinks every remote channel requires dropping a file first
- Assumes creating your own service is stealthier than reusing a running one
- Believes already-listening channels need no admin rights on the target