Cracking wmiexec in Rust by byte-diffing against impacket
Most people treat impacket as a library. I treat it as a debugging oracle — a black box that emits the exact bytes a Windows DC will accept, and my job is to reproduce those bytes byte-for-byte in Rust. That's how I got wmiexec working from scratch inside ADhammer, an Active Directory audit toolkit built on my own DCE/RPC · NTLM · SMundefined · Kerberos stack (think "impacket for Rust").
The whole project is built with Claude Code, and this was the tightest loop I've ever had with an AI. Not autocomplete — a real hypothesis → capture traffic → diff → fix cycle against a live domain controller, with Claude reading the diffs alongside me.
What wmiexec actually does
wmiexec is the classic "quiet" RCE path. Instead of creating a service (psexec/SVCCTL) or a scheduled task (atexec), you talk to WMI over DCOM and call Win32_Process.Create. No service-install event, different host telemetry. Under the hood it's three stages, each a different flavor of pain:
1. DCOM activation — you send a RemoteCreateInstance to the WMI DCOM server and get back an object reference.
2. OXID resolution — the DC returns an OXID string, and you have to call the OXID resolver to turn it into a binding. This is where most of the "garbage error" happens.
3. MS-WMIO object marshaling — you invoke the WMI service and class methods with correct NDR marshalling for
This looks complex. Did you manage the SMundefined negotiation table or just hardcode a single version?
I went with 3.1.1. Does the server always accept that without needing the full negotiation table?