寻求Python中替代WinRM的远程Windows桌面操作模块
Hey there! Let’s work through your problem—you need a Python-based alternative to WinRM for interacting with remote Windows machines (since some don’t have WinRM set up) to copy over VB scripts, run them, and pull back the result files. Here are some reliable solutions that fit the bill:
Option 1: Use pypsexec (PsExec wrapper for Python)
PsExec is a trusted Sysinternals tool that lets you run commands on remote Windows machines, and pypsexec wraps it into a clean Python API. It relies on SMB (enabled by default on most Windows systems) and works without needing WinRM.
Setup & Example
First install the package:
pip install pypsexec
Then use this code flow to handle file transfer, execution, and result retrieval:
from pypsexec.client import Client # Initialize connection to remote Windows machine client = Client("remote_win_host", username="admin_user", password="secure_pass") client.connect() try: # Upload your VB script to the remote temp directory client.copy_file("local_script.vb", "C:\\temp\\remote_script.vb") # Execute the script using cscript (Windows' VB script runner) stdout, stderr, return_code = client.run_executable( "cscript.exe", arguments="C:\\temp\\remote_script.vb" ) print("Script Output:\n", stdout.decode()) print("Errors (if any):\n", stderr.decode()) # Pull the result file back to your local system client.copy_file_from_remote("C:\\temp\\test_results.txt", "local_results.txt") finally: # Clean up the connection client.disconnect()
Notes
- You’ll need admin-level credentials for the remote machine.
pypsexechandles the PsExec binary setup automatically, so no extra manual steps on the target.
Option 2: Combine SMB for File Transfer + WMI for Remote Execution
If you prefer using built-in Windows services instead of external tools, this combo uses SMB (for file transfers) and WMI (for running commands)—both enabled by default on nearly all Windows installations.
Setup & Example
Install the required packages:
pip install smbprotocol wmi
Step 1: Upload the VB script via SMB
from smbprotocol.connection import Connection from smbprotocol.session import Session from smbprotocol.tree import TreeConnect # Connect to the remote machine's C$ share (admin access required) with Connection("remote_win_host", 445) as conn: conn.connect(username="admin_user", password="secure_pass") with Session(conn) as session: with TreeConnect(session, "C$") as tree: # Upload local script to remote temp folder with open("local_script.vb", "rb") as local_file: with tree.open_file("temp\\remote_script.vb", "w") as remote_file: remote_file.write(local_file.read())
Step 2: Run the script via WMI
import wmi # Initialize WMI connection c = wmi.WMI(computer="remote_win_host", user="admin_user", password="secure_pass") # Execute the VB script process_id, return_code = c.Win32_Process.Create( CommandLine="cscript C:\\temp\\remote_script.vb" ) # Wait for the process to finish (you can add a delay or check process status here) # Then pull the result file using the same SMB code from Step 1 (reverse the copy direction)
Option 3: SSH via Paramiko (if you can enable OpenSSH on the target)
If you have the ability to pre-configure the remote Windows machine, enabling the OpenSSH Server feature (available as an optional component in Windows 10/11 and Server 2019+) lets you use paramiko—the standard Python SSH library—just like you would with Unix systems.
Setup & Example
Install the package:
pip install paramiko
Then use this workflow:
import paramiko # Initialize SSH connection ssh = paramiko.SSHClient() ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy()) ssh.connect("remote_win_host", username="admin_user", password="secure_pass") try: # Upload script via SFTP sftp = ssh.open_sftp() sftp.put("local_script.vb", "C:/temp/remote_script.vb") sftp.close() # Execute the script stdin, stdout, stderr = ssh.exec_command("cscript C:\\temp\\remote_script.vb") print("Script Output:\n", stdout.read().decode()) print("Errors (if any):\n", stderr.read().decode()) # Retrieve result file sftp = ssh.open_sftp() sftp.get("C:/temp/test_results.txt", "local_results.txt") sftp.close() finally: ssh.close()
Quick Recap
- For zero extra configuration on the remote machine, go with
pypsexecor the SMB+WMI combo—they leverage default Windows services. - If you can pre-set up OpenSSH on the target,
paramikogives you a familiar, Unix-like workflow that’s easy to adapt.
内容的提问来源于stack exchange,提问作者Jagan

