NetExec (nxc) Cheat Sheet
Reference for NetExec (nxc). Covers multi-protocol enumeration (SMB, LDAP, WinRM, MSSQL, RDP, WMI, SSH, VNC, FTP), safe password spraying, credential harvesting, BloodHound CE collection, execution methods, and detection telemetry.
Understanding NetExec Architecture
NetExec (nxc) is the modern, actively maintained successor to CrackMapExec (cme). Built on a modular Python asynchronous architecture, it automates assessment tasks across nine distinct network protocols. Rather than executing disjointed scripts, NetExec unifies network discovery, authentication testing, credential harvesting, and remote execution into a single, cohesive interface.
NetExec Architecture & Protocol Pipeline
Explore how NetExec coordinates multi-protocol enumeration, credential harvesting, and execution.
NetExec Core Orchestrator (`nxc`)
Async Python EngineCentral dispatcher managing concurrent network sockets, rate-limiters, credential vaults, and community modules.
SMB / CIFS Deep Dive
Default Port: 445 / 139Share enumeration, file spidering, relay target lists, local SAM/LSA dumping, and remote command execution.
nxc smb 10.10.10.0/24 -u 'Admin' -H 'hash...' --sam --lsaInstallation & Setup
Install NetExec via pipx to isolate its dependencies and ensure access to modern protocol extensions and community modules.
Tip: NetExec stores configuration files, protocol databases, and downloaded logs in
~/.nxc/. Protocol modules reside in~/.nxc/modules/.
Global Options & The Built-in Database Engine
::Command Structure Anatomy
NetExec commands follow a modular structure: Protocol → Scope / Target → Authentication → Assessment Action / Module.
NetExec Command Architecture & Token Anatomy
Click any token in the command stream below to inspect its operational mechanism, syntax rules, and alternatives.
Identity & Credentials
authUser authentication via NTLM Pass-the-Hash (PtH).
Accepts 32-character NT hashes, LM:NT pairs, plaintext passwords (-p), or Kerberos ticket caches (-k).
| Global Flag | Example Value | Operational Behavior & Default |
|---|---|---|
-t | 50 or 100 | Concurrent worker threads (default: 100 network scan, 50 command execution). |
--timeout | 5 | Socket response threshold in seconds (default: 2.0s). Adjust higher over slow VPN links. |
--jitter | 2-5 | Randomized pause range (seconds) injected between targets to defeat rate-based SIEM rules. |
--delay | 10 | Static sleep interval (seconds) enforced between consecutive authentication attempts. |
--continue-on-success | (Flag) | Continue auditing remaining accounts in a wordlist even after locating valid credentials. |
--no-bruteforce | (Flag) | Enforces 1:1 pair matching (user1:pass1, user2:pass2) rather than Cartesian matrix spraying. |
--local-auth | (Flag) | Directs authentication against the target's local SAM rather than domain Active Directory. |
-k | (Flag) | Enforce Kerberos negotiation instead of NTLM (requires target FQDN, not IP). |
--use-kcache | (Flag) | Read and inject valid Kerberos ticket-granting tickets directly from the environment cache. |
::Target Specification Syntax
NetExec handles multiple target representations seamlessly:
::The Built-in SQLite Database (nxc db)
Every successful authentication, discovered host, open share, and extracted credential hash is automatically indexed in NetExec's local SQLite store (~/.nxc/workspaces/).
Unified Multi-Protocol Architecture Matrix
NetExec supports nine network protocols out of the box. Use the matrix below to identify capabilities, default network ports, and supported execution mechanics.
| Protocol | Default Port | Primary Assessment Focus | Remote Execution | Key Modules Available |
|---|---|---|---|---|
| SMB | 445 / 139 | Host recon, share hunting, SAM/LSA/NTDS dumping, relaying | Yes (--exec-method) | spider_plus, lsassy, nanodump, slinky, coerce_plus |
| LDAP(S) | 389 / 636 | AD directory objects, BloodHound CE ingest, AS-REP/Kerberoast | No | adcs, maq, pre2k, whisker, rbcd, ldap-checker |
| WinRM | 5985 / 5986 | Administrative PowerShell management, lateral movement | Yes (-x, -X) | Native PowerShell execution |
| MSSQL | 1433 | Database auditing, xp_cmdshell execution, hash capturing | Yes (-x) | mssql_priv, slinky |
| RDP | 3389 | NLA verification, user credential testing, desktop snapshots | No | --screenshot |
| WMI | 135 / RPC | DCOM-based remote process invocation | Yes (-x, -X) | Native process execution |
| SSH | 22 | Linux host auditing, key and credential spraying | Yes (-x) | Key file authentication (--key-file) |
| VNC | 5900 | Remote screen session validation | No | Screen capture / password auth |
| FTP | 21 | Anonymous access, sensitive backup file harvesting | No | --ls, --get |
Authentication & Identity Mechanics
NetExec supports multiple authentication primitives. Mastering these flags prevents account lockouts and enables Pass-the-Hash, Kerberos ticket injection, and certificate-based PKINIT authentication.
::Null Sessions & Guest Accounts
::Local Authentication vs Domain Authentication
By default, NetExec evaluates credentials against the target host's domain. When auditing standalone servers, workstations, or local administrator accounts, use --local-auth.
::Pass-the-Hash (PtH)
NetExec accepts NTLM hashes in either LM:NT format or raw 32-character NT hash format using the -H flag:
::Kerberos & Ticket Cache (KRB5CCNAME)
Using Kerberos avoids generating NTLM challenge-response pairs on the wire, making actions stealthier and bypassing NTLM-disabled environments.
Warning: When using Kerberos (
-kor--use-kcache), you must supply target hostnames (e.g.dc01.corp.local), not raw IP addresses, so that NetExec can construct valid Service Principal Names (SPNs).
::Certificate & PKINIT Authentication
NetExec supports Public Key Cryptography for Initial Authentication (PKINIT) using exported .pfx certificates or paired PEM files:
Phase 1: Discovery, Recon & Misconfiguration Auditing
Begin an engagement with zero-privilege and unauthenticated enumeration to map signing policies, locate relay targets, and inspect password complexity rules.
::SMB Signing & Relay List Generation
SMB Relay attacks require targets where SMB message signing is not required (Signing: False). NetExec scans entire subnets and formats valid relay targets automatically.
::Domain Password Policy Auditing
Before conducting password spraying, always extract the domain password policy to determine the BadPasswordCount, LockoutDuration, and ResetLockoutCounter thresholds.
Example Output Breakdown:
- ▹
Account Lockout Threshold:5(Spraying must not exceed 4 failed attempts within the reset window). - ▹
Lockout Observation Window:30 mins(Wait 31+ minutes before spraying the next candidate password).
::Share & IPC Enumeration
::RID Cycling / Brute-Forcing
When unauthenticated LDAP is blocked, query the local LSA/SAM interface via SMB SID resolution to discover domain users and groups:
::WebDAV & Coercion Prerequisite Detection
The WebClient (WebDAV) service on Windows workstations provides an HTTP attack vector for NTLM relaying to ADCS or LDAP.
Phase 2: Credential Auditing & Password Spraying
Password spraying attempts one password against many users to prevent triggering lockout thresholds. Always calculate delays based on the discovered --pass-pol.
::Safe Password Spraying Execution
::1:1 Credential Testing (--no-bruteforce)
When testing credential lists obtained from external breach dumps or past compromises, pair each user with their corresponding password without doing a combinatorial cross-product:
::Cross-Protocol Validation
Once a credential set is validated, test access across other remote services:
Phase 3: Active Directory & LDAP Deep Dive
LDAP is the primary protocol for auditing Active Directory structures, certificate authorities, Kerberos tickets, and delegation misconfigurations.
::BloodHound CE Data Collection
NetExec includes a native BloodHound ingestor, eliminating the need to drop external binaries or PowerShell scripts on disk.
::Kerberoasting & AS-REP Roasting
Harvest Kerberos ticket hashes for offline cracking with Hashcat (modes 13100 and 18200):
::ADCS (Active Directory Certificate Services) Audit
Locate Enterprise Certificate Authorities and vulnerable certificate templates (e.g. ESC1, ESC2, ESC3, ESC8):
::Delegation & Machine Account Quota (MAQ)
::Group Managed Service Accounts (gMSA)
Accounts configured as gMSA have 128-character managed passwords rotated automatically by Active Directory. If an account has ReadGMSAPassword rights, NetExec extracts and decrypts the password blob:
Phase 4: Multi-Protocol Service Assessment
::WinRM Protocol (TCP 5985/5986)
WinRM provides native remote management for Windows hosts. If an account is part of Remote Management Users or Administrators, execution runs natively without creating SMB services.
::MSSQL Protocol (TCP 1433)
NetExec interacts directly with Microsoft SQL Server instances using SQL native authentication, Windows domain authentication, or Kerberos.
::RDP Protocol (TCP 3389)
Audit Network Level Authentication (NLA) status, validate credentials without establishing interactive sessions, and capture desktop screenshots.
::Native WMI Protocol (TCP 135 / RPC)
Modern NetExec includes a native wmi protocol implementation that bypasses SMB port 445 entirely:
::SSH, FTP & VNC Operations
Phase 5: Share Spidering, File Hunting & Coercion
::Comprehensive Share Spidering (spider_plus)
The spider_plus module catalogs all accessible shares across an organization, producing a JSON tree of files while filtering out noise.
::File Upload & Download Operations
::Authentication Coercion Suite
Coerce machine accounts into authenticating to an attacker-controlled listener (e.g. Responder, ntlmrelayx) using MS-RPRN or MS-EFSR protocols:
::Malicious Shortcut Injection (slinky)
Place .lnk files in writable network shares to coerce NTLM hashes when domain users navigate to the folder in Windows Explorer:
Phase 6: Credential Extraction & Secrets Harvesting
Once administrative access ((Pwn3d!)) is confirmed, extract credentials from local storage, Active Directory databases, or process memory.
::Local Credential Extraction (SAM, LSA, DPAPI)
::Domain NTDS.dit Extraction
Extracting NTDS.dit provides password hashes for every account in the Active Directory domain.
::LAPS Password Extraction (Legacy & Windows LAPS)
Local Administrator Password Solution (LAPS) stores randomized local admin passwords in Active Directory attributes. NetExec queries both legacy and modern Windows LAPS schemas:
Note: Legacy LAPS utilizes the attribute
ms-Mcs-AdmPwd(plaintext), whereas modern Windows LAPS (Windows 11 / Server 2022+) stores passwords inmsLAPS-Password(optionally encrypted). NetExec handles schema negotiation automatically.
::LSASS Process Memory Dumping
Dumping lsass.exe directly often alerts modern EDR solutions. NetExec integrates multiple specialized modules designed to minimize detection:
::Group Policy Preference (GPP) Passwords
Legacy Domain Controllers often retain encrypted passwords in SYSVOL policy XML files (Groups.xml, Services.xml). NetExec recovers and decrypts them using the static Microsoft AES private key:
Phase 7: Execution Methods & Tradecraft Matrix
When executing commands over SMB, NetExec provides multiple backend mechanisms configured via --exec-method. Choosing the appropriate method depends on the target's operating system version and endpoint security posture.
::Under-The-Hood Execution Comparison
| Method | Protocol / API | Service Created? | Output Delivery Mechanism | Forensic Indicator |
|---|---|---|---|---|
wmiexec | DCOM (135) / WMI (Win32_Process) | No | Output written to temp file via cmd.exe /c redirected to ADMIN$ or C$ | Process creation with parent WmiPrvSE.exe |
smbexec | RPC / Service Control Manager (SVCCTL) | Yes | Temporary Windows service executes .bat script, pipes to __output share file, deletes service | Windows Event ID 7045 / 4697 generated |
atexec | RPC / Task Scheduler (ATSVC / ITaskScheduler) | No | Creates scheduled task set to run immediately, extracts output from temp file, deletes task | Windows Event ID 4698 (Scheduled Task created) |
mmcexec | DCOM (MMC20.Application) | No | Invokes Document.ActiveView.ExecuteShellCommand via COM | Spawned process child of mmc.exe |
Key Rule: Avoid
smbexecagainst environments monitored by SIEM or EDR, because creating and instantly deleting a service triggers high-confidence detection rules (7045). Preferwmiexecor nativewinrm.
MSFvenom Cheat Sheet
Enhanced, practical msfvenom reference covering payload generation across all platforms, staged vs stageless selection, encoding, encryption, bad-character handling, template injection, advanced handlers, and real-world delivery techniques.
File Transfer Techniques
Cheatsheet for moving files across Linux, Windows, restricted shells, and inspected networks. Built for CTF players, bug bounty hunters, and internal pentesters.
Active Directory Enumeration & Attacks Cheatsheet
A comprehensive reference for AD enumeration and attack paths — covering external/internal recon, password spraying, network poisoning, credentialed enumeration, ACL abuse, Kerberos attacks, delegation abuse, lateral movement, domain dominance, GPO exploitation, ADCS misconfigurations, cross-forest trust abuse, and advanced exploits. Designed for Red Team engagements.
