≈801 tokens on demand. Your agent reads this file only when SKILL.md points to it.
CrackMapExec / NetExec Module Recommendations
Curated module list for internal engagements. Invoke with nxc <proto> <target> ... -M <module>.
Information gathering (SMB)
| Module |
Purpose |
enum_av |
Identify AV/EDR product on target |
enum_dns |
Pull DNS records from SMB share //dc/SYSVOL\policies |
get_netconnections |
Discover outbound network connections from host |
get_description |
AD computer description field harvesting |
get_localgroups |
Local groups + membership via SAMR |
get_loggedon_users |
Live logged-on users |
get_sessions |
Active SMB sessions |
spider_plus |
Share spidering with include/exclude filters, content search |
veeam |
Look for Veeam creds on Veeam backup servers |
met_inject |
Mssql linked-server enumeration |
Credential access
| Module |
Purpose |
lsassy |
Remote LSASS dump + offline pypykatz parse |
nanodump |
LSASS dump via NanoDump (stealthier) |
handlekatz |
LSASS via process handle duplication |
mimikatz |
Invoke in-memory mimikatz (loud; triggers EDR) |
masky |
Abuse ADCS ESC1 via template from computer context |
dpapi |
Decrypt DPAPI-protected secrets (requires master key) |
rdcman |
Extract Remote Desktop Connection Manager stored creds |
wifi |
Dump Wi-Fi profiles + cleartext passwords |
AD / LDAP modules
| Module |
Purpose |
adcs |
Enumerate ADCS templates and mark ESC1/ESC4/ESC6/ESC8 candidates |
laps |
Retrieve LAPS-managed local admin passwords |
gmsa |
Dump gMSA NT hashes for readable accounts |
maq |
Print ms-DS-MachineAccountQuota value |
group-mem |
Recursively resolve a group's members |
user-desc |
Pull description fields for all user objects (cleartext password hunt) |
whoami |
Who am I in the domain (groups, SID) |
subnets |
Get AD Sites subnet definitions |
Coercion
| Module |
Purpose |
petitpotam |
MS-EFSR coercion |
shadowcoerce |
MS-FSRVP coercion |
dfscoerce |
MS-DFSNM coercion |
printerbug |
MS-RPRN coercion (SpoolSample) |
coerce_plus |
Auto-select coercion primitive and fire |
Exploitation
| Module |
Purpose |
zerologon |
Test / exploit CVE-2020-1472 (destructive — resets DC$ password) |
noPac |
CVE-2021-42278/42287 sAMAccountName spoofing |
printnightmare |
PrintNightmare RCE test |
ms17-010 |
EternalBlue detection |
smbghost |
CVE-2020-0796 SMBv3 compression bug |
Recommended default run (passive)
nxc smb targets.txt -u "$USER" -p "$PASS" \
-M enum_av -M get_sessions -M get_loggedon_users -M spider_plus
nxc ldap dc.corp.local -u "$USER" -p "$PASS" \
-M adcs -M laps -M gmsa -M maq -M user-desc
Safety
zerologon: the test will break DC netlogon until the DC$ password is reset — DO NOT RUN without authorization and customer rollback plan.
mimikatz module loads mimikatz in memory — EDR-visible. Prefer lsassy with obfuscation for routine LSASS dumps.
spider_plus with DOWNLOAD_FLAG=True can exfiltrate files — confirm this is in scope and configure --max-size.