GO KALI FREE

NetExec

Post Exploitation

Advancedhigh risk

NetExec (formerly CrackMapExec successor) is a post-exploitation tool for enumerating and attacking Active Directory environments. It automates SMB, WinRM, LDAP, and SSH attacks across large networks with support for Kerberos, NTLM, and pass-the-hash authentication.

Installation

sudo apt install netexec

Basic Syntax

netexec <protocol> <target> [options]

Quick Facts

Full Name
NetExec
License
BSD
Written In
Python
Platforms
Linux
Category
Active Directory / Post-Exploitation
Protocols
SMB, LDAP, WinRM, SSH, FTP, MSSQL
First Release
2019
Author
Pennyw0rth

Tool Overview

NetExec is the leading post-exploitation tool for Active Directory security testing. Successor to CrackMapExec, it provides automated SMB, LDAP, WinRM, SSH, and MSSQL enumeration and attack capabilities with pass-the-hash, Kerberos, and NTLM authentication support.

The tool's color-coded output (green for success, red for failure, yellow for partial) enables rapid interpretation of results across large network scans. Its modular architecture supports protocol-specific modules for targeted operations.

Security professionals use NetExec during Active Directory penetration tests to enumerate hosts, test credentials, discover accessible shares, extract user lists, dump password hashes, and perform lateral movement across Windows networks.

Common Commands

netexec smb 192.168.1.0/24SMB network scan — discover live SMB hosts across a subnet
netexec smb 192.168.1.10 -u admin -p passwordSMB authentication — test credentials against a target
netexec smb 192.168.1.10 -u admin -p password --sharesShare enumeration — list accessible SMB shares with credentials
netexec smb 192.168.1.10 -u admin -p password --usersUser enumeration — extract local user accounts from the target
netexec smb 192.168.1.10 -u admin -p password --samSAM dump — extract local password hashes from the SAM database
netexec ldap 192.168.1.10 -u admin -p password --groupsLDAP group enumeration — list Active Directory group memberships
netexec smb 192.168.1.0/24 -u admin -p password --pass-polPassword policy — retrieve password policy across the network
netexec smb 192.168.1.10 -u admin -p password --lsaLSA dump — extract cached credentials and LSA secrets
netexec smb 192.168.1.10 -u admin -p password -x whoamiCommand execution — run a command via SMB (wmiexec/atexec)
netexec winrm 192.168.1.10 -u admin -p password -X 'Get-Process'WinRM PowerShell — execute a PowerShell command over WinRM
netexec smb 192.168.1.0/24 -u users.txt -p passwords.txtPassword spray — test credential lists across a subnet
netexec smb 192.168.1.10 -u admin -H aad3b435...:31d6cfe0...Pass-the-hash — authenticate with an NTLM hash instead of a password
netexec smb 192.168.1.10 -u admin -p password -M spider_plusModule — run the spider_plus module to map share contents
netexec ldap 192.168.1.10 -u admin -p password --bloodhound -c AllBloodHound — collect AD data for graph analysis
netexec ldap 192.168.1.10 -u admin -p password --asreproast out.txtAS-REP roast — extract crackable hashes for users without preauth

Step-by-Step Guide

  1. 1Identify the target network range and verify SMB ports (139/445) are open using Nmap
  2. 2Perform initial network enumeration: netexec smb <range> to discover live hosts
  3. 3Test known credentials against discovered hosts to identify valid accounts
  4. 4Enumerate shares, users, and groups on authenticated hosts
  5. 5Use SMBClient for manual verification of high-value shares identified by NetExec
  6. 6Dump SAM hashes and LSA secrets for offline password cracking
  7. 7Use discovered credentials for lateral movement across the network
  8. 8Document all findings including accessible shares, users, and cracked passwords

Warnings

Use Cases

SMB Enumeration

Discover SMB hosts, test credentials, and enumerate shares across large networks.

LDAP Querying

Extract Active Directory users, groups, computers, and policies through LDAP queries.

Credential Dumping

Dump SAM and LSA secrets from Windows targets for offline password cracking.

Pass-the-Hash

Authenticate using NTLM hashes without knowing plaintext passwords for lateral movement.

Password Policy Audit

Retrieve domain password policies to inform brute-force attack strategies.

WinRM Access

Execute commands on targets using WinRM with valid credentials or hashes.

Related Tools

Impacket

Post Exploitation

Python collection of classes for working with network protocols including SMB, LDAP, and Kerberos.

CrackMapExec

Post Exploitation

Original AD enumeration tool that NetExec is based on.

SMBClient

Post Exploitation

Command-line tool for interacting with SMB shares directly.

Enum4linux

Information Gathering

SMB enumeration tool for detailed share and user information extraction.

Evil-WinRM

Post Exploitation

WinRM shell for remote command execution on Windows systems.

Frequently Asked Questions

What is NetExec used for?

NetExec is a post-exploitation tool for enumerating and attacking Active Directory environments. It automates SMB, LDAP, WinRM, and SSH operations with support for pass-the-hash, Kerberos, and credential spraying across large networks.

What is the difference between NetExec and CrackMapExec?

NetExec is the modern successor to CrackMapExec (CME). It offers better performance, more features, and active development. The syntax is similar but NetExec has additional protocol support and modules.

Can NetExec dump hashes?

Yes, NetExec can dump SAM and LSA secrets from Windows targets with administrative privileges using --sam and --lsa options.

Does NetExec support pass-the-hash?

Yes, NetExec supports pass-the-hash authentication using NTLM hashes instead of plaintext passwords for SMB, LDAP, and WinRM protocols.

How does NetExec handle SMB enumeration?

NetExec connects to target hosts over SMB (ports 139/445) and authenticates with provided credentials or hashes. Once authenticated, it can enumerate shares, users, groups, policies, and dump SAM/LSA data using protocol-specific modules.

Can NetExec perform credential testing across multiple hosts?

Yes, NetExec excels at credential testing across large networks. You can provide a username/password list and it will test credentials against all hosts in a subnet, identifying valid accounts and tracking lockout policies to avoid triggering account lockouts.

What is Pass-the-Hash in NetExec?

Pass-the-Hash allows NetExec to authenticate using NTLM hashes directly instead of plaintext passwords. This technique works because Windows authenticates using the hash value rather than the original password, enabling lateral movement without cracking the password.

How does NetExec support lateral movement?

NetExec facilitates lateral movement by identifying valid credentials on one host, dumping hashes and secrets, then using those credentials to authenticate to additional hosts. It supports pass-the-hash, pass-the-ticket, and Kerberos authentication for pivoting through Active Directory environments.

What protocols does NetExec support?

NetExec supports SMB (file sharing and authentication), LDAP (directory queries), WinRM (remote management), SSH (Linux systems), FTP (file transfer), and MSSQL (database enumeration) for comprehensive multi-protocol assessments.

How does NetExec logging work?

NetExec outputs color-coded results (green for success, red for failure, yellow for partial) in a structured format. Results can be logged using the --log flag for documentation, and the tool integrates with BloodHound for Active Directory visualization and analysis.

How do I install NetExec on Kali Linux?

Install with: sudo pipx install netexec. Or from GitHub: git clone https://github.com/Pennyw0rth/NetExec.git && cd NetExec && pip3 install -r requirements.txt. NetExec requires Python 3 and an active network connection.

Can NetExec enumerate LDAP attributes?

Yes, use NetExec with LDAP protocol: netexec ldap target -u user -p pass --attributes. Query specific AD attributes like memberOf, userAccountControl, and servicePrincipalNames for detailed enumeration.

How do I use NetExec with Kerberos authentication?

Use --use-krb5 for Kerberos authentication: netexec smb target -u user -k. Ensure you have a valid Kerberos ticket (use kinit first) and configure DNS resolution for the domain controller.

Can NetExec perform password spraying?

Yes, NetExec excels at password spraying: netexec smb targets.txt -u users.txt -p Password1 --no-bruteforce. This tests one password against multiple users, avoiding account lockouts from brute-force attempts.

How do I extract NetLogon hashes with NetExec?

Use the --lsa flag: netexec smb target -u admin -p pass --lsa. NetExec extracts LSA secrets including service account passwords, trust keys, and cached domain credentials from Windows systems.

Can NetExec enumerate shares recursively?

Use --shares to list shares and --recursive to enumerate contents: netexec smb target -u user -p pass --shares --recursive. This discovers all accessible files and directories across SMB shares.

How does NetExec handle account lockout prevention?

Use --no-bruteforce to test one credential at a time, --delay to add pauses between attempts, and --jitter to randomize timing. Monitor target lockout policies and adjust accordingly.

Can NetExec execute commands via WinRM?

Yes, use the WinRM protocol: netexec winrm target -u user -p pass -x 'whoami'. This executes commands on Windows targets through Windows Remote Management, similar to PowerShell remoting.

How do I integrate NetExec with BloodHound?

Use NetExec to gather AD data and import into BloodHound: netexec ldap target -u user -p pass --bloodhound -c all. This collects AD objects and relationships for visualization in BloodHound's graph interface.

Tags

#post-exploitation#active-directory#smb-attacks#credential-dumping#lateral-movement

Output Explanation

NetExec output uses color-coded results: green for success (authenticated, accessible), red for failure (denied, locked), and yellow for partial results. The tool displays host status, authentication results, share listings, user enumerations, and hash dumps in a structured format suitable for scripting and automation.

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.