NetExec

crack map exec alternative

Introduction

NetExec is a tool for assisting in network service exploitation. It has tons of different modules for exploiting different kinds of network protocols, like RPC, SMB, and others like LDAP, WMI, SSH and FTP. 💥

You can find it online on Github, and the official documentation website:

Their documentation includes this note:

This tool is based on CrackMapExec and was originally created by bytebleeder and maintained by @mpgn over the years, shout out to them! With the retirement of mpgn, we (@zblurx, @Marshall and @NeffIsBack) decided to maintain the tool NetExec, formerly known as CrackMapExec, as a completely free open source tool.

As mentioned, NetExec has support for a lot of different protocols:

  • SMB

  • SSH

  • LDAP

  • FTP

  • WMI

  • WINRM

  • RDP

  • VNC

  • MSSQL

Often times, you'll interact with these using different sets of credentials, either with username or password pairing that you already know authenticate, or bruteforcing to uncover new access.

you should be able to run

or more simply:

Enumerating host with smb and Netexec

Enumerating SMB shares

NULL Logon Sessions

Trying Guest or Anonymous Sessions

Password Spraying

Dumping shares

We can use NetExec and its supported modules to dump or download all the files present on the share.

Finding Users

We may try with guest user or null session

Dumping LSA

Last updated