Active Directory
CrackMapExec / NetExec
Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Spraying creds, enumerating SMB/WinRM/LDAP, and validating access at scale.
How
Provide subnet + creds/protocol module; use carefully with lockout policies.
Why
Fast situational awareness across Windows estates.
Commands & usage
nxc smb 192.168.1.0/24
nxc smb 192.168.1.0/24 -u user -p pass --shares
nxc smb 192.168.1.10 -u user -H aad3b435b51404eeaad3b435b51404ee:ntlmhash -x whoami
nxc ldap 192.168.1.10 -u user -p pass --users
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
ATT&CK
Tags
Related in Active Directory
Impacket
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
BloodHound / SharpHound / AzureHound
Maps Active Directory attack paths using graph theory.
Rubeus
C# toolset for Kerberos abuse (AS-REP, kerberoast, tickets, etc.).
enum4linux-ng
SMB/Windows enumeration tool wrapping common Samba tools.
SMBMap
Enumerates Samba share drives across networks with permissions.
ldapsearch / windapsearch
Query LDAP/Active Directory directory data.