All tools

Active Directory

CrackMapExec / NetExec

Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).

intermediate
Linux
Enumeration
Lateral Movement
Post-Exploitation

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Spraying creds, enumerating SMB/WinRM/LDAP, and validating access at scale.

How

Provide subnet + creds/protocol module; use carefully with lockout policies.

Why

Fast situational awareness across Windows estates.

Commands & usage

nxc smb 192.168.1.0/24
nxc smb 192.168.1.0/24 -u user -p pass --shares
nxc smb 192.168.1.10 -u user -H aad3b435b51404eeaad3b435b51404ee:ntlmhash -x whoami
nxc ldap 192.168.1.10 -u user -p pass --users

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

ad
smb
spraying

Related in Active Directory