home/toolvault/exploitation/netexec-nxc

NetExec (nxc) //

Exploitationnetwork execution

The Active Directory workhorse (CrackMapExec's successor): validate creds, enumerate shares/users, and execute β€” across whole subnets at once.

difficulty Β· intermediate
20 min
time to first win
5
guided steps
0
students started here*

HOW TO USE NETEXEC

Follow the steps β€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

netexec-nxc β€” guided lab session
static view
step 01

Map the lab subnet

nxc smb 10.0.2.0/24

One command fingerprints every Windows host on the range.

step 02

Test stolen creds

nxc smb 10.0.2.10 -u user1 -p 'Pass123'

Green = valid creds. [Pwn3d!] = admin rights on that box.

step 03

Password spray the safe way

nxc smb 10.0.2.10 -u users.txt -p 'Summer2026!' --continue-on-success

Spraying classics β€” mind lockout policies even in labs (good habit).

step 04

Enumerate everything

nxc smb 10.0.2.10 -u user1 -p 'Pass123' --shares --users

Access mapped = lateral movement planned.

step 05

Execute (lab)

nxc smb 10.0.2.10 -u admin -p 'Pass123' -x 'whoami'

Authenticated command exec across Windows β€” controlled chaos.

THE WORKFLOW AT A GLANCE

🌐
Sweep
subnet smb
πŸ”‘
Creds
validate
πŸ“‚
Enum
shares/users
↔️
Lateral
next host
πŸ‘‘
[Pwn3d!]
system
LEARNING CURVE
intermediate β€” 20 min to first win

FLAGS & SUPER-MOVES

smb/wmi/winrmprotocols
-u/-p/-Huser/pass/hash
--shares/--usersenumeration
-x 'cmd'execute
--local-authlocal accounts
--sam/--lsadump (lab!)

PRO TIPS

01

[Pwn3d!] marker = admin; liners like --shares on those are your next hour.

[Pwn3d!] marker = admin; liners like --shares on those are your next hour.

02

Pair with Responder β†’ captured hash β†’ nxc -H hash everywhere.

Pair with Responder β†’ captured hash β†’ nxc -H hash everywhere.

03

BloodHound first, nxc second

BloodHound first, nxc second: know the map, then walk it.

04

Impacket suite does what nxc can't; they overlap, learn both.

Impacket suite does what nxc can't; they overlap, learn both.

βš–οΈ

Golden rule

Use NetExec (nxc) only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 Β· v2 immersive Β· latest news
Made for learners, everywhere Β· 2026
*plausibly. verify commands with official docs.