The Active Directory workhorse (CrackMapExec's successor): validate creds, enumerate shares/users, and execute β across whole subnets at once.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
One command fingerprints every Windows host on the range.
Green = valid creds. [Pwn3d!] = admin rights on that box.
Spraying classics β mind lockout policies even in labs (good habit).
Access mapped = lateral movement planned.
Authenticated command exec across Windows β controlled chaos.
| smb/wmi/winrm | protocols |
| -u/-p/-H | user/pass/hash |
| --shares/--users | enumeration |
| -x 'cmd' | execute |
| --local-auth | local accounts |
| --sam/--lsa | dump (lab!) |
[Pwn3d!] marker = admin; liners like --shares on those are your next hour.
Pair with Responder β captured hash β nxc -H hash everywhere.
BloodHound first, nxc second: know the map, then walk it.
Impacket suite does what nxc can't; they overlap, learn both.
Use NetExec (nxc) only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.