#NetExec
Small technical update: Impacket and therefore NetExec now support LDAP Channel Binding🔥

Finally you can use all the great features NetExec has to offer even in more mature environments
November 26, 2024 at 5:05 PM
ldap socks on netexec / nxc 🎃
January 2, 2025 at 10:22 PM
So you want to exploit ADCS ESC8 with only netexec and ntlmrelayx ? Fear not my friend, I will show you how to do it 👇

NetExec now supports "Pass-the-Cert" as an authentication method, thanks to @dirkjanm.io original work on PKINITtools ⛱️
January 6, 2025 at 8:33 PM
The AD Grave: Tombstoned objects🪦

If the AD Recycle Bin is enabled, objects are moved to the "Deleted Objects" container if they are "deleted". With the new "tombstone" NetExec module, you can query and restore such objects (given you have the required privs).
Made by Fabrizzio🚀
September 25, 2026 at 2:24 PM
NetExec has a new Module: Timeroast🔥

In AD environments, the DC hashes NTP responses with the computer account NT hash. That means that you can request and brute force all computer accounts in a domain from an UNAUTHENTICATED perspective!

Implemented by Disgame

1/3🧵
December 1, 2024 at 4:16 PM
Generate a valid krb5 conf file directly from netexec 🔥

Not that NXC needs it, but sometimes you gotta help other tools for them to work. 😂
January 20, 2025 at 8:11 AM
New module on #NetExec : wam
Dump #Entra access tokens from Windows Token Broker Cache, and make your way to Entra 🚀

Thanks @xpnsec.com for the technique! More info on his blog : blog.xpnsec.com/wam-bam/
December 18, 2024 at 4:26 PM
DCsync a domain when you find a user in the Backup Operators group using netexec, very simple and no need for a custom smb server 😛🏆
January 13, 2025 at 8:19 PM
NetExec v1.4.0 has been released! 🎉

There is a HUGE number of new features and improvements, including:
- backup_operator: Automatic priv esc for backup operators
- Certificate authentication
- NFS escape to root file system

And much more!
Full rundown available at:
github.com/Pennyw0rth/N...
April 14, 2025 at 1:47 PM
SPN-less RBCD with NetExec🔥

While classic RBCD requires a computer account, you can use User-to-User (U2U) authentication to perform RBCD with a normal user account, if a computer account is not available.

Thanks to azoxlpf, you can now perform this attack with NetExec as well🚀
June 7, 2026 at 3:57 PM
SMB share enumeration via ACLs with NetExec🔥

NetExec now detects share permissions via ACL enumeration, instead of trying to write a file. In addition, we can now detect if a user has indirect access to the share, e.g. by having ACL write permissions!

Made by @PytelJack🚀
June 4, 2026 at 3:39 PM
NetExec now has a module to remotely dump Recall data in an AD environment

github.com/Pennyw0rth/N...
June 7, 2024 at 8:04 AM
AI-driven Active Directory pentesting with Claude Desktop, HexStrike AI, and NetExec maps attack paths from LDAP and SMB enumeration to Domain Admin, highlighting weak passwords, delegation flaws, and durable persistence. #NetExec #HexStrikeAI #LAPS
AI-Powered Active Directory Pentesting with Claude, HexStrike AI & NetExec
This guide demonstrates an end-to-end Active Directory lab engagement driven by plain-English prompts to Claude Desktop through HexStrike AI and NetExec, covering reconnaissance, exploitation, post-exploitation, and defensive log review. It shows how weak passwords, roastable accounts, delegation flaws, and credential storage issues can lead from initial access to Domain Admin and durable persistence in #IGNITE.LOCAL #NetExec #HexStrikeAI #ClaudeDesktop #LAPS #DCSync
www.hendryadrian.com
June 22, 2026 at 2:45 PM
Claude Desktop connected to an MCP Kali Server to orchestrate a full lab pentest with Nmap, sqlmap, Hydra, Metasploit, John the Ripper, WPScan, and NetExec, ending in root, WordPress, and domain admin access. #ClaudeDesktop #Metasploit #WPScan
Automated Penetration Testing with Claude AI
This article describes an end-to-end lab penetration test orchestrated through Claude Desktop connected to an MCP Kali Server, where natural-language prompts drove tools like Nmap, sqlmap, Hydra, Metasploit, John the Ripper, WPScan, and NetExec. The attack chain moved from reconnaissance and exploitation to root access, WordPress compromise, and domain administrator credential recovery on a Windows Server 2019 domain controller. #ClaudeDesktop #MCPKaliServer #Metasploit #sqlmap #Hydra #JohnTheRipper #WPScan #NetExec #Samba #WordPress #WindowsServer2019
www.hendryadrian.com
June 13, 2026 at 11:45 PM
⚠️ Qilin RaaS leak exposes ops

Infighting within #Qilin #ransomware led to a rare leak of its affiliate panel credentials.

600+ victims, elite tools (Mimikatz, NetExec, XenoRAT), and tactics now exposed. A goldmine for defenders, thanks to angry affiliates & rival gangs.

#ransomNews
August 2, 2025 at 3:55 PM
𝗦𝗲𝗲𝗶𝗻𝗴 𝘀𝗼𝗺𝗲 𝘀𝗲𝗰𝗿𝗲𝘁𝘀𝗱𝘂𝗺𝗽 𝗮𝗰𝘁𝗶𝘃𝗶𝘁𝘆 𝗶𝗻 𝘁𝗵𝗲 𝘄𝗶𝗹𝗱 𝗹𝗮𝘁𝗲𝗹𝘆, 𝗮𝗻𝗱 𝗶𝘁’𝘀 𝘁𝗿𝗶𝗰𝗸𝘆 𝘁𝗼 𝗰𝗮𝘁𝗰𝗵 𝗯𝗲𝗰𝗮𝘂𝘀𝗲 𝗼𝗳 𝗮𝗹𝗹 𝘁𝗵𝗲 𝗳𝗮𝗹𝘀𝗲 𝗽𝗼𝘀𝗶𝘁𝗶𝘃𝗲𝘀.

The recent NetExec update (codename SmoothOperator) pushed me to share this one 👇
🔗 www.netexec.wiki/news/v1.4.0-...

𝗙𝗶𝗿𝘀𝘁 𝗲𝘃𝗲𝗻𝘁 (𝟰𝟲𝟳𝟮)
Special privileges assigned to new logon:
October 22, 2025 at 4:36 AM
Confirmed with NetExec 1.3.0 and Impacket 0.12.0.dev1 that the new path is indeed:

C\:\\Windows\\Temp\\[a-zA-Z0-9]{8}.tmp

Good news? Detected by Microsoft Defender by default:

And another detection: Behavior:Win32/RegDump.SA.
January 21, 2025 at 3:07 AM
If your SQL detections stop at xp_cmdshell, you have a blind spot.

Our latest blog explores how Machine Learning Services changes execution context, process chains, and opportunities for code execution via Netexec and R scripts.

Full post here:
Goodbye xp_cmdshell, Hello MLS: Weaponizing SQL Machine Learning Services for RCE with Netexec - Netragard
Learn how attackers abuse SQL Server Machine Learning Services to bypass xp_cmdshell restrictions and gain RCE using a custom Netexec module.
ntrgd.io
March 3, 2026 at 2:24 PM
This looks off to you? Yeah...

In the default configuration, NFS exposes THE ENTIRE FILE SYSTEM and not only the exported directory!
This means that you can read every file on the system that is not root:root owned, e.g. /etc/shadow.

But it can get even worse 1/4🧵
March 3, 2025 at 6:01 PM
Did anyone say Shadow Credentials?🔑

A very common alternative to RBCD is to add a certificate to a computer account. However, inspecting or removing them later on was not possible with NetExec so far. Heavily inspired by pyWhisker, I wrote a module to interact with these Shadow Credentials.
September 2, 2026 at 2:01 PM
Modifying group membership with NetExec🛠️

A classic situation: You have obtained a privileged user and want to add yourself to one of their groups, e.g. the Domain Admins. With NetExec's new modify-group module you can do that now via both SMB and LDAP. Made by termanix.
April 12, 2026 at 4:03 PM
And this is our pull request to NetExec which adds efsr_spray which can re-enable EFSR/PetitPotam on up-to-date Windows 11 hosts 🤯 if they have a writeable share:

github.com/Pennyw0rth/N...
Add efsr_spray module by rtpt-romankarwacik · Pull Request #718 · Pennyw0rth/NetExec
Description Since Windows 11 23H2 the EFS service is only activated on demand. One ways to activate it is to write an encrypted file to a share on the respective device. This module automates this ...
github.com
June 4, 2025 at 7:57 AM
VulnLab always teaches me something. TIL, it's possible to enumerate domain users and groups via MSSQL, even with just a normal MSSQL account.

Just made a PR to add rid-brute functionality to netexec
github.com/Pennyw0rth/N...
November 23, 2024 at 9:02 PM