Finally you can use all the great features NetExec has to offer even in more mature environments
Finally you can use all the great features NetExec has to offer even in more mature environments
NetExec now supports "Pass-the-Cert" as an authentication method, thanks to @dirkjanm.io original work on PKINITtools ⛱️
NetExec now supports "Pass-the-Cert" as an authentication method, thanks to @dirkjanm.io original work on PKINITtools ⛱️
If the AD Recycle Bin is enabled, objects are moved to the "Deleted Objects" container if they are "deleted". With the new "tombstone" NetExec module, you can query and restore such objects (given you have the required privs).
Made by Fabrizzio🚀
If the AD Recycle Bin is enabled, objects are moved to the "Deleted Objects" container if they are "deleted". With the new "tombstone" NetExec module, you can query and restore such objects (given you have the required privs).
Made by Fabrizzio🚀
In AD environments, the DC hashes NTP responses with the computer account NT hash. That means that you can request and brute force all computer accounts in a domain from an UNAUTHENTICATED perspective!
Implemented by Disgame
1/3🧵
In AD environments, the DC hashes NTP responses with the computer account NT hash. That means that you can request and brute force all computer accounts in a domain from an UNAUTHENTICATED perspective!
Implemented by Disgame
1/3🧵
Not that NXC needs it, but sometimes you gotta help other tools for them to work. 😂
Not that NXC needs it, but sometimes you gotta help other tools for them to work. 😂
Dump #Entra access tokens from Windows Token Broker Cache, and make your way to Entra 🚀
Thanks @xpnsec.com for the technique! More info on his blog : blog.xpnsec.com/wam-bam/
Dump #Entra access tokens from Windows Token Broker Cache, and make your way to Entra 🚀
Thanks @xpnsec.com for the technique! More info on his blog : blog.xpnsec.com/wam-bam/
There is a HUGE number of new features and improvements, including:
- backup_operator: Automatic priv esc for backup operators
- Certificate authentication
- NFS escape to root file system
And much more!
Full rundown available at:
github.com/Pennyw0rth/N...
There is a HUGE number of new features and improvements, including:
- backup_operator: Automatic priv esc for backup operators
- Certificate authentication
- NFS escape to root file system
And much more!
Full rundown available at:
github.com/Pennyw0rth/N...
While classic RBCD requires a computer account, you can use User-to-User (U2U) authentication to perform RBCD with a normal user account, if a computer account is not available.
Thanks to azoxlpf, you can now perform this attack with NetExec as well🚀
While classic RBCD requires a computer account, you can use User-to-User (U2U) authentication to perform RBCD with a normal user account, if a computer account is not available.
Thanks to azoxlpf, you can now perform this attack with NetExec as well🚀
NetExec now detects share permissions via ACL enumeration, instead of trying to write a file. In addition, we can now detect if a user has indirect access to the share, e.g. by having ACL write permissions!
Made by @PytelJack🚀
NetExec now detects share permissions via ACL enumeration, instead of trying to write a file. In addition, we can now detect if a user has indirect access to the share, e.g. by having ACL write permissions!
Made by @PytelJack🚀
github.com/Pennyw0rth/N...
github.com/Pennyw0rth/N...
Infighting within #Qilin #ransomware led to a rare leak of its affiliate panel credentials.
600+ victims, elite tools (Mimikatz, NetExec, XenoRAT), and tactics now exposed. A goldmine for defenders, thanks to angry affiliates & rival gangs.
#ransomNews
Infighting within #Qilin #ransomware led to a rare leak of its affiliate panel credentials.
600+ victims, elite tools (Mimikatz, NetExec, XenoRAT), and tactics now exposed. A goldmine for defenders, thanks to angry affiliates & rival gangs.
#ransomNews
The recent NetExec update (codename SmoothOperator) pushed me to share this one 👇
🔗 www.netexec.wiki/news/v1.4.0-...
𝗙𝗶𝗿𝘀𝘁 𝗲𝘃𝗲𝗻𝘁 (𝟰𝟲𝟳𝟮)
Special privileges assigned to new logon:
The recent NetExec update (codename SmoothOperator) pushed me to share this one 👇
🔗 www.netexec.wiki/news/v1.4.0-...
𝗙𝗶𝗿𝘀𝘁 𝗲𝘃𝗲𝗻𝘁 (𝟰𝟲𝟳𝟮)
Special privileges assigned to new logon:
C\:\\Windows\\Temp\\[a-zA-Z0-9]{8}.tmp
Good news? Detected by Microsoft Defender by default:
And another detection: Behavior:Win32/RegDump.SA.
C\:\\Windows\\Temp\\[a-zA-Z0-9]{8}.tmp
Good news? Detected by Microsoft Defender by default:
And another detection: Behavior:Win32/RegDump.SA.
Our latest blog explores how Machine Learning Services changes execution context, process chains, and opportunities for code execution via Netexec and R scripts.
Full post here:
Our latest blog explores how Machine Learning Services changes execution context, process chains, and opportunities for code execution via Netexec and R scripts.
Full post here:
In the default configuration, NFS exposes THE ENTIRE FILE SYSTEM and not only the exported directory!
This means that you can read every file on the system that is not root:root owned, e.g. /etc/shadow.
But it can get even worse 1/4🧵
In the default configuration, NFS exposes THE ENTIRE FILE SYSTEM and not only the exported directory!
This means that you can read every file on the system that is not root:root owned, e.g. /etc/shadow.
But it can get even worse 1/4🧵
A very common alternative to RBCD is to add a certificate to a computer account. However, inspecting or removing them later on was not possible with NetExec so far. Heavily inspired by pyWhisker, I wrote a module to interact with these Shadow Credentials.
A very common alternative to RBCD is to add a certificate to a computer account. However, inspecting or removing them later on was not possible with NetExec so far. Heavily inspired by pyWhisker, I wrote a module to interact with these Shadow Credentials.
A classic situation: You have obtained a privileged user and want to add yourself to one of their groups, e.g. the Domain Admins. With NetExec's new modify-group module you can do that now via both SMB and LDAP. Made by termanix.
A classic situation: You have obtained a privileged user and want to add yourself to one of their groups, e.g. the Domain Admins. With NetExec's new modify-group module you can do that now via both SMB and LDAP. Made by termanix.
github.com/Pennyw0rth/N...
github.com/Pennyw0rth/N...
Just made a PR to add rid-brute functionality to netexec
github.com/Pennyw0rth/N...
Just made a PR to add rid-brute functionality to netexec
github.com/Pennyw0rth/N...