NOTES
NetExec is most useful as a consistent interface across Windows-facing protocols. I use it after host discovery to validate protocol reachability, identify domain context, test approved credentials, and collect narrow facts that guide manual follow-up.
Successful authentication is not the same as administrative execution. I record the protocol, identity format, target, signing or security posture, and the exact privilege the result actually proves.
WORKFLOW
- Start from a resolved, in-scope host list rather than a broad subnet guess.
- Run non-authenticated discovery before sending credentials.
- Validate one known-good account against a small target sample before expanding.
- Prefer modules and queries that answer a specific question.
- Save machine-readable output and deduplicate hosts, identities, and errors before reporting.
COMMANDS
nxc smb targets.txt
nxc smb targets.txt -u USER -p PASSWORD --continue-on-success
nxc ldap DC01 -u USER -p PASSWORD --users
nxc winrm targets.txt -u USER -p PASSWORD
GOTCHAS
- Quote passwords so the shell does not interpret special characters.
- Use the correct domain, local-account, or UPN form intentionally.
- Rate-limit sprays and document the approved lockout threshold.
- Distinguish signing not required from relay being immediately practical.
- Treat module output as evidence to validate, not a finished finding.