CheatSheetsPentesting
NetExec CheatSheet
CheatSheet
NetExec is a powerful tool for network enumeration, spraying, and various other penetration testing tasks. This guide provides an overview of its functionalities and commands to help you get started
Table of Contents
NXC
Enumeration
Initial Enumeration
Null Authentication
Guest Authentication
List Shares
List Usernames
Local Authentication
Using Kerberos
Check for Hosts with SMB Signing Disabled
Spraying
Password Spray
SMB
All In One
Spider_plus Module
Dump a Specific File
LDAP
Enumerate Users Using LDAP
All In One
MSSQL
Authentication
Execute Commands Using xp_cmdshell
Use
-X
for PowerShell and-x
for cmd
Get a File
Secrets Dump
Dump LSA Secrets
GMSA
Group Policy Preferences
Dump LAPS Password
Dump DPAPI Credentials
Dump NTDS.dit
Asreproast
Bloodhound
Useful Modules
Webdav
Checks whether the WebClient service is running on the target
Veeam
Extracts credentials from the local Veeam SQL Database
Slinky
Creates Windows shortcuts with the icon attribute containing a UNC path to the specified SMB server in all shares with write permissions
Ntdsutil
Dump NTDS with ntdsutil
Ldap-checker
Checks whether LDAP signing and binding are required and/or enforced
Check for Vulnerabilities
Check if the DC is vulnerable to zerologon, petitpotam, or nopac
Check the MachineAccountQuota
ADCS Enumeration
For more detailed installation instructions, visit the NetExec.