NetExec, formerly CrackMapExec, is a dual-use network assessment and post-exploitation framework used by security practitioners and threat actors. It is not inherently malware. It supports Active Directory enumeration, credential validation, password spraying, SMB access, credential dumping, and remote command execution, enabling operators to discover accounts and systems and move laterally through Windows enterprise networks. Its Kerberos functionality includes Pass-the-Ticket, Kerberoasting, and AS-REP Roasting. Additional capabilities include MSSQL enumeration and BloodHound integration.
NetExec is used during post-compromise activity in ransomware intrusions. Storm-2570 has used it for remote execution and lateral movement in operations involving multiple ransomware families, including Qilin, DragonForce, Anubis, and BERT. It has also appeared among the dual-use tools deployed in Osiris ransomware intrusions. These operational associations do not make NetExec specific to any threat actor or industry, and its presence alone does not establish malicious activity or attribution.
A separate historical remote-execution utility also uses the NetExec name; its implementation details should not be conflated with those of the modern framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The affiliate uploaded a Russian-language NetExec cheat-sheet repository on May 7, 2025.
Microsoft observed disabled real-time protection, antivirus exclusions and registry changes, followed by remote execution through PsExec, Impacket, NetExec or remote desktop scripts.
« Utilisation de NetExec (nxc.exe) pour énumération AD et mouvement latéral. »
« Utilisation de NetExec (nxc.exe) pour énumération AD et mouvement latéral. »
30 distinct techniques documented for this family, organized by ATT&CK tactic.
`nxc smb 192.168.13.110 ... --lsa` and `secretsdump.py ...` are used to retrieve hashes for Administrator, krbtgt, service accounts, and machine accounts from the domain controller.
“Using NetExec they dumped LSASS and got the Administrator’s actual password.”
...Different stages of the workflow got their own prompt: network scanning, web enumeration, Active Directory enumeration, credential enumeration, exploitation, privilege escalation.
[The attackers] used NetExec for Active Directory discovery, credential spraying, and remote execution.
The command history shows the installation and execution of tools targeting Windows authentication and Active Directory, including Responder, NTLM relay-related tools, Impacket, and NetExec.
"the escalation path was human nature and password re-use" followed by `nxc smb ... -u Administrator -H ... --lsa` and `secretsdump.py ... -hashes ...`, which outputs account NTLM hashes.
“Our SYSVOL has Groups.xml with cpassword” and “Microsoft encrypted the passwords using AES, but then made the private encryption key public.”
The SoftPerfect Network Scanner (netscan.exe) was deployed to identify accessible systems on the network. Additionally, NetExec (nxc.exe) was used for network enumeration and credential validation.
“NetExec SMB scanning: nxc smb 192.168.10.0/24… Custom scanner gogo.”
The next step was to find where this user was actively logged in on the internal network. By utilising our Domain Admin rights, we queried active logon sessions on the workstation via netexec --loggedon-users module over SMB.
esxi_finder.py identifie les hyperviseurs ESXi et serveurs vCenter en scannant les ports 443 et 902, en lisant les certificats TLS et en interrogeant /sdk, /ui/ et /.
Énumération du domaine AD (droits utilisateur) via le collecteur BloodHound de NetExec.
La liste des TTPs attribués à Aurora inclut « T1069.002 — Permission Groups Discovery: Domain Groups ».
« Reconnaissance (net user /domain, whoami) » ; « NetExec (nxc.exe) pour énumération AD ».
They then used NetExec and Impacket to attempt authentication to services such as SMB, LDAP, RDP, and WinRM, seeking access to multiple hosts and attempting lateral movement.
« utilisation de NetExec (nxc.exe) pour énumération AD et mouvement latéral » ; « T1021.002 — Remote Services: SMB/Windows Admin Shares ».
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offensive framework used by Longlegs during the documented intrusion for Active Directory enumeration, credential spraying, and lateral movement ahead of Warlock ransomware deployment.
Dual-use offensive security tooling used by Storm-2570 for remote execution and lateral movement after weakening security controls.
Post-exploitation framework used for credential validation, lateral movement, and remote command execution in compromised environments.
Post-exploitation/lateral movement tooling referenced as part of the campaign toolset to identify and move through the environment before encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.