NetExec badsuccessor Module (dMSA Abuse)

Detect BadSuccessor dMSA-link abuse: a Server 2025 delegated Managed Service Account whose msDS-ManagedAccountPrecededByLink points at a privileged user grants the dMSA's identity inheritance to anyone with write rights over it. Module flags vulnerable accounts and suggests the chain. Added in NetExec v1.5.0 (Dec 2025).

Tool
nxc
Category
Privilege Escalation / Delegation Abuse
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc ldap <dc-ip> -u '<user>' -p '<password>' -M badsuccessor

Examples

nxc ldap dc.corp.local -u jdoe -p 'Password123!' -M badsuccessor

Tags

netexec nxc badsuccessor dmsa delegation server-2025

References