NetExec enum_ca Module
Discover Active Directory Certificate Services CA hosts on the network and grab basic CA information (name, accessible templates, web enrollment endpoint). Quick triage before pivoting to certipy for the heavy lifting.
- Tool
- nxc
- Category
- Enumeration / SMB
- Platform
- linux
- Requires
- password
- Protocols
- SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc smb <target> -u '<user>' -p '<password>' -M enum_ca
Examples
nxc smb 10.10.10.0/24 -u jdoe -p 'Password123!' -M enum_ca
Tags
Related commands
- Enum4linux-ng SMB Enumeration Next generation enum4linux for SMB enumeration
- Impacket lookupsid Brute-force the RID space against SAMR / LSARPC to enumerate domain users, groups, and…
- Impacket NetView Enumerate logged-on users and sessions on remote hosts
- Impacket SAMRDump Dump user accounts and group information via SAMR protocol
- Impacket SMBClient Interactive SMB client written in pure Python. Drops you into a shell with shares, ls,…
- NetExec MS17-010 Check (EternalBlue) Detect MS17-010 (EternalBlue) vulnerable hosts via the SMBv1 transaction probe. Safe…
- NetExec Password Policy Enumerate Domain Password Policy
- NetExec SMB Enumerate AV Enumerate installed antivirus and security products on remote hosts