NetExec RDP Auth Check
Validate credentials against the RDP service (TCP/3389) without opening a graphical session. Useful for spraying and quick triage.
- Tool
- nxc
- Category
- Authentication / Credential Testing
- Platform
- linux
- Requires
- password
- Protocols
- RDP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc rdp <ip> -u <user> -p <password>
Credential variants
The same attack using a different authentication material.
NTLM Hash (Restricted Admin) requires NTLM hash
nxc rdp <ip> -u <user> -H <hash>
Spray Across Subnet requires password
nxc rdp <subnet> -u <user> -p <password> --continue-on-success
Examples
nxc rdp 10.10.10.10 -u administrator -p 'Password123!'
nxc rdp 10.10.10.0/24 -u admin -H :e19ccf75ee54e06b06a5907af13cef42 --continue-on-success
Tags
References
Related commands
- NetExec FTP Auth & Listing Validate FTP credentials and check anonymous access. Combine with --ls to list the root…
- NetExec SMB Auth Test Test SMB authentication with various credential types
- NetExec SMB with Kerberos Auth Authenticate to SMB using a Kerberos ticket from a ccache file instead of NTLM. Required…
- NetExec SSH Auth & Spray Validate credentials against SSH. Supports password, key file, and spraying across…
- NetExec WinRM Auth Check Validate credentials against the WinRM (PowerShell Remoting) service. A successful login…