NetExec RDP NLA Screenshot
Capture a pre-auth RDP login screen against hosts that have NLA enabled. Reveals OS branding, last logged-on user, and any logon banners — useful recon without burning credentials.
- Tool
- nxc
- Category
- Enumeration / Network Discovery
- Platform
- linux
- Requires
- no credentials
- Protocols
- RDP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc rdp <target> --nla-screenshot
Credential variants
The same attack using a different authentication material.
Custom Resolution requires no credentials
nxc rdp <target> --nla-screenshot --res 1920x1080
Custom Port requires no credentials
nxc rdp <target> --port 3390 --nla-screenshot
Examples
nxc rdp 10.10.10.0/24 --nla-screenshot
Tags
Related commands
- Impacket DumpNTLMInfo Dump NTLM server information (OS version, domain, hostname) without credentials
- Impacket RDP Check Check if credentials are valid for RDP access
- Impacket RPCDump Enumerate RPC endpoints and interfaces registered on a remote host
- Nmap TCP Scan Comprehensive TCP port scan with service version detection and default scripts