NetExec RDP Screenshot
Capture a screenshot of the current RDP login screen / desktop without authenticating into a session. Useful for spotting locked admin sessions and gathering information about the host.
- Tool
- nxc
- Category
- Post-Exploitation / Data Collection
- Platform
- linux
- Requires
- no credentials
- Protocols
- RDP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc rdp <ip> -u <user> -p <password> --screenshot
Credential variants
The same attack using a different authentication material.
Authenticated Screenshot requires password
nxc rdp <ip> -u <user> -p <password> --screenshot --screentime 5
NLA Disabled (no creds) requires no credentials
nxc rdp <ip> --nla-screenshot
Examples
nxc rdp 10.10.10.10 --nla-screenshot
nxc rdp 10.10.10.0/24 -u admin -p 'Password123!' --screenshot
Tags
References
Related commands
- Impacket NTFS-Read (Offline NTDS Browse) Browse a raw NTFS image (e.g. a VSS shadow copy of C:\Windows\NTDS) offline as if it…
- NetExec SMB BitLocker Recovery Keys Retrieve BitLocker recovery keys stored in Active Directory
- NetExec WMI bitlocker Module Pull BitLocker recovery keys from a host over WMI. Faster than the SMB equivalent in…
- SMBClient Recursive Download Download folder recursively from SMB share