NetExec RDP Screenshot

Capture a screenshot of the current RDP login screen / desktop without authenticating into a session. Useful for spotting locked admin sessions and gathering information about the host.

Tool
nxc
Category
Post-Exploitation / Data Collection
Platform
linux
Requires
no credentials
Protocols
RDP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc rdp <ip> -u <user> -p <password> --screenshot

Credential variants

The same attack using a different authentication material.

Authenticated Screenshot requires password

nxc rdp <ip> -u <user> -p <password> --screenshot --screentime 5

NLA Disabled (no creds) requires no credentials

nxc rdp <ip> --nla-screenshot

Examples

nxc rdp 10.10.10.10 --nla-screenshot
nxc rdp 10.10.10.0/24 -u admin -p 'Password123!' --screenshot

Tags

nxc netexec rdp screenshot recon

References