NetExec SMB Enum Impersonate
Enumerate tokens and privileges available for impersonation on remote hosts
- Tool
- nxc
- Category
- Privilege Escalation / Local PrivEsc
- Platform
- linux
- Requires
- password
- Protocols
- SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc smb '<ip>' -u '<user>' -p '<password>' -M enum_impersonate
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
nxc smb '<ip>' -u '<user>' -H '<hash>' -M enum_impersonate
Examples
nxc smb '192.168.1.100' -u 'user' -p 'password' -M enum_impersonate
Tags
Related commands
- NetExec SMB MS17-010 (EternalBlue) Check for MS17-010 (EternalBlue) vulnerability without credentials
- NetExec SMB PrintNightmare Exploit PrintNightmare (CVE-2021-1675/34527) to load a malicious DLL via the Print…
- NetExec SMB SMBGhost Check for SMBGhost (CVE-2020-0796) SMBv3 compression vulnerability without credentials