NetExec SMB with Kerberos Auth

Authenticate to SMB using a Kerberos ticket from a ccache file instead of NTLM. Required when NTLM is disabled or when impersonating via S4U / silver tickets. The target must be addressed by hostname (FQDN), not IP, and DNS must resolve correctly.

Tool
KRB5CCNAME=<ccache>
Category
Authentication / Credential Testing
Platform
linux
Requires
Kerberos ticket
Protocols
SMB, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

KRB5CCNAME=<ccache> nxc smb <hostname> -u <user> -k --use-kcache

Credential variants

The same attack using a different authentication material.

AES Key requires AES key

nxc smb <hostname> -u <user> -d <domain> --aesKey <aes_key> -k

With Shares Enum requires Kerberos ticket

KRB5CCNAME=<ccache> nxc smb <hostname> -u <user> -k --use-kcache --shares

Examples

KRB5CCNAME=administrator.ccache nxc smb dc01.corp.local -u administrator -k --use-kcache --shares
nxc smb dc01.corp.local -u administrator -d corp.local --aesKey 5f8a... -k

Tags

nxc netexec smb kerberos ccache pass-the-ticket

References