NetExec SMB with Kerberos Auth
Authenticate to SMB using a Kerberos ticket from a ccache file instead of NTLM. Required when NTLM is disabled or when impersonating via S4U / silver tickets. The target must be addressed by hostname (FQDN), not IP, and DNS must resolve correctly.
- Tool
- KRB5CCNAME=<ccache>
- Category
- Authentication / Credential Testing
- Platform
- linux
- Requires
- Kerberos ticket
- Protocols
- SMB, KERBEROS
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
KRB5CCNAME=<ccache> nxc smb <hostname> -u <user> -k --use-kcache
Credential variants
The same attack using a different authentication material.
AES Key requires AES key
nxc smb <hostname> -u <user> -d <domain> --aesKey <aes_key> -k
With Shares Enum requires Kerberos ticket
KRB5CCNAME=<ccache> nxc smb <hostname> -u <user> -k --use-kcache --shares
Examples
KRB5CCNAME=administrator.ccache nxc smb dc01.corp.local -u administrator -k --use-kcache --shares
nxc smb dc01.corp.local -u administrator -d corp.local --aesKey 5f8a... -k
Tags
References
Related commands
- NetExec FTP Auth & Listing Validate FTP credentials and check anonymous access. Combine with --ls to list the root…
- NetExec RDP Auth Check Validate credentials against the RDP service (TCP/3389) without opening a graphical…
- NetExec SMB Auth Test Test SMB authentication with various credential types
- NetExec SSH Auth & Spray Validate credentials against SSH. Supports password, key file, and spraying across…
- NetExec WinRM Auth Check Validate credentials against the WinRM (PowerShell Remoting) service. A successful login…