moving-laterally-with-netexec - NetExec Network Penetration Testing
NetExec tool for SMB, WinRM, LDAP, MSSQL enumeration and remote execution
Tags
Updated: 2026-06-30Capabilities
Typical Inputs
Typical Outputs
What this skill does
- enumerate SMB shares
- enumerate domain users
- enumerate password policy
- enumerate loggedon sessions
- validate credentials
- perform password spraying
- execute remote commands
- dump SAM hashes
- dump LSA secrets
- dump NTDS credentials
- collect BloodHound data
- retrieve LAPS passwords
Inputs
- target host addresses
- valid credentials
- NT hashes
- Kerberos tickets
- network access to ports
Outputs
- enumeration results
- validated credentials
- executed command output
- dumped credential files
- BloodHound data files
Requirements
- Linux host
- NetExec installation
- network reachability to target ports
- authorized testing scope
