Crack Map Exec
Swiss army knife for pentesting Windows and Active Directory environments with credential spraying.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse security tools →What's next with Crack Map Exec?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Crack Map Exec?
CrackMapExec is an open-source penetration testing framework designed for network exploitation and reconnaissance. It serves as a centralized tool for security professionals to automate tasks like credential harvesting, SMB enumeration, and remote code execution during ethical hacking operations. Widely used by red teams, penetration testers, and security researchers, it streamlines the process of identifying vulnerabilities in Windows-based networks. The tool addresses the need for a unified interface to execute multiple exploitation techniques, reducing manual effort in complex pentesting scenarios. By integrating various modules, it enables users to perform tasks such as brute-forcing credentials, mapping network shares, and executing payloads across multiple targets efficiently. CrackMapExec's modular architecture allows it to leverage existing tools like CredCrack, smbexec, and smbmap, while extending their functionality through custom scripts. Its command-line interface (CLI) provides a flexible environment for scripting and automation, making it suitable for both interactive use and integration into larger security workflows. The tool's primary strength lies in its ability to consolidate disparate exploitation methods into a single platform, accelerating the discovery of exploitable weaknesses in target networks without requiring users to switch between multiple utilities.
How it works
CrackMapExec is a network exploitation framework for penetration testing, enabling users to automate tasks such as credential collection, remote code execution, and network mapping. It is designed to simplify the process of identifying and exploiting vulnerabilities in Windows-based environments by integrating multiple exploitation techniques into a single tool. The tool is primarily used by ethical hackers, red teams, and security researchers to conduct comprehensive network assessments. It addresses the challenge of manually executing various exploitation methods by providing a unified interface for tasks like SMB enumeration, Kerberos ticket extraction, and lateral movement. CrackMapExec supports SMB protocol-based attacks, including brute-forcing credentials, mapping network shares, and executing commands on remote systems. It also integrates with tools like CredCrack for credential harvesting and smbexec for remote code execution. The framework can leverage Kerberos tickets for privilege escalation and perform DNS reconnaissance to identify potential targets.
How to use it
- 1Install CrackMapExec via pip or clone the repository from its active GitHub fork. 2. Run the tool with the target IP address and specify modules for tasks like SMB enumeration or credential brute-forcing. 3. Use command chaining to execute multiple actions, such as `cme smb <target> -u <user> -p <password>` for SMB login attempts. 4. Monitor output for successful exploits or vulnerabilities, then leverage the results for further attacks. Practical tips include using the `--help` flag to explore available modules, prioritizing targets with known vulnerabilities, and combining modules for advanced reconnaissance. Always validate permissions and ensure compliance with legal frameworks when using the tool.
What it can do
- Active Directory pentest tool
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/byt3bl33d3r/CrackMapExec
- license: BSD-2-Clause — free to use
- privacy: Self-hosted — you control your data
Limitations
- Offensive tool — authorized penetration testing and lab use only; unauthorized use is illegal.
- The project is no longer actively maintained due to a hostile fork, which may limit future updates
- Requires prior knowledge of network protocols and exploitation techniques for effective use
- Depends on third-party tools like CredCrack and smbexec for certain functionalities
- May lack support for newer Windows security features like SMB3 encryption
Understanding the result
Swiss army knife for pentesting Windows and Active Directory environments with credential spraying.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (BSD-3-Clause).
- Built with
- (byt3bl33d3r/CrackMapExec)
- License
- BSD-3-Clause
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with byt3bl33d3r/CrackMapExec. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- BSD-3-Clause
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- BSD-2-Clause License
Upstream project
Frequently asked
What is CrackMapExec used for?
CrackMapExec is used for network penetration testing, enabling security professionals to automate tasks like credential harvesting, SMB enumeration, and remote code execution. It consolidates multiple exploitation techniques into a single framework, streamlining the process of identifying and exploiting vulnerabilities in Windows-based networks.
How does CrackMapExec work technically?
CrackMapExec operates by leveraging existing tools and protocols (e.g., SMB, Kerberos) to perform network reconnaissance and exploitation. It uses modules to interface with services like Active Directory, execute commands remotely, and extract credentials. The tool's modular design allows users to chain commands and automate workflows, enhancing efficiency in pentesting operations.
How do I execute a command on a remote system?
To execute a command, use the `smbexec` module with the target IP and credentials: `cme smb <target> -u <user> -p <password> -x "cmd.exe /c whoami"`. This will attempt to run the command on the remote system via SMB. Ensure the target is accessible and credentials are valid for successful execution.
How does CrackMapExec compare to alternatives like Metasploit or Empire?
CrackMapExec focuses on automation and modular exploitation, while Metasploit emphasizes payload delivery and post-exploitation modules. Empire is more tailored for PowerShell-based attacks. CrackMapExec integrates multiple tools into a single interface, making it ideal for rapid reconnaissance, whereas Metasploit and Empire offer deeper customization for specific attack vectors.
How do I troubleshoot connection issues?
Connection issues may arise from firewall blocks, incorrect credentials, or incompatible protocols. Verify network connectivity, ensure SMB is enabled on the target, and check credentials. Use the `--debug` flag for detailed error logs. If SMB is encrypted, consider using tools like `smbclient` to test connectivity before proceeding.