Skip to content

Crack Map Exec

Swiss army knife for pentesting Windows and Active Directory environments with credential spraying.

Self-hostedNot yet verified
Report issue
BSD-3-Clause★ 8000Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with Crack Map Exec?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Crack Map Exec?

CrackMapExec is an open-source penetration testing framework designed for network exploitation and reconnaissance. It serves as a centralized tool for security professionals to automate tasks like credential harvesting, SMB enumeration, and remote code execution during ethical hacking operations. Widely used by red teams, penetration testers, and security researchers, it streamlines the process of identifying vulnerabilities in Windows-based networks. The tool addresses the need for a unified interface to execute multiple exploitation techniques, reducing manual effort in complex pentesting scenarios. By integrating various modules, it enables users to perform tasks such as brute-forcing credentials, mapping network shares, and executing payloads across multiple targets efficiently. CrackMapExec's modular architecture allows it to leverage existing tools like CredCrack, smbexec, and smbmap, while extending their functionality through custom scripts. Its command-line interface (CLI) provides a flexible environment for scripting and automation, making it suitable for both interactive use and integration into larger security workflows. The tool's primary strength lies in its ability to consolidate disparate exploitation methods into a single platform, accelerating the discovery of exploitable weaknesses in target networks without requiring users to switch between multiple utilities.

How it works

CrackMapExec is a network exploitation framework for penetration testing, enabling users to automate tasks such as credential collection, remote code execution, and network mapping. It is designed to simplify the process of identifying and exploiting vulnerabilities in Windows-based environments by integrating multiple exploitation techniques into a single tool. The tool is primarily used by ethical hackers, red teams, and security researchers to conduct comprehensive network assessments. It addresses the challenge of manually executing various exploitation methods by providing a unified interface for tasks like SMB enumeration, Kerberos ticket extraction, and lateral movement. CrackMapExec supports SMB protocol-based attacks, including brute-forcing credentials, mapping network shares, and executing commands on remote systems. It also integrates with tools like CredCrack for credential harvesting and smbexec for remote code execution. The framework can leverage Kerberos tickets for privilege escalation and perform DNS reconnaissance to identify potential targets.

How to use it

  1. 1Install CrackMapExec via pip or clone the repository from its active GitHub fork. 2. Run the tool with the target IP address and specify modules for tasks like SMB enumeration or credential brute-forcing. 3. Use command chaining to execute multiple actions, such as `cme smb <target> -u <user> -p <password>` for SMB login attempts. 4. Monitor output for successful exploits or vulnerabilities, then leverage the results for further attacks. Practical tips include using the `--help` flag to explore available modules, prioritizing targets with known vulnerabilities, and combining modules for advanced reconnaissance. Always validate permissions and ensure compliance with legal frameworks when using the tool.

What it can do

  • Active Directory pentest tool

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/byt3bl33d3r/CrackMapExec
  • license: BSD-2-Clause — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Offensive tool — authorized penetration testing and lab use only; unauthorized use is illegal.
  • The project is no longer actively maintained due to a hostile fork, which may limit future updates
  • Requires prior knowledge of network protocols and exploitation techniques for effective use
  • Depends on third-party tools like CredCrack and smbexec for certain functionalities
  • May lack support for newer Windows security features like SMB3 encryption

Understanding the result

Swiss army knife for pentesting Windows and Active Directory environments with credential spraying.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (BSD-3-Clause).
Built with
(byt3bl33d3r/CrackMapExec)
License
BSD-3-Clause
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with byt3bl33d3r/CrackMapExec. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
BSD-3-Clause
View source on GitHub

Open-source project

License: BSD-3-ClauseSource: this project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is CrackMapExec used for?

CrackMapExec is used for network penetration testing, enabling security professionals to automate tasks like credential harvesting, SMB enumeration, and remote code execution. It consolidates multiple exploitation techniques into a single framework, streamlining the process of identifying and exploiting vulnerabilities in Windows-based networks.

How does CrackMapExec work technically?

CrackMapExec operates by leveraging existing tools and protocols (e.g., SMB, Kerberos) to perform network reconnaissance and exploitation. It uses modules to interface with services like Active Directory, execute commands remotely, and extract credentials. The tool's modular design allows users to chain commands and automate workflows, enhancing efficiency in pentesting operations.

How do I execute a command on a remote system?

To execute a command, use the `smbexec` module with the target IP and credentials: `cme smb <target> -u <user> -p <password> -x "cmd.exe /c whoami"`. This will attempt to run the command on the remote system via SMB. Ensure the target is accessible and credentials are valid for successful execution.

How does CrackMapExec compare to alternatives like Metasploit or Empire?

CrackMapExec focuses on automation and modular exploitation, while Metasploit emphasizes payload delivery and post-exploitation modules. Empire is more tailored for PowerShell-based attacks. CrackMapExec integrates multiple tools into a single interface, making it ideal for rapid reconnaissance, whereas Metasploit and Empire offer deeper customization for specific attack vectors.

How do I troubleshoot connection issues?

Connection issues may arise from firewall blocks, incorrect credentials, or incompatible protocols. Verify network connectivity, ensure SMB is enabled on the target, and check credentials. Use the `--debug` flag for detailed error logs. If SMB is encrypted, consider using tools like `smbclient` to test connectivity before proceeding.

Spotted something wrong with Crack Map Exec, or want to maintain it? See how to help.