Skip to content

Net Exec

Network exploitation and post-exploitation tool (successor to CrackMapExec) for pentesting Active Directory networks.

Self-hostedNot yet verified
Report issue
BSD-3-Clause★ 6000Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with Net Exec?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Net Exec?

NetExec is an open-source network execution tool designed to automate the assessment of large network environments for security vulnerabilities. Originally forked from CrackMapExec in 2015, it has evolved into a community-maintained project focused on streamlining network reconnaissance, exploitation, and post-exploitation tasks. Security professionals, penetration testers, and red-hat teams use NetExec to identify weaknesses in network infrastructure, such as misconfigured services or unpatched systems. The tool addresses the challenge of manually scanning and exploiting complex networks by providing a centralized framework for executing commands across multiple targets efficiently.

How it works

NetExec (nxc) is a command-line utility that leverages network protocols to execute arbitrary code on remote systems, primarily targeting Windows Active Directory environments. It simplifies tasks like credential harvesting, privilege escalation, and lateral movement by abstracting complex interaction with network services. The tool is particularly useful for security teams conducting penetration tests or red-team simulations, as it reduces the manual effort required to assess and exploit networked systems. NetExec supports protocols like SMB, RDP, and LDAP for network discovery and exploitation. It can execute commands on remote hosts, dump credentials via tools like Mimikatz, and map network shares. Integration with Python-based modules allows for custom exploit development, while Docker and CLI interfaces enable flexible deployment.

How to use it

  1. 1Clone the repository from GitHub: `git clone https://github.com/Pennyw0rth/NetExec.git`.
  2. 2Install dependencies (Python 3.10+, Docker, or manual build tools).
  3. 3Run the tool via CLI: `python3 nxc.py -h` to view available commands.
  4. 4Execute targeted scans using options like `-t` for targets and `-m` for modules.

What it can do

  • network exploitation tool

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/Pennyw0rth/NetExec
  • license: BSD-2-Clause — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Requires deep knowledge of network protocols and Windows internals for effective use
  • Limited support for non-Windows targets compared to specialized tools like Metasploit
  • Depends on network access and may fail in environments with strict firewall rules
  • Manual configuration of Docker or build environments may deter casual users
  • Lacks built-in GUI, relying on CLI for interaction

Understanding the result

Network exploitation and post-exploitation tool (successor to CrackMapExec) for pentesting Active Directory networks.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (BSD-3-Clause).
Built with
(Pennyw0rth/NetExec)
License
BSD-3-Clause
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with Pennyw0rth/NetExec. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
BSD-3-Clause
View source on GitHub

Open-source project

License: BSD-3-ClauseSource: this project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is the primary use case for NetExec?

NetExec is primarily used for automating network reconnaissance, credential harvesting, and post-exploitation tasks in Windows environments. It enables security teams to assess vulnerabilities in Active Directory setups and execute commands across multiple targets efficiently.

How does NetExec differ from Metasploit?

NetExec focuses on network-level exploitation and automation, particularly for Windows domains, while Metasploit is a broader penetration testing framework with more extensive exploit libraries. NetExec excels in scenarios requiring rapid credential access and lateral movement, whereas Metasploit offers deeper customization for individual vulnerabilities.

How do I run a basic network scan with NetExec?

Use the `nxc` CLI tool with the `-t` flag to specify targets and `-m` to select modules. For example: `nxc -t 192.168.1.0/24 -m smb_login` will scan the subnet for SMB login vulnerabilities. Replace the IP range and module as needed for your target environment.

What are common issues when installing NetExec?

Installation issues often arise from missing Python dependencies or incompatible system libraries. Ensure Python 3.10+ is installed, and use Docker for simplified deployment. If building manually, verify all required tools (e.g., Poetry, Docker) are correctly configured.

How does NetExec handle credential storage?

NetExec stores credentials in memory during operations and does not persist them to disk by default. Users must manage credential handling manually, often using tools like Mimikatz for extraction. Always ensure secure practices to avoid exposing sensitive data.

Spotted something wrong with Net Exec, or want to maintain it? See how to help.