Skip to content
← LibraryTechnique entry
AD-NETEXECDiscovery

NetExec / CrackMapExec Sweep

Authenticated SMB/LDAP/WinRM/MSSQL sweeps across the estate — module-driven enumeration.

§ Where this technique fits

AD-NETEXEC is catalogued under the Discovery tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    GPP cpassword Recovery (MS14-025)
    AD-GPP-CPASSWORD · Credential Access
    seen 1×
  2. 02
    LLMNR/NBT-NS Poisoning and SMB Relay
    T1557.001 · Credential Access
    seen 1×