crackmapexec
Supports smb, ldap, ssh, winrm, mssql
crackmapexec PROTOCOL IP[/CIDR] [--port PORT] [-d DOMAIN] -u USER|USER.txt -p PASS|PASS.txt [-H HASH|HASH.txt]
--share SHARE
--local-auth: authenticate locally to each target
--continue-on-successCredential Gathering flags
dumps SAM:
--samdumps LSA secrets:
--lsadumps NTDS.dit:
--ntds
Enumeration
get all shares:
--sharesget sessions:
--sessionsget logged-on users:
--loggedon-usersget domain users:
--usersget domain groups:
--groups
File commands
upload:
--put-file FILE TARGET_PATH_FILEdownload:
--put-file TARGET_PATH_FILE FILE
Command Execution
method of commmand execution:
--exec-method [smbexec|atexec|mmcexec|wmiexec]specific command for cmd:
-x COMMANDspecific command for powershell:
-X COMMAND
SMB
# to get password policy
crackmapexec smb IP -u '' -p '' --pass-polLast updated
Was this helpful?