wrapper for netexec
A very small, very simple NetExec (nxc) wrapper to spray one username + password
across multiple protocols and targets without having to type the same command 20 times.
Any one is welcome to improve it 🙂
• Spray a single username + password across:
• SMB
• LDAP
• WinRM
• RDP
• SSH
• MSSQL
• FTP
• VNC
• WMI
• Supports:
• Single target
• Target list file
• Username file
• Validation mode (--validate)
• Confirms real access (not just auth)
• Smart output:
• [ACCESS] → confirmed execution / real access
• [VALID] → authentication only
• Detects:
• Pwn3d! from NetExec automatically
• Logging:
• Saves full output to timestamped log file
Requirements • Python 3 • netexec (nxc) installed and in PATH
Optional (for validation) • xfreerdp3 → RDP validation • impacket → MSSQL validation
Installation
git clone https://github.com/I-AlanF90/netexecspray.git
cd netexecspray
chmod +x netexecspray.pysudo ln -s /opt/netexecspray/netexecspray.py /usr/local/bin/netexecspray
python3 netexecspray.py smb 192.168.1.10 -u Alan -p 'Sup3rS3cretPass!'netexecspray smb,ldap,winrm,rdp,wmi 192.168.1.10 -u Alan -p 'Password123'netexecspray all targets.txt -U users.txt -p 'Winter2024!'netexecspray smb,ldap,winrm,rdp,wmi 192.168.1.10 -u Alan -p 'Password123' --validatenetexecspray all targets.txt -U users.txt -p 'Password123' --validate --only-access• [ACCESS] = you can likely execute commands / move laterally
• [VALID] = creds are good, but access is restricted
• LDAP → use for BloodHound
• RDP → may be blocked by policy
• WMI → may lack execution rights