
NetExec
Open-source network execution tool (nxc), successor to CrackMapExec, for assessing Windows and Active Directory services in authorised engagements.
0 upvotes · 0 downvotes
- Category
- Offensive Security & Pentesting
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 1 October 2026
**What it is**
NetExec (command `nxc`) is an open-source network service assessment tool maintained by the Pennyw0rth project. It is the actively maintained successor to CrackMapExec. Testers use it to authenticate against common protocols at scale, run built-in and community modules, and automate post-authentication checks during authorised penetration tests, especially against Windows and Active Directory environments.
**What it helps with**
- Scanning and authenticating across hosts with protocols such as SMB, LDAP, WinRM, WMI, RDP, MSSQL, SSH, FTP, VNC and NFS.
- Validating credentials, hashes or tickets against many targets in a controlled engagement.
- Running modules for enumeration, credential-related checks and authorised remote execution helpers.
- Speeding up Active Directory and Windows network assessment workflows that previously used CrackMapExec.
- Using `nxcdb` and related helpers documented in the NetExec wiki for engagement data handling.
- Installing via pipx from GitHub or using distribution packages and release binaries where available.
**Who it's for**
Penetration testers and red teams assessing Windows, Active Directory and mixed network services under a clear written scope.
**Worth knowing**
Use NetExec only on systems and networks you are explicitly authorised to test. Many modules perform authentication and remote actions that are inappropriate without permission. NetExec replaced CrackMapExec after the earlier project’s maintenance ended; prefer the Pennyw0rth repository and netexec.wiki docs for current guidance. Licence is BSD 2-Clause. Attribution: framing from netexec.wiki and the Pennyw0rth/NetExec README; licence from the repository LICENSE file.