NetExec is a dual-use remote execution and post-exploitation utility used to execute commands or programs on remote Windows systems. The provided content describes it both as a general utility for remote command execution and as a tool frequently observed in intrusions for credential validation, lateral movement, and remote command execution. It is also referenced in detection content as being associated with Kerberos-related offensive activity, including Pass-the-Ticket, Kerberoasting, and AS-REP Roasting, with analytics focused on Windows processes exhibiting NetExec command-line parameters.
A technical appendix in the content describes a sample netexec.exe (MD5: aca94bb7bdfb735f267f083e28f4db37), compiled on 2015-09-01 07:37:04Z, self-reporting as Version 0.9. According to that description, NetExec has no persistence mechanism and supports executing remote files, uploading and executing files, opening a remote command shell, opening a remote PowerShell instance, and copying itself to a remote machine. When invoked with --cmd or --ps, it copies an embedded runsvc.exe to the target and executes it. The dropped runsvc.exe path is %WINDIR%<System32/SysWOW64>\wbem\xml\runsvc.exe, with MD5 1904cad4927541e47d453becbd934bf0. Runsvc.exe launches cmd.exe or powershell.exe interactively and communicates via randomly named pipes.
The content also places NetExec in real-world intrusion activity. CERT Intrinsec reported frequent observation of NetExec during post-exploitation in 2025 incidents affecting French organizations across sectors including banking and insurance, construction, agrifood, public sector, transportation, and media and telecommunications. In those incidents, NetExec appeared alongside Impacket tools, PsExec, and administrative share access in corporate network compromises. Separate reporting on the Osiris ransomware intrusion in Southeast Asia states that attackers used dual-use tools including Netscan, NetExec, and MeshAgent, and defenders were advised to monitor for NetExec as part of pre-encryption activity.
High-confidence indicators directly mentioned in the content include the malware/tool name netexec.exe, MD5 aca94bb7bdfb735f267f083e28f4db37, the dropped component runsvc.exe with MD5 1904cad4927541e47d453becbd934bf0, the runsvc.exe drop location under %WINDIR%<System32/SysWOW64>\wbem\xml\runsvc.exe, and command-line usage involving --cmd or --ps.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
`nxc smb 192.168.13.110 ... --lsa` and `secretsdump.py ...` are used to retrieve hashes for Administrator, krbtgt, service accounts, and machine accounts from the domain controller.
“Using NetExec they dumped LSASS and got the Administrator’s actual password.”
...Different stages of the workflow got their own prompt: network scanning, web enumeration, Active Directory enumeration, credential enumeration, exploitation, privilege escalation.
[The attackers] used NetExec for Active Directory discovery, credential spraying, and remote execution.
The command history shows the installation and execution of tools targeting Windows authentication and Active Directory, including Responder, NTLM relay-related tools, Impacket, and NetExec.
"the escalation path was human nature and password re-use" followed by `nxc smb ... -u Administrator -H ... --lsa` and `secretsdump.py ... -hashes ...`, which outputs account NTLM hashes.
“Our SYSVOL has Groups.xml with cpassword” and “Microsoft encrypted the passwords using AES, but then made the private encryption key public.”
The SoftPerfect Network Scanner (netscan.exe) was deployed to identify accessible systems on the network. Additionally, NetExec (nxc.exe) was used for network enumeration and credential validation.
“NetExec SMB scanning: nxc smb 192.168.10.0/24… Custom scanner gogo.”
The next step was to find where this user was actively logged in on the internal network. By utilising our Domain Admin rights, we queried active logon sessions on the workstation via netexec --loggedon-users module over SMB.
esxi_finder.py identifie les hyperviseurs ESXi et serveurs vCenter en scannant les ports 443 et 902, en lisant les certificats TLS et en interrogeant /sdk, /ui/ et /.
Énumération du domaine AD (droits utilisateur) via le collecteur BloodHound de NetExec.
La liste des TTPs attribués à Aurora inclut « T1069.002 — Permission Groups Discovery: Domain Groups ».
They then used NetExec and Impacket to attempt authentication to services such as SMB, LDAP, RDP, and WinRM, seeking access to multiple hosts and attempting lateral movement.
“NetExec with forced share creation via PowerShell… net share … /grant:everyone,FULL.”
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-exploitation framework used for credential validation, lateral movement, and remote command execution in compromised environments.
Post-exploitation/lateral movement tooling referenced as part of the campaign toolset to identify and move through the environment before encryption.
Dual-use post-exploitation tool used for network operations (commonly discovery/execution/lateral movement) in the intrusion chain.
NetExec is referenced as a tool associated with command-line activity related to Kerberos abuse techniques such as Pass the Ticket, Kerberoasting, and AS-REP Roasting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.