Tool
NetExec
- First Reported
- Dec 17, 2025
- Latest Reported
- Oct 1, 2026
Reported Context (3)
- Later that evening Computer 2 ran NetExec (nxc.exe), the open-source, actively maintained successor to the CrackMapExec penetration testing framework. It was used for Active Directory enumeration, credential spraying, Warlock Ransomware Group Hits Water and Telecom Operators, Continues Exploiting SharePoint
- Over the following days, they expanded access through RDP, SMB, WinRM, NetExec (nxc), Mimikatz, and LSASS/NTDS dumping activity while resetting privileged account passwords and conducting broad Active Directory EtherRAT and TukTuk C2 Lead to The Gentlemen Ransomware Deployment
- They resumed reconnaissance by running netscan, then downloaded NetExec through a web browser and conducted a password spray attack over port 445. Lynx Ransomware Attack Began with Compromised RDP Credentials
CVE (6)
Malware (5)
People (6)
Threat Actors (5)
MITRE ATT&CK (42)
Vendors (10)
Products (16)
Tools (5)
Industries (4)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.