
How Hackers Compromise BIG Networks (with NetExec)
Source: YouTube · John Hammond · published Mar 22, 2024 · 36:43
This video demonstrates NetExec, a versatile network service exploitation tool based on CrackMapExec, showing how to use it for penetration testing across an Active Directory environment 0:46-1:08.
Key Takeaways:
• NetExec installation using pipx on Linux/Kali 2:12-2:58
• SMB enumeration to discover hosts and services 7:55-8:31
• Finding accessible shares using null session and guest access 8:57-9:57
• BloodHound integration to map Active Directory relationships 18:48-20:14
• Kerberoasting users to escalate privileges 21:13-23:50
• Gaining SQL server access to extract credentials 23:56-26:31
The demonstration concludes with achieving domain admin access through privilege escalation techniques, showcasing NetExec's power in penetration testing 31:01-35:18.
Sources:
- 0:46-1:08 Introduction to NetExec and its origins
- 2:12-2:58 NetExec installation process
- 7:55-8:31 SMB enumeration demonstration
- 8:57-9:57 Finding shares with guest access
- 18:48-20:14 BloodHound integration
- 21:13-23:50 Kerberoasting for privilege escalation
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
this video comes with a whole Lab environment that you can practice in and follow along with me it includes an entire active directory domain fully guided material and a walkthrough with interactive questions and virtual machines that you can spin up and control right from your browser we'll chat about it more as we get into the video N exac is a tool for assisting in network service exploitation it has tons of different modules for exploiting different kinds of network protocols like RPC remote procedure call SMB server message block and tons of others like ldap wmi SSH and even FTP you can find it online on GitHub and the documentation where I am right now at net exec. Wiki when net exac was first released there was a little bit of chatter on how it came to life because if you take a loo…