Ross ROSS = Recommend OSS · open-source software intelligence for agents

Pennyw0rth/NetExec

The Network Execution Tool observed · 2026-08-28

github.com/Pennyw0rth/NetExec · homepage · Python · BSD-2-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

74/100

  • Activity 99
  • Release rhythm 40
  • Longevity 77
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 181
  • age_days: 1090
  • days_rel: 191
  • days_push: 7
  • n_releases_24m: 4

Full methodology

Adoption not part of the score

5815 stars · 752 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

NetExec (nxc) is a community-maintained, open-source network execution tool and successor to CrackMapExec, used for pentesting and red-team operations against Windows and Active Directory environments. It supports multiple protocols (SMB, LDAP, WinRM, MSSQL, SSH, FTP, RDP, WMI, NFS) for enumeration, authentication attacks like password spraying, command execution, and credential gathering.

Use cases

  • password spray an active directory domain
  • enumerate smb shares on a network
  • dump ntds credentials from a domain controller
  • kerberoast and asreproast domain users
  • execute commands remotely via winrm or wmi
  • find active directory misconfigurations like delegation attacks
  • enumerate ldap users and groups during a pentest
  • check hosts for vulnerabilities across a subnet

When to choose

  • you need a modern, actively maintained replacement for CrackMapExec
  • you are performing red-team or pentest work against Windows/AD environments
  • you want one tool covering many protocols (SMB, LDAP, WinRM, MSSQL, SSH, RDP) for enumeration and post-exploitation
  • you need community-driven updates, modules, and BloodHound integration

When to avoid

  • you need a GUI-driven vulnerability scanner rather than a command-line tool
  • your target is non-Windows infrastructure outside the supported protocols
  • you require a fully documented stable API for building integrations (wiki is still in development)
  • you are looking for a defensive-only auditing tool without offensive capabilities

Facets

cli-tool · maturity active

security penetration-testing cli networking auth security penetration-testing networking developer-tools windows python cli cross-platform red-team active-directory crackmapexec-successor smb ldap winrm password-spraying kerberos post-exploitation pentesting command-line linux macos docker

10 sources

Member repositories

RepositoryRoleHealth v2
Pennyw0rth/NetExecmain74

For agents

markdown · JSON · MCP: product_card(name="Pennyw0rth/NetExec")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem