Sign in

Alex Neff

@al3x-n3ff.bsky.social
122 followers 51 following 39 posts

Pentester | Maintainer of NetExec | aneff.io

PostsRepliesMedia
Alex Neff @al3x-n3ff.bsky.social · 25/09/2026
The AD Grave: Tombstoned objects🪦 If the AD Recycle Bin is enabled, objects are moved to the "Deleted Objects" container if they are "deleted". With the new "tombstone" NetExec module, you can query and restore such objects (given you have the required privs). Made by Fabrizzio🚀
List, delete and restore AD objects using the tombstone NetExec module.
111
Reposted by Alex Neff
Dirk-jan @dirkjanm.io · 14/09/2026
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/ask...
github.com
GitHub - dirkjanm/askWAM: Ask the Web Account Manager (WAM) for Entra ID tokens
Ask the Web Account Manager (WAM) for Entra ID tokens - dirkjanm/askWAM
1103
Alex Neff @al3x-n3ff.bsky.social · 14/09/2026
ItsNotAlwaysSMB: DPAPI in other protocols🔥 SMB is monitored closely nowadays, stopping attacks like looting DPAPI secrets. Thanks to zblurx, NetExec got a huge upgrade, extending DPAPI credential dumping to other protocols such as WMI, WinRM and MSSQL alongside with many other similar modules🔑
Dumping DPAPI secrets via WinRM, MSSQL and WMIDump various credentials using DPLoot
011
Alex Neff @al3x-n3ff.bsky.social · 06/09/2026
Are you (like me) constantly running into your own Responder? The days are finally over!🚀 Deft and I finally finished up a PR by bdrogja that let's you define exclusions such as "yourself". You can also exclude entire ranges or IPv6 addresses (if anyone uses those lol).
Exclude yourself or IP (ranges) when using NetExec
000
Alex Neff @al3x-n3ff.bsky.social · 02/09/2026
Did anyone say Shadow Credentials?🔑 A very common alternative to RBCD is to add a certificate to a computer account. However, inspecting or removing them later on was not possible with NetExec so far. Heavily inspired by pyWhisker, I wrote a module to interact with these Shadow Credentials.
Manipulating Shadow Credentials using NetExec
020
Alex Neff @al3x-n3ff.bsky.social · 02/08/2026
A new module just got merged into NetExec: rclone🔥 Rclone is a popular tool for connecting and synchronizing data to cloud services. Credentials stored with Rclone are often enough not encrypted. Thanks to crosscutsaw we can now dump these creds with NetExec🚀
Dumping credentials stored with Rclone using NetExec
000
Alex Neff @al3x-n3ff.bsky.social · 26/07/2026
Detect the Certighost with NetExec🔥 Thanks to Xed_sama, the enum_cve module of NetExec will now detect if a host has not been patched and is potentially vulnerable to the Certighost vulnerability (CVE-2026-54121)🚀
Detect the Certighost vulnerability (CVE-2026-54121) with the enum_cve module of NetExec.
000
Alex Neff @al3x-n3ff.bsky.social · 23/06/2026
Onelogon: Taking over Active Directory Accounts via Netlogon🔑 We analyzed Netlogon, bypassed the Zerologon patch, resulting in a full auth bypass. An attacker can leverage this to compromise computer accounts, or even the entire AD. Non-standard config must be present tho 🧵
Compromise an Active Directory Domain with the Onelogon vulnerabilityScanning an AD domain for accounts vulnerable to Onelogon
110
Alex Neff @al3x-n3ff.bsky.social · 07/06/2026
SPN-less RBCD with NetExec🔥 While classic RBCD requires a computer account, you can use User-to-User (U2U) authentication to perform RBCD with a normal user account, if a computer account is not available. Thanks to azoxlpf, you can now perform this attack with NetExec as well🚀
SPN-less RBCD with NetExec
120
Alex Neff @al3x-n3ff.bsky.social · 04/06/2026
SMB share enumeration via ACLs with NetExec🔥 NetExec now detects share permissions via ACL enumeration, instead of trying to write a file. In addition, we can now detect if a user has indirect access to the share, e.g. by having ACL write permissions! Made by @PytelJack🚀
Enumerate SMB shares via ACLs with NetExec
020
Alex Neff @al3x-n3ff.bsky.social · 25/05/2026
Small QOL update for NetExec: Ctrl+C will now immediately exit NetExec without any weird stack traces🚀 However, keep in mind that this still does not exit gracefully, but immediately kills all existing threads. Only do so if necessary. Made by T1erno
Better Ctrl+C handling in NetExec
000
Alex Neff @al3x-n3ff.bsky.social · 26/04/2026
Targeted Keberoasting with NetExec🔥 If you have Write privileges over a user, you can temporarily add an SPN to your target user, request the service ticket, and then remove the SPN. Voilà: a crackable hash without interfering with potentially critical users. Made by azoxlpf🚀
Targeted Kerberoasting with NetExec
000
Alex Neff @al3x-n3ff.bsky.social · 25/04/2026
@cookietheft.ioc.exchange.ap.brid.gy and I have been accepted to speak at Troopers this year🎉 Hope you all are eager to learn a thing or two about ADCS and ESC17. See you there!
000
Alex Neff @al3x-n3ff.bsky.social · 12/04/2026
Modifying group membership with NetExec🛠️ A classic situation: You have obtained a privileged user and want to add yourself to one of their groups, e.g. the Domain Admins. With NetExec's new modify-group module you can do that now via both SMB and LDAP. Made by termanix.
Modify group memberships with the new modify-group NetExec module.
020
Alex Neff @al3x-n3ff.bsky.social · 29/03/2026
A new module just got merged into NetExec: get-scriptpath📜 This module queries all users for the scriptpath attribute. If you have write privileges over one of these scripts (or they e.g. try to mount a network share) you can easily compromise these users on their next login. Made by 0xwyndo.
Enumerate the scriptpath attribute of users using the new NetExec module and compromise this user in certain scenarios. E.g. if the login script tries to mount a non existent network share we can easily capture that connection attempt with responder.
000
Alex Neff @al3x-n3ff.bsky.social · 25/03/2026
Crawling MSSQL databases with NetExec: mssql_dumper💾 The new mssql_dumper module, created by LTJAXSON, enables you to crawl MSSQL databases for a predefined set of keywords, including classic credential phrases, or to search using your own regular expression/keyword list.
Crawl MSSQL databases for credentials and personal identifiable information (PII) with the new NetExec module "mssql_dumper".
000
Alex Neff @al3x-n3ff.bsky.social · 22/03/2026
New NetExec module: mssql_cbt🔥 Relaying to MSSQL can be a hidden gem when you are out of (relaying) options. The only protection against relaying to MSSQL is to enforce Channel Binding Tokens (CBT). Thanks to Defte, NetExec now has a module that checks whether this CBT is required.
Relaying to MSSQL when Channel Binding Tokens (CBT) are not required, which you can check with the new NetExec module "mssql_cbt".
000
Reposted by Alex Neff
0xdf @0xdf.bsky.social · 11/02/2026
Netexec has some really nice NFS capabilities. I found a some weird behavior in one of them, which turned out to be a bug that just got patched. Let's walk through it.
youtube.com
Finding and Fixing a Bug in Netexec NFS
Netexec has some awesome NFS capabilities. While playing Slonik from VulnLab / HackTheBox, I found an issue I couldn't understand. I'll walk through how Nete...
011
Alex Neff @al3x-n3ff.bsky.social · 19/03/2026
Collecting ADCS data with NetExec🔥 Thanks to the addition of CertiHound, developed and implemented by 0x0Trace, we can now collect ADCS data using the --bloodhound collector of NetExec. As before, the data is exported as JSON files that can be imported directly into BloodHound for further analysis.
Collecting ADCS data for BloodHound using the new CertiHound collector in NetExec.
001
Alex Neff @al3x-n3ff.bsky.social · 17/03/2026
Releasing one of my research tools: EVENmonitor🖥️ Inspired by LDAPmonitor, I implemented a monitoring tool for the Windows Event log in pure python. You can just attach it via the network and then filter for specific event IDs or keywords. Available at: github.com/NeffIsBack/E...
002
Alex Neff @al3x-n3ff.bsky.social · 04/01/2026
Using ADCS to Attack HTTPS-Enabled WSUS Clients: @cookietheft.ioc.exchange.ap.brid.gy and I have extended the research by @Coontzy1 on WSUS attacks and explored how to leverage misconfigured ADCS templates to gain code execution on HTTPS-enabled WSUS clients. 1/2🧵
So WSUS with HTTPS is secure u said?
110
Reposted by Alex Neff
Lisa Forte @lisaforte.bsky.social · 24/05/2025
Yep. Pretty much 😂
520818
Alex Neff @al3x-n3ff.bsky.social · 14/04/2025
NetExec v1.4.0 has been released! 🎉 There is a HUGE number of new features and improvements, including: - backup_operator: Automatic priv esc for backup operators - Certificate authentication - NFS escape to root file system And much more! Full rundown available at: github.com/Pennyw0rth/N...
NetExec release v1.4.0
040
Reposted by Alex Neff
SpecterOps @specterops.io · 07/03/2025
Happy #BloodHoundBasics day to all who celebrate! Easily RETURN computers, users, and certificate templates created in the last X days where X can match anything you want. In this case we are looking for objects created in the last 365 days. 🧵: 1/3
153
Alex Neff @al3x-n3ff.bsky.social · 03/03/2025
This looks off to you? Yeah... In the default configuration, NFS exposes THE ENTIRE FILE SYSTEM and not only the exported directory! This means that you can read every file on the system that is not root:root owned, e.g. /etc/shadow. But it can get even worse 1/4🧵
NFS escape to the root directory with NetExecNFS downloading the /etc/shadow file from a system with default NFS configs
184
Alex Neff @al3x-n3ff.bsky.social · 27/02/2025
Finally, two new options by @Defte_ got merged into NetExec🔥 --qwinsta: Enumerate active sessions on the target, including numerous useful information --tasklist: Well... enumerates all running tasks on the host Update & enjoy the new reconnaissance flags🔎
Enumerate active sessions and tasks running on the target
000
Reposted by Alex Neff
mpgn @mpgn.bsky.social · 20/01/2025
Generate a valid krb5 conf file directly from netexec 🔥 Not that NXC needs it, but sometimes you gotta help other tools for them to work. 😂
0154
Reposted by Alex Neff
mpgn @mpgn.bsky.social · 13/01/2025
DCsync a domain when you find a user in the Backup Operators group using netexec, very simple and no need for a custom smb server 😛🏆
071
Reposted by Alex Neff
Dirk-jan @dirkjanm.io · 02/01/2025
Few BloodHound python updates: LDAP channel binding is now supported with Kerberos auth (native) or with NTLM (custom ldap3 version). Furthermore, the BH CE collector now has its own pypi package and command. You can have both on the same system with pipx. github.com/dirkjanm/Blo...
github.com
GitHub - dirkjanm/BloodHound.py: A Python based ingestor for BloodHound
A Python based ingestor for BloodHound. Contribute to dirkjanm/BloodHound.py development by creating an account on GitHub.
22914
Reposted by Alex Neff
mpgn @mpgn.bsky.social · 06/01/2025
So you want to exploit ADCS ESC8 with only netexec and ntlmrelayx ? Fear not my friend, I will show you how to do it 👇 NetExec now supports "Pass-the-Cert" as an authentication method, thanks to @dirkjanm.io original work on PKINITtools ⛱️
0147
Reposted by Alex Neff
Mänu @emanuelduss.ch · 01/01/2025
Crazy and mind blown 🤯 If you have read access to an NFS share, you can basically read all files from the same filesystem. - Research: www.hvs-consulting.de/en/nfs-secur... - Tooling: github.com/hvs-consulti... - 38c3 CTF Writeup: hxp.io/blog/111/hxp... #pentest #nfs
hvs-consulting.de
NFS Security: Identifying and Exploiting Misconfigurations
Understand security features, misconfigurations and technical attacks on NFS shares. Explore tools to analyze NFS endpoints and abuse misconfigurations.
011
Reposted by Alex Neff
Andrea P @decoder-it.bsky.social · 25/11/2024
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/K...
36343
Reposted by Alex Neff
mpgn @mpgn.bsky.social · 17/12/2024
Two new modules for MSSQL on NXC, thanks to the contributions of @lodos2005.bsky.social and @adamkadaban.bsky.social 🔥 - rid-brute from mssql - mssql_coerce from mssql github.com/Pennyw0rth/N...
0157
Reposted by Alex Neff
Justin Elze @handle.invalid · 04/12/2024
The @trustedsec.com BoF dev class is up learn.trustedsec.com/catalog
1187
Alex Neff @al3x-n3ff.bsky.social · 01/12/2024
NetExec has a new Module: Timeroast🔥 In AD environments, the DC hashes NTP responses with the computer account NT hash. That means that you can request and brute force all computer accounts in a domain from an UNAUTHENTICATED perspective! Implemented by Disgame 1/3🧵
Timeroast with NetExec
1135
Alex Neff @al3x-n3ff.bsky.social · 26/11/2024
Small technical update: Impacket and therefore NetExec now support LDAP Channel Binding🔥 Finally you can use all the great features NetExec has to offer even in more mature environments
0147
Reposted by Alex Neff
Dirk-jan @dirkjanm.io · 20/11/2024
Awesome new addition to krbrelayx by Hugow from Synacktiv: www.synacktiv.com/publications...
synacktiv.com
Relaying Kerberos over SMB using krbrelayx
02914
Reposted by Alex Neff
Justin Elze @handle.invalid · 19/11/2024
TrustedSec Tech Brief 00:30 - NTLM Hash Disclosure Zero-Day 01:45 - Task Scheduler Vulnerability 02:30 - Exchange Server Issues 03:15 - AD Certificate Services Flaw 04:00 - Vulnerability Breakdown 04:45 - Palo Alto Zero-Day 05:30 - FortiGate VPN Update www.youtube.com/watch?v=3mSD...
youtube.com
TrustedSec Tech Brief - November 2024
YouTube video by TrustedSec
36021
Reposted by Alex Neff
mpgn @mpgn.bsky.social · 15/11/2024
If you want to first blood a windows box in @hackthebox.bsky.social every minute counts ! 🩸 I've added a special flag --generate-hosts-file so you just have to copy past into your /etc/hosts file and be ready to pwn as soon as possible 🔥
031
Alex Neff @al3x-n3ff.bsky.social · 19/11/2024
Hello world :)
120