# NetExec (nxc): what the CrackMapExec successor does and how to install it

> NetExec is the community-maintained continuation of CrackMapExec, a Python 3.10+ command-line tool for authenticated enumeration and execution across SMB, LDAP, MSSQL, FTP and other network protocols. It is built for authorized penetration tests and red team engagements, and its README sends you to the project wiki for installation and usage.

**Pennyw0rth/NetExec** — The Network Execution Tool

- Repository: https://github.com/Pennyw0rth/NetExec
- Website: https://netexec.wiki/
- Stars: 5,891 · Forks: 775
- Language: Python
- License: BSD-2-Clause
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/pennyw0rth-netexec

## What NetExec replaces, and who it is for

NetExec is the renamed continuation of CrackMapExec. The README states that the project was created in 2015 by @byt3bl33d3r, maintained from 2019 by @mpgn_x64 for four years, and that after that maintainer retired in September 2023 the remaining active contributors took it over under the NetExec name. The stated reason for the split is concrete: during the later CrackMapExec period there were both a private and a public repository, community contributions were not easily merged, and the README describes a 6-8 month discrepancy between the two code bases that reduced community-driven development.

So the audience is narrow and technical. This is a tool for people who already hold credentials for a Windows or Active Directory environment and want to enumerate it, query it, and in some cases execute commands against it, from a Linux command line. The repository topics list active-directory, pentest, red-team and security-tools. If you do not have authorization over the target network, the tool has no use case for you; everything it does assumes a valid credential or a deliberate authentication attempt as part of an agreed test.

## How nxc is structured: protocols as subcommands, features as modules

The entry point is the nxc command, and pyproject.toml maps several script names to the same function: nxc = "nxc.netexec:main", plus netexec and NetExec pointing at the same target. A separate nxcdb = "nxc.nxcdb:main" script exists, which suggests a database-facing command alongside the main one.

The dependency list in pyproject.toml is the clearest description of the architecture you can get without running anything. It includes impacket, minikerberos, asyauth, aardwolf and pypsrp for Windows authentication and remote protocol work; ldap-related and Kerberos-adjacent libraries such as pyasn1-modules and dsinternals; lsassy, dploot, masky and pypykatz for credential and secrets parsing; bloodhound-ce, certihound and neo4j for graph-oriented collection; and sqlalchemy for storage. Three dependencies are pulled directly from git rather than PyPI: certipy-ad from Pennyw0rth/Certipy, impacket from fortra/impacket, and pynfsclient from Pennyw0rth/NfsClient.

That git-dependency pattern is the single most important structural fact for anyone planning to deploy this. Installing NetExec means cloning and building three external repositories at install time, not just resolving wheels from an index. The Dockerfile confirms the cost: the builder stage installs libffi-dev, libxml2-dev, libxslt-dev, libssl-dev, autoconf, g++, python3-dev, curl, git and unzip, then installs the Rust toolchain via rustup before running pip install. The runtime image is python:3.13-slim-bookworm and its ENTRYPOINT is nxc. If your build environment has no network access to GitHub, or no compiler toolchain, the install path described in the README will not complete.

## Installing NetExec on Linux with pipx

The README gives one installation route directly, for Linux, and points to the wiki for anything else. It uses pipx so the tool lands in its own virtual environment rather than in your system Python. The README does not document rollback or an uninstall procedure, so plan for that yourself before you start.

First install pipx and git, then make sure pipx-managed binaries are on your PATH:

```bash
sudo apt install pipx git
pipx ensurepath
```

After ensurepath, open a new shell so the updated PATH takes effect. Then install NetExec straight from the repository:

```bash
pipx install git+https://github.com/Pennyw0rth/NetExec
```

This is the command the README gives. Expect it to take a while and to need a working compiler, because of the three git-sourced dependencies described above. When it finishes, the nxc script from pyproject.toml is on your PATH.

For a container-based setup, the repository ships a Dockerfile whose final ENTRYPOINT is nxc, so the image behaves like the CLI itself:

```bash
docker build -t netexec .
docker run --rm netexec --help
```

A first real use is protocol enumeration against a host you are authorized to test. The related searches for this project include netexec smb and netexec ldap, which is what the subcommand structure implies: you pick a protocol, then supply targets and credentials. The README does not reproduce a full command example, so check the wiki page for the protocol you need before running anything, and start with the help output for that subcommand rather than guessing flags.

## The documentation gap is the real adoption cost

The README says, in its own words, that the wiki is "in development" and directs readers there for documentation, tutorials and examples. Installation instructions for anything other than the Linux pipx route are also deferred to the wiki. That is an honest statement, and it should shape how you evaluate the tool.

In practice this means the repository is the documentation. The nxc/ directory, the pyproject.toml dependency list and the Dockerfile tell you more about what the tool can reach than the front page does. If your team needs a stable reference page per subcommand before you will put a tool into a client engagement, NetExec is not there yet, and the project does not claim otherwise.

The second limitation is the packaging model. Because impacket, certipy-ad and pynfsclient come from git URLs, an install is not reproducible from a lockfile alone in the way a pure-PyPI project would be. The repository does carry poetry.lock and uv.lock, which is a good sign for contributors, but the README's install command resolves those git references at the time you run it. On an air-gapped assessment laptop, or behind a proxy that blocks GitHub, this is a hard stop rather than an inconvenience. Pin your own mirror or vendor the dependencies if that is your environment.

## Where NetExec is the wrong tool

NetExec assumes you already have a foothold in terms of credentials. It is not a vulnerability scanner and the README does not present it as one: nothing in the description, the topics or the dependency list suggests unauthenticated vulnerability detection. If your job is to find missing patches or misconfigured services on a network you have no credentials for, a scanner is the right instrument and NetExec is not.

It is also a poor fit where you need a signed, vendor-supported binary. The project is a Python package with a git-based install and a Dockerfile; there is no mention in the repository of a signed Windows installer, an enterprise support contract, or a stable release channel beyond the version tags. The related searches include NetExec binary and NetExec exe, which suggests people look for a packaged Windows build, but the README's only stated installation path is the Linux command above plus the wiki. Treat any expectation of an official Windows executable as unverified until the wiki says otherwise.

Finally, the tool is dual-use by design. Remote execution against Windows hosts is what the name means. Running it outside a scope you can point to in writing is not a configuration problem, it is a legal one, and no amount of tooling changes that.

## NetExec compared with Impacket's example scripts

The closest honest alternative is not another all-in-one framework but the Impacket example scripts themselves, which NetExec depends on. Impacket is a Python library with a set of per-protocol example scripts; you invoke the script for the protocol you want, pass your own flags, and handle target lists, output formatting, credential storage and result aggregation yourself.

NetExec takes the opposite approach. It wraps those protocol implementations behind one nxc command with protocol subcommands, adds a module layer, and pulls in a database layer via sqlalchemy plus the nxcdb entry point so results can be stored and queried rather than scrolled past in a terminal. It also bundles credential-parsing libraries such as lsassy, pypykatz and dploot that you would otherwise assemble by hand.

The trade-off is control versus convenience. With Impacket you know exactly which call is being made and you can read the script. With NetExec you get a uniform interface and stored output, but you inherit the project's dependency graph, including the three git-sourced packages, and you depend on the wiki being accurate for flags the README does not list. Teams that already have Impacket-based tooling and a results pipeline may find NetExec's abstractions redundant; teams running repeated assessments across many hosts will find the module and database layer worth the install complexity.

## Maintenance, releases and the BSD-2-Clause licence

The repository is not archived and the last push was on 2026-09-22, so the project is being pushed to. Release history shows v1.4.0 in April 2025, v1.5.0 in December 2025 and v1.5.1 in February 2026, a cadence of roughly two to three tagged releases a year. The README states the maintainers' intent to keep the project community-driven with regular updates, and names NeffIsBack, Marshall-Hallenbeck and zblurx as the current maintainers alongside a list of code contributors.

Upgrade cost is dominated by the dependency model rather than by the tool's own code. Because impacket, certipy-ad and pynfsclient are git dependencies, an upgrade can pull upstream changes in those libraries at the same time as NetExec's own changes, so a version bump is not isolated to one project. If you pin NetExec to a tag, pin the git dependencies too, or you will not be able to reproduce a working environment later.

The licence is BSD-2-Clause, declared in pyproject.toml as license = { text = "BSD-2-Clause" } and listed in the repository's classifiers as an OSI-approved BSD licence. That is a permissive licence, which matters if you intend to redistribute the tool internally or bundle it into another product, but the obligations depend on how you distribute it and on the licences of the bundled dependencies, which are not all stated in the repository. Read the LICENSE file and the dependency licences before shipping anything; this is not legal advice.

## Conclusion

Adopt NetExec if you run authorized Active Directory or Windows network assessments and want one Python CLI that speaks SMB, LDAP, MSSQL and FTP with a module system on top. Do not adopt it if you need a supported commercial product, a signed Windows installer, or a tool whose every subcommand is documented on a stable page, because the README itself labels the wiki as in development. Before relying on it in an engagement, verify three things: that pipx install git+https://github.com/Pennyw0rth/NetExec resolves the three git dependencies in pyproject.toml, that your target protocol has a working module in the nxc/ tree, and that your rules of engagement explicitly permit the actions you intend to run.

## FAQ

### How do I install NetExec on Ubuntu?

The README gives a Linux path: install pipx and git with apt, run pipx ensurepath, then run pipx install git+https://github.com/Pennyw0rth/NetExec. It also points to the wiki for installation instructions.

### What does NetExec smb do?

The README does not describe individual protocol subcommands in detail. Its documentation, tutorials and examples live on the wiki, and the related searches include netexec smb, so that is the page to check for what the SMB subcommand supports.

### What is NetExec used for?

It is a network execution and enumeration tool for authorized security testing. Its repository topics cover active-directory, pentest, red-team and security-tools, and its dependency list includes SMB, LDAP, Kerberos and credential-parsing libraries.

### Is NetExec the same as CrackMapExec?

NetExec is the continuation of CrackMapExec. The README states the project was created in 2015 as CrackMapExec and renamed NetExec after the previous maintainer retired in September 2023, with the remaining active contributors maintaining it as a fully free and open source project.

### How do I install NetExec on Windows?

The README only documents a Linux installation with pipx and refers to the wiki for other instructions. It does not describe a Windows installer or an official executable, so treat that as unverified until the wiki covers it.

### How do I use NetExec?

The README directs usage questions to the project wiki, which it describes as in development, and to the Discord channel for questions if you do not have a GitHub account. The command itself is nxc, with protocol subcommands and a module layer on top.

## Sources

- [License: BSD-2-Clause](https://github.com/Pennyw0rth/NetExec/blob/main/LICENSE)
- [Pennyw0rth/NetExec on GitHub](https://github.com/Pennyw0rth/NetExec)
- [Project website](https://netexec.wiki/)
- [README](https://github.com/Pennyw0rth/NetExec/blob/main/README.md)
- [Releases](https://github.com/Pennyw0rth/NetExec/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/pennyw0rth-netexec
