CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral movement through targeted networks.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
CrackMapExec can dump usernames and hashed passwords from the SAM. |
| T1003.003 NTDS |
CrackMapExec can dump hashed passwords associated with Active Directory using Windows' Directory Replication Services API (DRSUAPI), or Volume Shadow Copy. |
| T1003.004 LSA Secrets |
CrackMapExec can dump hashed passwords from LSA secrets for the targeted system. |
| T1016 System Network Configuration Discovery |
CrackMapExec can collect DNS information from the targeted system. |
| T1018 Remote System Discovery |
CrackMapExec can discover active IP addresses, along with the machine name, within a targeted network. |
| T1047 Windows Management Instrumentation |
CrackMapExec can execute remote commands using Windows Management Instrumentation. |
| T1049 System Network Connections Discovery |
CrackMapExec can discover active sessions for a targeted system. |
| T1053.002 At |
CrackMapExec can set a scheduled task on the target system to execute commands remotely using at. |
| T1059.001 PowerShell |
CrackMapExec can execute PowerShell commands via WMI. |
| T1069.002 Domain Groups |
CrackMapExec can gather the user accounts within domain groups. |
| T1083 File and Directory Discovery |
CrackMapExec can discover specified filetypes and log files on a targeted system. |
| T1087.002 Domain Account |
CrackMapExec can enumerate the domain user accounts on a targeted system. |
| T1110 Brute Force |
CrackMapExec can brute force supplied user credentials across a network range. |
| T1110.001 Password Guessing |
CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network. |
| T1110.003 Password Spraying |
CrackMapExec can brute force credential authentication by using a supplied list of usernames and a single password. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.