ATT&CKSoftwareCrackMapExec

CrackMapExec

S0488

Tool.View on attack.mitre.org

About this tool

CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral movement through targeted networks.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1003.002
Security Account Manager

CrackMapExec can dump usernames and hashed passwords from the SAM.

T1003.003
NTDS

CrackMapExec can dump hashed passwords associated with Active Directory using Windows' Directory Replication Services API (DRSUAPI), or Volume Shadow Copy.

T1003.004
LSA Secrets

CrackMapExec can dump hashed passwords from LSA secrets for the targeted system.

T1016
System Network Configuration Discovery

CrackMapExec can collect DNS information from the targeted system.

T1018
Remote System Discovery

CrackMapExec can discover active IP addresses, along with the machine name, within a targeted network.

T1047
Windows Management Instrumentation

CrackMapExec can execute remote commands using Windows Management Instrumentation.

T1049
System Network Connections Discovery

CrackMapExec can discover active sessions for a targeted system.

T1053.002
At

CrackMapExec can set a scheduled task on the target system to execute commands remotely using at.

T1059.001
PowerShell

CrackMapExec can execute PowerShell commands via WMI.

T1069.002
Domain Groups

CrackMapExec can gather the user accounts within domain groups.

T1083
File and Directory Discovery

CrackMapExec can discover specified filetypes and log files on a targeted system.

T1087.002
Domain Account

CrackMapExec can enumerate the domain user accounts on a targeted system.

T1110
Brute Force

CrackMapExec can brute force supplied user credentials across a network range.

T1110.001
Password Guessing

CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network.

T1110.003
Password Spraying

CrackMapExec can brute force credential authentication by using a supplied list of usernames and a single password.

View all 20 procedure examples

Groups that use it5

Campaigns1

References1

  1. CME Github September 2018 Open source
    byt3bl33d3r. (2018, September 8). SMB: Command Reference. Retrieved July 17, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.