CrackMapExec — Malware Profile
CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral movement through targeted networks.
MITRE ATT&CK techniques (20)
- T1003.002 Security Account Manager
- T1003.003 NTDS
- T1003.004 LSA Secrets
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1047 Windows Management Instrumentation
- T1049 System Network Connections Discovery
- T1053.002 At
- T1059.001 PowerShell
- T1069.002 Domain Groups
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1110 Brute Force
- T1110.001 Password Guessing
- T1110.003 Password Spraying
- T1112 Modify Registry
- T1135 Network Share Discovery
- T1201 Password Policy Discovery
- T1550.002 Pass the Hash
- T1680 Local Storage Discovery