CrackMapExec

MITRE ATT&CK: S0488 View on attack.mitre.org

Aliases: CrackMapExec

First seen
2015-05-01 00:00:00
Malware type
credential-stealer
Operating systems
windows
Profile updated
2026-07-07 15:33:24

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services healthcare-and-pharmaceutical

Context

CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral movement through targeted networks.

Detection coverage

  • 505 Sigma rules

Malware & tools used

  • Security Account Manager (attack-pattern)
  • NTDS (attack-pattern)
  • Password Spraying (attack-pattern)
  • Password Policy Discovery (attack-pattern)
  • Domain Account (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Password Guessing (attack-pattern)
  • At (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • LSA Secrets (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Modify Registry (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Pass the Hash (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Domain Groups (attack-pattern)
  • PowerShell (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Brute Force (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0488 (report)
  • github.com — Smb Command Reference (report)

External references