1200KM / tool
CrackMapExec — Attack Tool
CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral movement through targeted networks.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: CrackMapExec
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Dragonfly · G0035 · Pinned relationship source (relationship--a60d34fc-9c1e-4b36-a82b-56258445c7f0)
- FIN7 · G0046 · Pinned relationship source (relationship--707474c8-890d-4be2-81d5-f6a4902b1309)
- MuddyWater · G0069 · Pinned relationship source (relationship--aa0e4bee-a9a4-4d32-bb62-f024058842c6)
- APT39 · G0087 · Pinned relationship source (relationship--37fee9dc-701e-49be-8cec-b2fde4b533d8)
- Ember Bear · G1003 · Pinned relationship source (relationship--71b0e83e-8b1e-41ea-b7ec-35f66a3ee9d8)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.002 · Security Account Manager · Detection rules & anomalies
- T1003.003 · NTDS · Detection rules & anomalies
- T1003.004 · LSA Secrets · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1018 · Remote System Discovery · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1053.002 · At · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1069.002 · Domain Groups · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1110 · Brute Force · Detection rules & anomalies
- T1110.001 · Password Guessing · Detection rules & anomalies
- T1110.003 · Password Spraying · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1201 · Password Policy Discovery · Detection rules & anomalies
- T1550.002 · Pass the Hash · Detection rules & anomalies
- T1680 · Local Storage Discovery · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Active Directory Object Access · DC0071
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Modification · DC0061
- Logon Session Creation · DC0067
- Module Load · DC0016
- Named Pipe Metadata · DC0048
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Scheduled Job Creation · DC0001
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- Volume Creation · DC0097
- WMI Creation · DC0008
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.