Pure-Nim network enumeration and exec toolkit

nimux

A native command surface for authorized operators: enumerate protocols, validate credentials, execute remotely, move files, manage Kerberos tickets, and document repeatable paths.

Remote execution

WinRM, WMI, SCM, DCOM, scheduled tasks, and helper services.

AD operations

Kerberos, LDAP writes, GPO paths, secrets, DCSync, and tickets.

Enumeration

SMB, LDAP, RDP, MSSQL, HTTP, SSH, FTP, NFS, VNC, and WebDAV.

Kerberos

TGT, TGS, S4U, ccache, kirbi conversion, roasting, and ticket forge.

File movement

Upload, download, recursive transfer, and shell-session helpers.

MSSQL paths

Query execution, xp_cmdshell, linked servers, OLE, CLR, and capture.

Network enumeration

Probe the services that matter, enumerate HTTP paths and vhosts, resolve DNS names, spider SMB shares, and keep the output scriptable.

Remote execution

Run commands and shells through native protocol paths without leaving one CLI surface.

Identity operations

Work with Kerberos, LDAP, secrets, certificates, tickets, and Active Directory write paths.

MCP integration

Expose nimux workflows to MCP-compatible AI clients with policy gates, redaction, progress, and pivot metadata.

Command surface

Protocol work without changing tools.

nimux keeps protocol checks, web discovery, SMB share triage, authentication, execution, ticket handling, and file movement in a compact workflow built for fast authorized assessment work.

operator

$ nimux smb target.corp.local -u operator -H <nt_hash> --shares

Native by design

Built as a native operator toolkit.

nimux focuses on speed, portability, and a consistent command model for authorized security work.

Pure Nim core

Built around native Nim code paths for a compact operator workflow without a Python runtime dependency.

Single-tool mindset

Keep protocol checks, execution, file movement, Kerberos, and AD operations behind one command surface.

Fast local feedback

Designed for quick validation loops during authorized labs, internal assessments, and repeatable operator chains.

Modules

Native paths in one binary.

scan

Fast TCP and UDP scanner

http

HTTP dirs, files, vhosts, recursion, and filters

dns

Subdomain discovery with worker support

smb

Shares, null-session checks, spidering, users, RID brute, coercion, ticket capture

ldap

AD query and write operations

adcs

Template checks, enrollment, PKINIT, mapping, and shadow paths

kerberos

TGT, TGS, S4U, forge, ccache, and kirbi

winrm

NTLM and Kerberos shells

mssql

Queries, xp_cmdshell, links, OLE, and CLR

secrets

SAM, LSA, DPAPI, and cached logons

dcsync

Native MS-DRSR replication requests

gpo

Create, link, backup, edit, and rollback policy paths

bloodhound

Legacy 4.x-compatible AD graph output

spray

Lockout-aware credential validation

socks

Operator proxy workflows

proxy

Route supported commands through SOCKS5

files

SMB and WinRM file transfer

mcp

AI-client wrapper with safety policy and progress

protocols

RDP, SSH, FTP, NFS, AFP, WebDAV, SQL

Workflow

Built for repeatable operator chains.

Keep scanning, authentication, execution, ticket work, file transfer, and post-auth validation in one command model.

Probe and fingerprint reachable services
Validate NTLM, Kerberos, and local auth
Move files and run managed assemblies
Repeat documented chains from one CLI syntax