NOTES
Impacket provides focused protocol implementations and example scripts for Windows assessment. I use it when I need transparent command-line control over SMB, Kerberos, WMI, DCOM, secrets, tickets, or relay-related behavior.
Tool choice should follow the access already proven. Remote execution scripts have different service creation, file, logging, and privilege requirements; using several blindly creates noise without answering a new question.
SELECT
- smbclient.py for shares and file operations.
- GetUserSPNs.py and GetNPUsers.py for narrowly scoped Kerberos ticket requests.
- secretsdump.py for approved secrets extraction after the required privilege is established.
- wmiexec.py, dcomexec.py, smbexec.py, or psexec.py only when remote execution is authorized and their operational differences are understood.
- ntlmrelayx.py only after validating relay prerequisites, targets, and engagement constraints.
CREDENTIALS
DOMAIN/USER:PASSWORD@TARGET
DOMAIN/USER@TARGET -hashes LMHASH:NTHASH
DOMAIN/USER@TARGET -k -no-pass
GOTCHAS
- Use FQDNs and correct DNS when Kerberos service principal names matter.
- Check clock skew before assuming a ticket or credential is invalid.
- An empty LM hash placeholder is still part of the hashes syntax.
- Record which protocol and execution method created any service, file, or process.
- Clean up only the artifacts your action created and verify removal.