Impacket getPac

Retrieve the PAC (Privilege Attribute Certificate) for a target user via the S4U2self extension. Useful for inspecting group memberships from a low-privileged context, validating that S4U is allowed, and as a building block for delegation attacks.

Tool
impacket-getPac
Category
Credential Attacks / Ticket Forgery & Conversion
Platform
linux
Requires
password
Protocols
KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-getPac -targetUser <target_user> '<domain>/<user>:<password>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-getPac -targetUser <target_user> -hashes ':<hash>' '<domain>/<user>'

Examples

impacket-getPac -targetUser administrator 'CORP/jdoe:Password123!'

Tags

impacket pac s4u2self kerberos delegation

References