Impacket RPCDump
Enumerate RPC endpoints and interfaces registered on a remote host
- Tool
- impacket-rpcdump
- Category
- Enumeration / Network Discovery
- Platform
- linux
- Requires
- password
- Protocols
- RPC
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-rpcdump '<domain>/<user>:<password>'@'<ip>'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
impacket-rpcdump -hashes ':<hash>' '<domain>/<user>'@'<ip>'
Kerberos Ticket requires Kerberos ticket
impacket-rpcdump -k -no-pass '<domain>/<user>'@'<ip>'
Examples
impacket-rpcdump 'CORP.LOCAL/user:password'@192.168.1.100
Tags
Related commands
- Impacket DumpNTLMInfo Dump NTLM server information (OS version, domain, hostname) without credentials
- Impacket RDP Check Check if credentials are valid for RDP access
- NetExec RDP NLA Screenshot Capture a pre-auth RDP login screen against hosts that have NLA enabled. Reveals OS…
- Nmap TCP Scan Comprehensive TCP port scan with service version detection and default scripts