Impacket LookupSID

Enumerate domain SIDs and discover trust relationships via SID brute-forcing

Tool
impacket-lookupsid
Category
Privilege Escalation / Trust Attacks
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-lookupsid '<domain>/<user>:<password>'@<ip>

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-lookupsid -hashes ':<hash>' '<domain>/<user>'@<ip>

Kerberos Ticket requires Kerberos ticket

impacket-lookupsid -k -no-pass '<domain>/<user>'@<ip>

Examples

impacket-lookupsid 'corp.local/user:password'@192.168.1.100

Tags

impacket lookupsid sid trust enumeration