Credential Attacks Commands
110 commands across 9 subcategories. Every entry lists the authentication material it needs, the protocols it speaks and links to upstream tool documentation.
Hash Dumping 29
- Impacket DPAPI Masterkey Decrypt DPAPI masterkey using user password to derive DPAPI encryption key
- Impacket Secrets Dump Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Impacket Targeted DCSync (Single User) DCSync only one specific account instead of replicating the whole NTDS. Massively reduces noise on the wire…
- Lsassy LSASS Dump Remotely dump LSASS credentials using lsassy
- Mimikatz Credential Dump Extract plaintext passwords and hashes from all available sources
- Mimikatz dpapi::masterkey Decrypt a DPAPI master key using the owner's plaintext password (or NT hash). Required step before…
- Mimikatz lsadump::dcsync Pull a single user's NT hash and Kerberos keys directly from a DC via the MS-DRSR replication protocol. No…
- Mimikatz lsadump::sam Extract local SAM hashes (built-in Administrator, local users) from a live Windows host. Run as SYSTEM…
- Mimikatz sekurlsa::logonpasswords Dump credentials (NT hashes, Kerberos keys, plaintext where wdigest is enabled, MSV1_0) from LSASS for every…
- Mimikatz Ticket Extraction Extract cached Kerberos tickets
- NetExec dpapi_hash Module Extract DPAPI master-key hashes for offline cracking with hashcat (mode 15300 for v1 / 15900 for v2).…
- NetExec eventlog_creds Module Harvest plaintext credentials passed to processes (typically scheduled tasks, runas, custom scripts) from…
- NetExec gpp_password Module Search SYSVOL for Group Policy Preferences XML files containing AES-encrypted cpassword values, then decrypt…
- NetExec lsassy Module (Remote LSASS Dump) Dump LSASS remotely via the lsassy module — uses procdump/comsvcs/dllinjection methods, parses on the fly…
- NetExec masky Module Remotely abuse a vulnerable certificate template (typically User) to enroll certificates as every…
- NetExec nanodump Module Dump LSASS using the nanodump BOF/PE technique — minimal dump, fewer EDR signatures than full minidumps,…
- NetExec SMB Backup Operator Abuse Backup Operators group membership to dump registry hives (SAM, SYSTEM, SECURITY)
- NetExec SMB DPAPI Hash Extract DPAPI master key hashes from remote hosts for offline cracking
- NetExec SMB HandleKatz Dump LSASS credentials by duplicating process handles to bypass PPL/AV restrictions
- NetExec SMB Masky Abuse ADCS to request certificates for all logged-on users and extract their NT hashes
- NetExec SMB NTDS Dump Dump the NTDS.dit database from a Domain Controller to extract all domain hashes
- NetExec SMB NTDSUtil Dump Dump NTDS.dit using ntdsutil IFM method (creates install-from-media backup)
- NetExec SMB SAM & LSA Dump Dump SAM database and LSA secrets from a remote Windows system via NetExec
- NetExec SMB WDigest Enable Enable or disable WDigest authentication to force cleartext password caching in LSASS
- NetExec timeroast Module Timeroast: brute computer-account passwords via the MS-SNTP authenticated NTP exchange. The DC signs replies…
- Pypykatz SAM Dump Extract hashes from SAM and SYSTEM registry files
- Rubeus dump Extract every Kerberos ticket currently in memory across all logon sessions. Requires elevation for other…
- Rubeus harvest Continuously monitor LSA for new TGTs and auto-renew them before expiry. Long-running collection — pair with…
- Rubeus tgtdeleg Extract a usable TGT for the current user without elevation by abusing the GSS-API delegation flow. The…
Hash Cracking 5
- Hashcat AS-REP Roasting Cracking Crack AS-REP roasting hashes obtained from accounts without Kerberos pre-auth
- Hashcat Kerberoast Crack Crack Kerberoasting hashes
- Hashcat MSCacheV2 (DCC2) Cracking Crack MSCacheV2 (Domain Cached Credentials v2 / DCC2) hashes extracted from registry
- Hashcat NTLM Crack Crack NTLM hashes using wordlist attack
- Hashcat NTLMv2 Cracking Crack NTLMv2 (NetNTLMv2) challenge-response hashes captured from Responder or relay attacks
Kerberoasting 12
- Impacket AS-REP Roast AS-REP Roasting for accounts without Kerberos Pre-Authentication
- Impacket Get TGT Get TGT to be used in Kerberos authentication
- Impacket Kerberoast Extract service account hashes via Kerberoasting
- Impacket KeyListAttack Abuse RODC (Read-Only DC) credential caching to retrieve hashes for accounts cached on the RODC
- Impacket Targeted Kerberoast Request a TGS only for a specific service account instead of every kerberoastable user in the domain.…
- NetExec LDAP AS-REP Roasting Request AS-REP responses for every account with DONT_REQ_PREAUTH set and write hashes to a file ready for…
- NetExec LDAP Kerberoasting Request TGS tickets for every account with a SPN and write hashes to a file ready for hashcat (-m 13100).…
- NetExec LDAP Pre-Windows 2000 Accounts Enumerate pre-Windows 2000 compatible computer accounts that use the hostname as password
- NetExec SMB Timeroast Exploit NTP to request hashes for computer accounts without a password (Timeroasting)
- Rubeus asktgt Request a TGT for a user with a password, NT hash, or AES key. /ptt injects it into the current session;…
- Rubeus kerberoast Roast every kerberoastable account in the domain from a Windows host. Auto-discovers SPNs via LDAP and dumps…
- Targeted Kerberoast Targeted Kerberoasting attack on specific accounts
AS-REP Roasting 1
- Rubeus asreproast Find every account with DONT_REQ_PREAUTH set and dump AS-REP hashes for offline cracking (hashcat 18200).…
NTLM Relay & Coercion 18
- Coercer Coerce NTLM authentication using multiple RPC protocols
- Coercer Scan (Find Coercion Vectors) Probe a target for every known authentication-coercion RPC method (PetitPotam, PrinterBug, DFSCoerce,…
- DFSCoerce Coerce NTLM authentication using MS-DFSNM (Distributed File System)
- NetExec coerce_plus Module Unified coercion module — replaces the individual petitpotam/printerbug/dfscoerce/shadowcoerce/mserven…
- NetExec Generate Relay Target List Scan a subnet over SMB and write a file containing every host with SMB signing disabled. The resulting list…
- NetExec mssql_coerce Module Coerce the MSSQL service account to authenticate to your relay listener via xp_dirtree / xp_subdirs /…
- NetExec PetitPotam Coercion Coerce a Windows host (typically a DC) to authenticate back to the attacker via the EFSRPC interface…
- NetExec SMB Coerce Plus Trigger NTLM authentication coercion using multiple methods (PetitPotam, PrinterBug, etc.) without credentials
- NetExec SMB NTLMv1 Check Check if NTLMv1 authentication is accepted on remote hosts (enables downgrade attacks)
- NetExec SMB ShadowCoerce Coerce NTLM authentication via the VSS shadow copy API (ShadowCoerce)
- NTLM Relay to ADCS Relay NTLM authentication to ADCS web enrollment to obtain a certificate
- NTLM Relay to LDAP Relay NTLM authentication to LDAP to configure RBCD delegation
- NTLM Relay to SMB NTLM relay attack targeting SMB service
- ntlmrelayx → LDAPS (Add Computer / RBCD / Shadow Creds) Relay coerced authentication to LDAPS — required when MIC and channel binding force LDAP signing. Common…
- ntlmrelayx SOCKS Proxy Run ntlmrelayx in SOCKS mode to keep relayed sessions alive after the initial authentication. Drive them…
- PetitPotam Coercion Coerce NTLM authentication from a target using MS-EFSRPC (PetitPotam)
- PrinterBug / SpoolSample Coerce NTLM authentication using the Print Spooler service (MS-RPRN)
- Responder Poison LLMNR, NBT-NS, and mDNS to capture NTLM hashes on the network
ADCS (Certificate Abuse) 22
- bloodyAD Shadow Credentials Add a Key Credential (msDS-KeyCredentialLink) to a target object you have GenericWrite over. After this you…
- Certipy Account Operations Create, update, read, or delete user / computer accounts directly through Certipy. Particularly useful for…
- Certipy Authenticate with Certificate Authenticate using a PFX certificate to obtain a TGT and NT hash
- Certipy CA Management Enumerate and manipulate the certificate authority itself: list officers (ESC7), backup the CA private key,…
- Certipy ESC1 (Subject in Request) Exploit ESC1: a template that allows the requester to specify a Subject Alternative Name…
- Certipy ESC11 (RPC Relay to ICPR) ESC11: ICertPassage RPC interface accepts NTLM without IF_ENFORCEENCRYPTICERTREQUEST. Relay coerced…
- Certipy ESC13 (OID Group Link) ESC13: a template's issuance policy is linked to a privileged group via msDS-OIDToGroupLink. Enrolling adds…
- Certipy ESC14 (altSecurityIdentities Mapping) ESC14: weak explicit certificate mapping via altSecurityIdentities. With write access over a victim object,…
- Certipy ESC15 (Schema V1 EKUwu) ESC15 / EKUwu: schema v1 templates honor Application Policies from the CSR, letting an enrollee inject…
- Certipy ESC16 (CA Security Extension Disabled) ESC16: the CA has the szOID_NTDS_CA_SECURITY_EXT object identifier in DisableExtensionList, so issued…
- Certipy ESC2 (Any Purpose EKU) ESC2: template has the Any Purpose EKU (or no EKU at all), so the issued cert can be used for any purpose…
- Certipy ESC3 (Enrollment Agent) ESC3: a template has the Certificate Request Agent EKU. Get an enrollment-agent cert, then use it to enroll…
- Certipy ESC6 (EDITF_ATTRIBUTESUBJECTALTNAME2) ESC6: the CA has EDITF_ATTRIBUTESUBJECTALTNAME2 set, allowing any enrollee to specify an arbitrary SAN on…
- Certipy ESC7 (Vulnerable CA Access Rights) ESC7: you have ManageCA or ManageCertificates on the CA. Add yourself as an officer, approve a previously…
- Certipy ESC8 (HTTP Web Enrollment Relay) ESC8: AD CS Web Enrollment endpoint accepts NTLM and is missing EPA. Relay coerced machine authentication…
- Certipy ESC9 (No Security Extension) ESC9: certificate template has CT_FLAG_NO_SECURITY_EXTENSION, so the new szOID_NTDS_CA_SECURITY_EXT is not…
- Certipy Find Vulnerable Templates Enumerate ADCS certificate templates and identify vulnerable configurations
- Certipy Relay to ADCS Relay NTLM authentication to ADCS web enrollment to obtain a certificate
- Certipy Request Certificate Request a certificate from a vulnerable ADCS template
- Certipy Shadow Credentials Abuse shadow credentials to obtain a certificate for a target account
- Certipy Shadow Credentials (msDS-KeyCredentialLink) Abuse GenericAll/GenericWrite/WriteProperty over a target by writing a Key Credential to…
- Certipy Template Edit (ESC4) ESC4: when you have GenericWrite/WriteOwner over a template, rewrite its security descriptor / flags to make…
Ticket Forgery & Conversion 7
- Impacket describeTicket Parse and display the contents of a Kerberos ticket (.ccache or .kirbi)
- Impacket Diamond Ticket Forge a Diamond Ticket: request a legitimate TGT from the KDC and then patch its PAC with custom group…
- Impacket getPac Retrieve the PAC (Privilege Attribute Certificate) for a target user via the S4U2self extension. Useful for…
- Impacket Golden Ticket Forge a Golden Ticket (TGT) using the krbtgt NTLM hash
- Impacket Silver Ticket Forge a Silver Ticket (TGS) for a specific service using its NTLM hash
- Impacket Ticket Converter Convert Kerberos tickets between kirbi (Windows) and ccache (Linux) formats
- Impacket ticketer.py Golden Ticket Forge a Golden Ticket (TGT signed with the krbtgt key) granting any user, any privilege, until the krbtgt…
Password Manipulation 10
- bloodyAD add uac Toggle UserAccountControl flags on a target account. Setting DONT_REQ_PREAUTH on a user you control (via…
- BloodyAD Force Password Change Force password change using BloodyAD
- bloodyAD Set Password Reset another user's password if you have ForceChangePassword (User-Force-Change-Password extended right) on…
- Impacket changepasswd Change an AD user's password via RPC (requires appropriate ACL rights)
- Impacket Get-GPPPassword Decrypt Group Policy Preference (GPP) passwords from XML files
- Net RPC Password Change Force password change via Net RPC
- NetExec change-password Module Reset a user's password when they are flagged STATUS_PASSWORD_MUST_CHANGE — typical after a freshly-spawned…
- NetExec SMB GPP AutoLogin Search Group Policy Preferences for AutoLogon credentials stored in SYSVOL
- NetExec SMB GPP Password Search SYSVOL for Group Policy Preference XML files containing encrypted passwords
- NetExec SMB Winlogon Credentials Extract AutoLogon credentials from the Winlogon registry key on remote hosts
gMSA & LAPS 6
- BloodyAD LAPS Password Read Read LAPS passwords from Active Directory using BloodyAD
- gMSA Password Dump Read password of Group Managed Service Account
- Impacket GetLAPSPassword Retrieve LAPS managed local administrator passwords from Active Directory
- NetExec LAPS Module (Read ms-MCS-AdmPwd) Read LAPS-managed local admin passwords from ms-MCS-AdmPwd / msLAPS-Password attributes for every computer…
- NetExec LDAP gMSA Dump Read Group Managed Service Account passwords via NetExec
- NetExec LDAP LAPS Retrieve LAPS managed local administrator passwords from Active Directory via LDAP