Impacket SMBExec: A Pentester’s Guide to Remote Windows Command Execution

Summary
A practical guide to using Impacket SMBExec for remote Windows command execution with passwords, hashes, and Kerberos credentials, plus recommendations for limiting and detecting its use.
Key points
- SMBExec creates a Windows service and uses SMB and a named pipe to run remote commands and return output.
- The tutorial demonstrates password, NTLM pass-the-hash, Kerberos ticket, and AES-key authentication.
- Commands run with SYSTEM privileges by default; operators can use cmd or PowerShell and run commands interactively or non-interactively.
- Options control the output share, target IP, logging, and service name; a less conspicuous service name may make activity harder to spot.
- Suggested defenses include least privilege, unique local administrator passwords, limiting NTLM, and restricting SMB access through network segmentation.
- The article recommends monitoring for unusual service creation, suspicious writes to administrative shares, and unexpected command lines.
Article Details
- Topic
- Authorized remote command execution and lateral movement testing with impacket-smbexec
MITRE ATT&CK
T1016 · System Network Configuration DiscoveryDemonstrates running ipconfig remotely to obtain the target's network configuration.T1021.002 · SMB/Windows Admin SharesUses SMB and administrative shares for remote execution and retrieval of command output.T1036.004 · Masquerade Task or ServiceDescribes assigning a benign-looking custom service name to blend in with legitimate services.T1059.001 · PowerShellSupports selecting PowerShell as the remote command processor.T1059.003 · Windows Command ShellExecutes remote commands through the Windows command interpreter by default.T1078 · Valid AccountsUses valid account credentials to authenticate to a remote Windows host and execute commands.T1550.002 · Pass the HashDemonstrates pass-the-hash authentication using an NTLM hash without the plaintext password.T1569.002 · Service ExecutionCreates a Windows service on the remote host to execute commands with SYSTEM privileges.
Vendors
Products
Active DirectoryRemote command execution sits at the heart of nearly every successful Active Directory engagement.Microsoft WindowsIt opens a semi-interactive command prompt on a remote Windows machine over the SMB protocol, allowing an operator to run commands, gather information, and validate the scope of compromised accounts without everPowerShellSelecting the PowerShell Command Processor