DEV Community

lupingQAQ
lupingQAQ

Posted on

impacket-programming-manual: writing your own domain-penetration scripts

impacket-programming-manual: writing your own domain-penetration scripts

A book-length, source-code-driven guide to developing your own domain-penetration scripts on top of impacket - not another walkthrough of secretsdump.py / psexec.py flags.

Why this manual exists

Almost every public exploit for recent Active Directory vulnerabilities was built directly on impacket modules: sam-the-admin, CVE-2022-33679, noPac, Zerologon tooling, PetitPotam-style relay chains. Yet nearly all existing articles only explain how to run the example scripts. This manual fills the gap the other way around: it walks module by module through the impacket source tree, so when the next domain vulnerability drops you can grab impacket and write your own PoC fast.

  • Author: Lu Ping
  • Length: ~5,400 lines, 9 chapters, 6 parts
  • Covers: LDAP, Kerberos (krb5), GSS-API/SPNEGO, DCE/RPC (NDR, EPM, transport), 20+ MS protocol modules, DCOM and WMI, the support libraries, and the impacket 0.12-0.14 additions

What's inside

Part Chapter Content
I. Preliminaries Ch.1 impacket overview and directory layout Where every module lives in the source tree
Ch.2 structure.py - universal serialization base The base class behind every protocol packet structure
II. Authentication and Directory Ch.3 LDAP (ldap) Directory queries, ACL structures, Global Catalog
Ch.4 Kerberos (krb5) Tickets, ccache/keytab, PAC, GSS-API and SPNEGO
III. DCE/RPC Ch.5 dcerpc RPC basics (NDR, rpcrt, EPM, transport) + 20+ interface modules in 5 functional groups (SAMR, NRPC, LSAD, RRP, SRVS, RPRN/PAR, TSCH, BKRP, DRSUAPI...)
IV. DCOM and WMI Ch.6 MS-DCOM COM/DCOM programming, dcomrt, oaut/comev/scmp/vds/wmi submodules
V. Support libraries Ch.7 common SMB2/3, DPAPI, NTDS (ese), TDS
VI. New interfaces and case studies Ch.8 interfaces added in 0.12-0.14 ICPR (AD CS certificate enrollment), GKDI (group key distribution), NEGOEX, RAA (remote authorization), SCMR, plus acl.py and dpapi_ng.py
Ch.9 case studies BadSuccessor (CVE-2025-53779) and CVE-2025-33073 - PoC walk-throughs

Case studies woven through the chapters

Zerologon (CVE-2020-1472) in nrpc; PrinterBug / PrintNightmare in rprn/par; CVE-2019-1040 NTLM MIC bypass in gssapi; Exchange RPC-over-HTTP relay (rpcmap / ProxyRelay); Akamai's "Cold Hard Cache" RPC security-callback bypass; WMI persistence (wmipersist); golden PAC forging. In Part VI: BadSuccessor (CVE-2025-53779), which abuses the Windows Server 2025 dMSA account type, and CVE-2025-33073, the reflective relay that yields SYSTEM on any host without SMB signing.

Highlights

  • Source-level, not example-level. Every chapter reads the actual impacket source: getKerberosTGT/getKerberosTGS internals, ccache/keytab binary layouts, DCERPCTransportFactory dispatch, DCOMConnection/INTERFACE/IRemUnknown object model, IWbemServices method tables.
  • Annotated code excerpts. Long listings are compressed to key code paths with step-numbered annotations, so you see the flow at a glance instead of scrolling through hundreds of lines of boilerplate.
  • Upstream-verified quotes. All cited code was checked against the current fortra/impacket master; known upstream quirks (the par.py opnum 39 tuple, hept_map spelling, MimiUnbind vs MiniUnbind) are preserved and annotated instead of silently "fixed".

Formats

English edition (impacket_programming_manual_EN.pdf) and Chinese edition (impacket编程手册.pdf), both included, plus the source-first chapters.

Repo and docs: https://github.com/lupingQAQ/impacket-programming-manual

Top comments (0)