impacket-programming-manual: writing your own domain-penetration scripts
A book-length, source-code-driven guide to developing your own domain-penetration scripts on top of impacket - not another walkthrough of secretsdump.py / psexec.py flags.
Why this manual exists
Almost every public exploit for recent Active Directory vulnerabilities was built directly on impacket modules: sam-the-admin, CVE-2022-33679, noPac, Zerologon tooling, PetitPotam-style relay chains. Yet nearly all existing articles only explain how to run the example scripts. This manual fills the gap the other way around: it walks module by module through the impacket source tree, so when the next domain vulnerability drops you can grab impacket and write your own PoC fast.
- Author: Lu Ping
- Length: ~5,400 lines, 9 chapters, 6 parts
- Covers: LDAP, Kerberos (krb5), GSS-API/SPNEGO, DCE/RPC (NDR, EPM, transport), 20+ MS protocol modules, DCOM and WMI, the support libraries, and the impacket 0.12-0.14 additions
What's inside
| Part | Chapter | Content |
|---|---|---|
| I. Preliminaries | Ch.1 impacket overview and directory layout | Where every module lives in the source tree |
Ch.2 structure.py - universal serialization base |
The base class behind every protocol packet structure | |
| II. Authentication and Directory | Ch.3 LDAP (ldap) |
Directory queries, ACL structures, Global Catalog |
Ch.4 Kerberos (krb5) |
Tickets, ccache/keytab, PAC, GSS-API and SPNEGO | |
| III. DCE/RPC | Ch.5 dcerpc
|
RPC basics (NDR, rpcrt, EPM, transport) + 20+ interface modules in 5 functional groups (SAMR, NRPC, LSAD, RRP, SRVS, RPRN/PAR, TSCH, BKRP, DRSUAPI...) |
| IV. DCOM and WMI | Ch.6 MS-DCOM | COM/DCOM programming, dcomrt, oaut/comev/scmp/vds/wmi submodules |
| V. Support libraries | Ch.7 common
|
SMB2/3, DPAPI, NTDS (ese), TDS |
| VI. New interfaces and case studies | Ch.8 interfaces added in 0.12-0.14 | ICPR (AD CS certificate enrollment), GKDI (group key distribution), NEGOEX, RAA (remote authorization), SCMR, plus acl.py and dpapi_ng.py
|
| Ch.9 case studies | BadSuccessor (CVE-2025-53779) and CVE-2025-33073 - PoC walk-throughs |
Case studies woven through the chapters
Zerologon (CVE-2020-1472) in nrpc; PrinterBug / PrintNightmare in rprn/par; CVE-2019-1040 NTLM MIC bypass in gssapi; Exchange RPC-over-HTTP relay (rpcmap / ProxyRelay); Akamai's "Cold Hard Cache" RPC security-callback bypass; WMI persistence (wmipersist); golden PAC forging. In Part VI: BadSuccessor (CVE-2025-53779), which abuses the Windows Server 2025 dMSA account type, and CVE-2025-33073, the reflective relay that yields SYSTEM on any host without SMB signing.
Highlights
-
Source-level, not example-level. Every chapter reads the actual impacket source:
getKerberosTGT/getKerberosTGSinternals, ccache/keytab binary layouts,DCERPCTransportFactorydispatch,DCOMConnection/INTERFACE/IRemUnknownobject model,IWbemServicesmethod tables. - Annotated code excerpts. Long listings are compressed to key code paths with step-numbered annotations, so you see the flow at a glance instead of scrolling through hundreds of lines of boilerplate.
-
Upstream-verified quotes. All cited code was checked against the current fortra/impacket master; known upstream quirks (the
par.pyopnum 39 tuple,hept_mapspelling,MimiUnbindvsMiniUnbind) are preserved and annotated instead of silently "fixed".
Formats
English edition (impacket_programming_manual_EN.pdf) and Chinese edition (impacket编程手册.pdf), both included, plus the source-first chapters.
Repo and docs: https://github.com/lupingQAQ/impacket-programming-manual
Top comments (0)