logo

Impacket Offense Basics With an Azure Lab

ID: bf597fe5-44ea-57a0-9f53-3274721b0b02

STIX ID: report--bf597fe5-44ea-57a0-9f53-3274721b0b02

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2022-06-01

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog-style lab walkthrough demonstrates how to use Impacket tools (ntlmrelayx.py, GetADUsers.py, Get-GPPPassword.py, GetUserSPNs.py, secretsdump.py) to perform NTLM relay attacks (including SMB and LDAPS relays), credential enumeration and dumping, and AD manipulation in a controlled Azure lab. The author maps each technique to MITRE ATT&CK, provides command examples and outputs, and highlights impacts such as domain credential harvests and potential domain takeover while noting defensive considerations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.