Library / SDK
fortra/impacket avatar
fortra/impacket

Impacket: Python Network Protocol Classes and the Example Toolkit

Impacket is a collection of Python classes for working with network protocols.

16,134 stars3,969 forksPythonNOASSERTION

At a glance

What is it?
Impacket is a Python library for constructing and parsing network protocol packets, with SMB and MSRPC implemented at the protocol level, plus a set of example scripts. It is aimed at security researchers, and its own README says it is not meant for production use.
Who is it for?
Adopt Impacket if you are writing Python that has to speak SMB, MSRPC, Kerberos or LDAP at packet level, or if the example scripts already match the research task in front of you. Do not adopt it as a production integration layer: the README states the code is for research and educational purposes and not meant for use in production environments or as part of commercial products.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 7 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Impacket Is For, and Who Actually Needs It

Most Python code that touches Windows networking sits on top of someone else's abstraction: a wrapper around SMB, a client library for LDAP, a Kerberos helper. Impacket takes the opposite position. The README describes it as a collection of Python classes for working with network protocols, focused on low-level programmatic access to the packets, and for some protocols, SMB1-3 and MSRPC among them, the protocol implementation itself. Packets can be built from scratch or parsed from raw bytes, and the object-oriented API is designed for deep protocol hierarchies.

That framing tells you who the library is for. If you need to send a malformed SMB2 negotiate request and observe what comes back, or assemble an MSRPC call over SMB/TCP by hand, Impacket gives you the layers rather than a finished client. The README's stated purpose is to help security researchers and the community speed up research and educational activities around protocol implementations. The example scripts in the examples/ directory exist to demonstrate what the library can do, not to be the product.

If you want a supported, documented client for talking to a file share in a business application, this is the wrong layer entirely. The library gives you the pieces; assembling them correctly is your job.

The Protocol Stack Impacket Implements

The breadth is the distinguishing feature. The README lists Ethernet and Linux cooked capture, IP, TCP, UDP, ICMP, IGMP and ARP, with IPv4 and IPv6 support. Above that sit NMB and SMB1, SMB2 and SMB3 as high-level implementations, and MSRPC version 5 over four transports: TCP, SMB/TCP, SMB/NetBIOS and HTTP.

Authentication is handled at the same level: plain, NTLM and Kerberos, using passwords, hashes, tickets or keys. That is why the topics list includes pass-the-hash and Kerberos. The hash-based path is not a bolt-on; it is one of the credential forms the authentication layer accepts.

On top of MSRPC, the README documents portions or full implementations of a long list of interfaces: EPM, DTYPES, LSAD, LSAT, NRPC, RRP, SAMR, SRVS, WKST, SCMR, BKRP, DHCPM, EVEN6, MGMT, SASEC, TSCH, DCOM, WMI, OXABREF, NSPI and OXNSPI. TDS (MSSQL) and LDAP are described as partial implementations, which is worth reading literally. Partial means some operations are covered and others are not, and the README does not enumerate the boundary.

The SMBv1 and NetBIOS support is credited to Pysmb by Michael Teo, per the licensing section. That is a useful detail when you are tracing where a behaviour comes from.

Installing Impacket and Running a First Script

The README's quick start recommends pipx over pip for system-wide installations, and the stable release is installed by name:

bash
python3 -m pipx install impacket

After that, the example scripts land on your PATH. To work with unreleased changes, the README says to download the development version from the master branch, extract it, and install from the unpacked directory with `python3 -m pipx install .`.

The repository also ships a Dockerfile, so the alternative is to build and run the image. The build stage uses python:3.13-alpine, installs git, gcc, musl-dev, python3-dev, libffi-dev, openssl-dev and cargo, creates a virtualenv, clones the repository and installs it:

bash
docker build -t "impacket:latest" .
docker run -it --rm "impacket:latest"

The image's entrypoint is /bin/sh, so the second command drops you into a shell inside the container rather than running a tool directly. You then invoke the example scripts from that shell.

For a first real use, pick a script whose purpose is visible in its name and whose target you are authorised to touch. examples/GetADUsers.py, examples/GetUserSPNs.py, examples/GetNPUsers.py and examples/smbserver.py are all part of the examples/ directory in the repository. Each is a standalone demonstration of the library, and reading the script is the fastest way to see which classes it wires together. The README does not document per-script arguments, so the scripts themselves are the reference.

Where Impacket Stops Being the Right Tool

The most direct limitation is written into the project's own disclaimer. The information in the repository is for research and educational purposes and is not meant to be used in production environments or as part of commercial products. That is not boilerplate to skim past. It means the maintainers are not positioning this as a dependency you build a product on, and the README goes on to recommend applying a proper security development life cycle and secure coding practices, and generating and tracking indicators of compromise, if you use the code for your own purposes.

The second limitation is scope. TDS and LDAP are described as partial implementations. If your task depends on an LDAP or MSSQL operation the library does not cover, you will be extending the protocol implementation yourself, which is a different project from using it.

The third is versioning. The README distinguishes the latest stable release, v0.13.1, from the development version, v0.14.0-dev on the master branch. setup.py in the repository carries version 0.14.0.dev and appends a local version segment built from the git commit date, time and short hash when it is run inside a git checkout. Installing from master therefore gets you a version string tied to a commit, not a released number. That is fine for research and awkward for anything that needs reproducible dependency pinning.

Finally, the repository reports a NOASSERTION licence identifier. The README says the software is provided under a slightly modified version of the Apache Software License and points at the LICENSE file. Those two statements are not in conflict, but the identifier alone does not tell you the terms. Read the file.

Impacket Compared With Protocol-Specific Python Libraries

The realistic alternative depends on which slice of Impacket you were going to use. If you only need to read and write SMB shares from Python, a focused SMB client library gives you a higher-level file API and hides the packet layer. Impacket's SMB is a high-level implementation per the README, but it is still a protocol implementation, and the surrounding library expects you to think in terms of sessions, trees and RPC calls.

If you only need LDAP queries against Active Directory, a dedicated LDAP library is a better fit, because Impacket's LDAP support is explicitly partial. Note that Impacket itself depends on ldap3 and ldapdomaindump according to requirements.txt, so a pure-LDAP task may already be better served by one of those directly.

The difference in approach is the point. A protocol-specific client is built to complete one job and hide the wire format. Impacket is built to expose the wire format and let you complete jobs the client authors did not anticipate. That is why the same library spans SMB, MSRPC, Kerberos, LDAP, TDS and the DCOM and WMI interfaces layered on MSRPC. If your problem is one of the anticipated jobs, the focused client will be less work.

Maintenance, Release Cadence and Upgrade Cost

The repository is not archived, and the last push was on 2026-09-16, which is days before this writing. The release history shows impacket_0_13_1 on 2026-05-19, impacket_0_13_0 on 2025-10-22 and impacket_0_12_0 on 2024-09-16. That is roughly two releases in the two years before this one, with the most recent stable release a few months old. Development is visible on master as 0.14.0-dev, but the interval between stable tags is long enough that pinning to a release means accepting a slower stream of fixes.

Upgrade cost is dominated by the example scripts rather than the library. They are the interface most users touch, and the README offers no compatibility statement for their arguments across versions. If you have wrapped an example script in automation, a version bump is a chance for its flags to move. Pin the version and read ChangeLog.md before upgrading.

On licensing, the README describes a slightly modified Apache Software License and directs you to the LICENSE file, while the repository metadata reports NOASSERTION. The README also credits Pysmb by Michael Teo for SMBv1 and NetBIOS support, which matters if you are tracing provenance for a redistribution. None of this is legal advice; the LICENSE file is the document that governs.

Editorial conclusion

Adopt Impacket if you are writing Python that has to speak SMB, MSRPC, Kerberos or LDAP at packet level, or if the example scripts already match the research task in front of you. Do not adopt it as a production integration layer: the README states the code is for research and educational purposes and not meant for use in production environments or as part of commercial products. Before building on it, read the LICENSE file, since the repository reports a NOASSERTION licence identifier while the README describes a slightly modified Apache Software License, and confirm which Python versions the master branch supports, because the development build is 0.14.0-dev while the latest stable release is 0.13.1.

Frequently asked questions

What is Impacket in Python?

It is a collection of Python classes for working with network protocols, providing low-level programmatic access to packets and, for protocols such as SMB1-3 and MSRPC, the protocol implementation itself. It also ships a set of example scripts that demonstrate what the library can do.

Who owns Impacket?

The README states that Impacket was originally created by SecureAuth and is now maintained by Fortra's Core Security, and the package is published under the fortra organization on GitHub. The copyright line reads Fortra, LLC and its affiliated companies.

Is Impacket still maintained?

The repository is not archived and the last push was on 2026-09-16. The most recent stable release listed is impacket_0_13_1 from 2026-05-19, with development continuing on the master branch as v0.14.0-dev.

How do you install Impacket?

The README's quick start recommends pipx over pip and gives the command python3 -m pipx install impacket for the latest stable release. For unreleased changes, it says to download the master branch, extract the package and run python3 -m pipx install . from the unpacked directory.

How do you use Impacket?

The library is used by importing its protocol classes into your own Python code, and the examples/ directory shows how: each script wires the classes together for one task. The README does not document individual script arguments, so the scripts are the reference.

What is Impacket?

Impacket is a collection of Python classes for working with network protocols, originally created by SecureAuth and now maintained by Fortra's Core Security. It provides low-level programmatic access to packets and, for some protocols, the protocol implementation itself.

Official sources

  1. fortra/impacket on GitHub
  2. Issues
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/fortra-impacket.svg)](https://hysenlabs.com/projects/fortra-impacket)