ATT&CKReferencesImpacket Tools

Impacket Tools

SecureAuth. (n.d.). Retrieved January 15, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.002
Security Account Manager
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.003
NTDS
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information from NTDS.dit.

T1003.004
LSA Secrets
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1040
Network Sniffing
ToolImpacket

Impacket can be used to sniff network traffic via an interface or raw socket.

T1047
Windows Management Instrumentation
ToolImpacket

Impacket's `wmiexec` module can be used to execute commands through WMI.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolImpacket

Impacket modules like ntlmrelayx and smbrelayx can be used in conjunction with Network Sniffing and Name Resolution Poisoning and SMB Relay to gather NetNTLM credentials for Brute Force or relay attacks that can gain code execution.

T1558.003
Kerberoasting
ToolImpacket

Impacket modules like GetUserSPNs can be used to get Service Principal Names (SPNs) for user accounts. The output is formatted to be compatible with cracking tools like John the Ripper and Hashcat.

T1569.002
Service Execution
ToolImpacket

Impacket contains various modules emulating other service execution tools such as PsExec.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.