| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.002 Security Account Manager |
SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.003 NTDS |
SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information from NTDS.dit. |
| T1003.004 LSA Secrets |
SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1040 Network Sniffing |
Impacket can be used to sniff network traffic via an interface or raw socket. |
| T1047 Windows Management Instrumentation |
Impacket's `wmiexec` module can be used to execute commands through WMI. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
Impacket modules like ntlmrelayx and smbrelayx can be used in conjunction with Network Sniffing and Name Resolution Poisoning and SMB Relay to gather NetNTLM credentials for Brute Force or relay attacks that can gain code execution. |
| T1558.003 Kerberoasting |
Impacket modules like GetUserSPNs can be used to get Service Principal Names (SPNs) for user accounts. The output is formatted to be compatible with cracking tools like John the Ripper and Hashcat. |
| T1558.005 Ccache Files |
Impacket tools – such as |
| T1569.002 Service Execution |
Impacket contains various modules emulating other service execution tools such as PsExec. |
| T1570 Lateral Tool Transfer |
Impacket has used its `wmiexec` command, leveraging Windows Management Instrumentation, to remotely stage and execute payloads in victim networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.