NBTscan is an open source tool that has been used by state groups to conduct internal reconnaissance within a compromised network.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
NBTscan can be used to collect MAC addresses. |
| T1018 Remote System Discovery |
NBTscan can list NetBIOS computer names. |
| T1033 System Owner/User Discovery |
NBTscan can list active users on the system. |
| T1040 Network Sniffing |
NBTscan can dump and print whole packet content. |
| T1046 Network Service Discovery |
NBTscan can be used to scan IP networks. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.