Impacket

MITRE ATT&CK: S0357 View on attack.mitre.org

Aliases: Impacket

First seen
2012-05-15 00:00:00
Malware type
credential-stealer, exploit-kit, spyware
Family
Malware family
Operating systems
linux, macos, windows
Profile updated
2026-07-07 15:33:13

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services professional-services

Context

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.

Detection coverage

  • 1 YARA rules
  • 260 Sigma rules

Malware & tools used

  • Name Resolution Poisoning and SMB Relay (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Kerberoasting (attack-pattern)
  • Ccache Files (attack-pattern)
  • NTDS (attack-pattern)
  • Service Execution (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Security Account Manager (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • LSA Secrets (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Hacktool_Impacket_Compiled_Binary (yara-rule)

Reports & references

  • MITRE ATT&CK — S0357 (report)
  • secureauth.com — Impacket (report)

External references