NBTscan

MITRE ATT&CK: S0590 View on attack.mitre.org

Aliases: NBTscan

Operating systems
windows, linux, macos
Profile updated
2026-07-07 12:55:03

Targeted industries: government-and-public-sector defense-and-aerospace

Context

NBTscan is an open source tool that has been used by state groups to conduct internal reconnaissance within a compromised network.

Detection coverage

  • 2 YARA rules
  • 82 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Remote System Discovery (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_INDICATOR_TOOL_SCN_Nbtscan (yara-rule)
  • SEKOIA_Hacktool_Nbtscan_Strings (yara-rule)

Reports & references

  • Mandiant — Apt39 Iranian Cyber Espionage Group Focused On Personal Information (report)
  • Broadcom/Symantec — Waterbug Espionage Governments (report)
  • MITRE ATT&CK — S0590 (report)
  • manpages.debian.org — Nbtscan.1.En (report)
  • sectools.org — Nbtscan (report)

External references