NBTscan
MITRE ATT&CK: S0590 View on attack.mitre.org
Aliases: NBTscan
- Operating systems
- windows, linux, macos
- Profile updated
- 2026-07-07 12:55:03
Targeted industries: government-and-public-sector defense-and-aerospace
Context
NBTscan is an open source tool that has been used by state groups to conduct internal reconnaissance within a compromised network.
Detection coverage
- 2 YARA rules
- 82 Sigma rules
Malware & tools used
- System Owner/User Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Network Sniffing (attack-pattern)
- Network Service Discovery (attack-pattern)
- Remote System Discovery (attack-pattern)
Used by threat actors
- Threat Group-3390 (threat-actor)
- Lotus Blossom (threat-actor)
- Earth Lusca (threat-actor)
- Tonto Team (threat-actor)
- Mustang Panda (threat-actor)
- Turla (threat-actor)
- Agrius (threat-actor)
- APT39 (threat-actor)
- GALLIUM (threat-actor)
- BackdoorDiplomacy (threat-actor)
Detection rules
- DITEKSHEN_INDICATOR_TOOL_SCN_Nbtscan (yara-rule)
- SEKOIA_Hacktool_Nbtscan_Strings (yara-rule)
Reports & references
- Mandiant — Apt39 Iranian Cyber Espionage Group Focused On Personal Information (report)
- Broadcom/Symantec — Waterbug Espionage Governments (report)
- MITRE ATT&CK — S0590 (report)
- manpages.debian.org — Nbtscan.1.En (report)
- sectools.org — Nbtscan (report)