Impacket

S0357

Tool.View on attack.mitre.org

About this tool

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1003.001
LSASS Memory

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.002
Security Account Manager

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.003
NTDS

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information from NTDS.dit.

T1003.004
LSA Secrets

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1040
Network Sniffing

Impacket can be used to sniff network traffic via an interface or raw socket.

T1047
Windows Management Instrumentation

Impacket's `wmiexec` module can be used to execute commands through WMI.

T1557.001
Name Resolution Poisoning and SMB Relay

Impacket modules like ntlmrelayx and smbrelayx can be used in conjunction with Network Sniffing and Name Resolution Poisoning and SMB Relay to gather NetNTLM credentials for Brute Force or relay attacks that can gain code execution.

T1558.003
Kerberoasting

Impacket modules like GetUserSPNs can be used to get Service Principal Names (SPNs) for user accounts. The output is formatted to be compatible with cracking tools like John the Ripper and Hashcat.

T1558.005
Ccache Files

Impacket tools – such as getST.py or ticketer.py – can be used to steal or forge Kerberos tickets using ccache files given a password, hash, aesKey, or TGT.

T1569.002
Service Execution

Impacket contains various modules emulating other service execution tools such as PsExec.

T1570
Lateral Tool Transfer

Impacket has used its `wmiexec` command, leveraging Windows Management Instrumentation, to remotely stage and execute payloads in victim networks.

Groups that use it18

Campaigns6

References1

  1. Impacket Tools Open source
    SecureAuth. (n.d.). Retrieved January 15, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.