1200KM / tool
Impacket — Attack Tool
Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Impacket
Existing author guides
No reviewed association in this snapshot.
Primary documentation
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT29 · G0016 · Pinned relationship source (relationship--d430bf8d-cbe9-4f0d-8040-7f7d66fcc204)
- Threat Group-3390 · G0027 · Pinned relationship source (relationship--565f6cdf-e29b-430d-8b42-e0b0b93fa994)
- Lotus Blossom · G0030 · Pinned relationship source (relationship--529664ab-4c44-4608-91e9-65dde54d0865)
- Sandworm Team · G0034 · Pinned relationship source (relationship--e4c6b2e0-e644-4bb6-b2d0-f5a757ed9485)
- Dragonfly · G0035 · Pinned relationship source (relationship--68ece5ad-73bd-4562-ac08-877bd1e18f79)
- menuPass · G0045 · Pinned relationship source (relationship--d61f5cc3-e075-4a5b-ac7c-e77feac1d310)
- Magic Hound · G0059 · Pinned relationship source (relationship--205c5e6d-90c1-4369-98ee-9968f87d687c)
- FIN8 · G0061 · Pinned relationship source (relationship--febe1cf5-d8b5-4218-b32d-1e9ea10eab7f)
- APT41 · G0096 · Pinned relationship source (relationship--2479e29e-c1a3-4cc9-b059-b3e15ac44428)
- HAFNIUM · G0125 · Pinned relationship source (relationship--4fd56621-eb11-43b9-b90f-e6739af43660)
- Mustang Panda · G0129 · Pinned relationship source (relationship--640596c4-55d0-4d7d-a734-b4cfb864c9f5)
- Ember Bear · G1003 · Pinned relationship source (relationship--e7169878-e45d-40ec-a579-6dd12d710cc3)
- FIN13 · G1016 · Pinned relationship source (relationship--055b4a0f-99aa-4d61-9aa4-a48fff427eb3)
- Volt Typhoon · G1017 · Pinned relationship source (relationship--c93cacac-5ecf-49cb-8377-18e319545329)
- Cinnamon Tempest · G1021 · Pinned relationship source (relationship--ad9f56c2-efb9-421e-99f5-d82396f89440)
- Storm-1811 · G1046 · Pinned relationship source (relationship--7a5d3c81-084a-413f-b696-8d7753a40e14)
- Velvet Ant · G1047 · Pinned relationship source (relationship--f1db30cc-c6c0-4ffd-8896-ff6beecae653)
- Storm-0501 · G1053 · Pinned relationship source (relationship--03fb981b-6ee6-4490-ab5d-d671691abdf6)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1003.002 · Security Account Manager · Detection rules & anomalies
- T1003.003 · NTDS · Detection rules & anomalies
- T1003.004 · LSA Secrets · Detection rules & anomalies
- T1040 · Network Sniffing · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1557.001 · Name Resolution Poisoning and SMB Relay · Detection rules & anomalies
- T1558.003 · Kerberoasting · Detection rules & anomalies
- T1558.005 · Ccache Files · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
- T1570 · Lateral Tool Transfer · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Cloud Service Modification · DC0069
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Share Access · DC0102
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- Process Access · DC0035
- Process Creation · DC0032
- Service Creation · DC0060
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- Volume Creation · DC0097
- WMI Creation · DC0008
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.