Tool
Impacket
- First Reported
- Sep 8, 2025
- Latest Reported
- Sep 30, 2026
Reported Context (7)
- the actor reused those credentials through the organization’s VPN, then moved through RDP, SMB, and Impacket to achieve full domain compromise. ReliaQuest Report Tracks Top Attacker Techniques in June–August 2026
- and Security Account Manager (SAM) registry dumping, which was achieved via MS-SAMR calls through Impacket’s secretsdump.py. Through these methods, the agent obtained the NT hash of a local administrator account Darktrace Tests Show AI Agents Hacking Simulated Corporate Networks to Cheat
- Impacket for Pentester: tstool Using Impacket’s tstool to Control Windows Sessions and Hijack RDP Sessions
- were used as footholds into internal networks. The operator deployed a standalone Linux build of Impacket's secretsdump directly onto selected SonicWall appliances, enabling remote credential theft from Hunt.io Links UK Council Attack to SonicWall SMA1000 Exploitation Campaign
- Impacket for Pentester: SMBExec Impacket SMBExec: A Pentester’s Guide to Remote Windows Command Execution
CVE (2)
Malware (10)
People (12)
Threat Actors (8)
MITRE ATT&CK (73)
Vendors (13)
Products (31)
Tools (40)
Industries (9)
Countries (13)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.