Impacket - Tool

Threat entity extracted from intelligence sources

Frequency
25
occurrences
First Seen
November 5, 2025
Last Seen
July 4, 2026

Impacket is a tool tracked across 21 threat clusters and 25 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity July 4, 2026.

Overview

Impacket is an open-source Python toolkit that provides low-level access to Windows network protocols (SMB, NTLM, Kerberos) through scriptable utilities (e.g., psexec.py, secretsdump.py, ntlmrelayx). It is widely used for credential dumping, lateral movement, and post-exploitation, with particular relevance to Kerberos delegation and NTLM authentication, making it a prominent tool in both security testing and threat actor workflows.

Related Threat Clusters

Recent Intelligence Reports

  • T1021 — attack.mitre.org · July 4, 2026
  • PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on ... — Gbhackers · June 30, 2026
  • G0129 — attack.mitre.org · June 29, 2026
  • Operation Escaneo Signals Shift in LatAm Threat Landscape — Darkreading · June 18, 2026
  • Operation Escaneo: Infrastructure Exposure, TTP Analysis, and Attribution Assessment of an ... — Cloudsek · June 17, 2026
  • Rapid7 Analysis: CVE-2021-34527 "PrintNightmare" — Rapid7 · June 17, 2026
  • Webworm: New burrowing techniques — Welivesecurity · May 20, 2026
  • Bitdefender uncovers FamousSparrow attacks on Azerbaijan energy sector using DLL ... — Industrialcyber.Co · May 14, 2026

CVSS v3.1 Breakdown