Impacket - Tool

Threat entity extracted from intelligence sources

Frequency
37
occurrences
First Seen
November 5, 2025
Last Seen
September 8, 2026

Impacket is an open-source Python toolkit that provides low-level access to Windows network protocols (SMB, NTLM, Kerberos) through scriptable utilities (e.g., psexec.py, secretsdump.py, ntlmrelayx).

Overview

Impacket is an open-source Python toolkit that provides low-level access to Windows network protocols (SMB, NTLM, Kerberos) through scriptable utilities (e.g., psexec.py, secretsdump.py, ntlmrelayx). It is widely used for credential dumping, lateral movement, and post-exploitation, with particular relevance to Kerberos delegation and NTLM authentication, making it a prominent tool in both security testing and threat actor workflows.

Related Threat Clusters

Recent Intelligence Reports

  • NTLMv1 DC Rainbow Tables: Domain Compromise — adscanpro.com · September 8, 2026
  • Financially Motivated Threat Actor Breeze Comet Targets Brazil — cloud.google.com · September 1, 2026
  • Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems — Thehackernews · September 1, 2026
  • CVE-2026-62911 Enables Pre-Auth RCE on Exchange Server — Socprime · August 31, 2026
  • Storm-0501 — attack.mitre.org · August 18, 2026
  • BlueHammer — www.cyderes.com · August 13, 2026
  • Gunra Ransomware Uses ChaCha20 and RSA-4096 Encryption — Socprime · August 12, 2026
  • Six Agencies Warn Gunra Ransomware Hacked MFA at Server Level; Linux Victims May ... — Techtimes · August 11, 2026

CVSS v3.1 Breakdown