Netskope Threat Labs

Impacket

ATP Sandbox Adv. HeuristicsAV

Impacket is a legitimate Python library for working with network protocols that security teams and cyberattackers both use to interact with Windows environments. Its example scripts handle tasks such as remote command execution, credential dumping, and file transfer over protocols like SMB, WMI, and Kerberos. Intrusion crews abuse the library heavily for lateral movement and credential access, which is why monitoring for its characteristic behaviors is essential in enterprise networks.

First seen
February 2022
Last seen
October 2026

11 techniques across 3 tactics.

TA0002 Execution

TA0006 Credential Access

TA0008 Lateral Movement

  • T1570Lateral Tool Transfer
Alert Name
Application.Impacket.A
Application.Impacket.C
Application.Impacket.E
Application.Python.Impacket.H
Application.Python.Impacket.J
Gen:Application.Impacket.1
Generic.Application.Impacket.1.0CAE3BB7
Generic.Application.Impacket.1.0D841E86
Generic.Application.Impacket.1.0EDB1966
Generic.Application.Impacket.1.1CC99DD3