Potential Impacket Execution

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This hunting query identifies execution of Impacket tool. Impacket is a popular tool used by attackers for remote service execution, Kerberos manipulation and Windows credential dumping.

Attribute Value
Type Hunting Query
Solution Attacker Tools Threat Protection Essentials
ID 24ae555c-5e33-4b5d-827a-44206e39f6b4
Tactics CredentialAccess
Techniques T1557.001, T1040, T1003.001, T1003.002, T1003.003, T1003.004, T1558.003
Required Connectors SecurityEvents, WindowsSecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SecurityEvent ?
WindowsEvent ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Attacker Tools Threat Protection Essentials