NBTscan — Malware Profile
NBTscan is an open source tool that has been used by state groups to conduct internal reconnaissance within a compromised network.
MITRE ATT&CK techniques (5)
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1033 System Owner/User Discovery
- T1040 Network Sniffing
- T1046 Network Service Discovery
IntelFusions coverage
Attributed threat actors
- Agrius
- Worok machine-inferred link
- Earth Kurma machine-inferred link
- GALLIUM
- Mustang Panda
- APT39
- Turla
- Lotus Blossom
- BackdoorDiplomacy
- Tonto Team
- Earth Lusca
- APT27