Nltest is a legitimate Windows command-line utility that appears in intrusion activity as an administrative discovery tool rather than bespoke malware. The provided content associates Nltest with MITRE ATT&CK techniques for Domain Trust Discovery, Remote System Discovery, and System Network Configuration Discovery. It may be used to enumerate remote domain controllers with options such as /dclist and /dsgetdc. The content specifically notes its use by FIN8 with nltest.exe /dclist to enumerate hosts and retrieve a list of domain controllers, by HAFNIUM with nltest /dclist to enumerate domain controllers, by Wizard Spider alongside AdFind and PowerShell scripts to enumerate domain computers including the domain controller, and by Play as part of network enumeration activity. The content does not provide malware-style infection vectors or persistence behavior for Nltest itself, because it is presented as a native discovery utility used post-compromise within Windows/Active Directory enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows domain discovery utility used to enumerate domain/trust information during intrusions.
Nltest is a Windows command-line utility used to enumerate domain trusts, remote systems, and network configuration information.
A utility used to enumerate remote domain controllers and domain information.
Windows utility used to enumerate domain controllers and domain information; commonly abused for AD discovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.