Active NTLM Relay / Pass-the-Hash / Coercion Response
Responds to detected active NTLM relay, forced authentication (PetitPotam/PrinterBug/DFSCoerce), or Pass-the-Hash chains with evidence-first containment, dismantling of relay persistence, and structural relay countermeasures.
Prepare
5 steps- Enable NTLM audit policies
Keep "Audit NTLM authentication in this domain" (EID 8004) and DC-level EID 4624 (LogonType 3, `AuthenticationPackageName=NTLM`) and AD 5136 (directory object change) auditing enabled
- Extract NTLM usage baseline and identify machine account NTLM targets
Identify expected NTLM targets for `DC$` and other machine accounts; unexpected targets are relay/coercion alarm triggers
- Audit ADCS Web Enrollment and LDAP EPA status
Check whether EPA (Extended Protection for Authentication) is enabled on installed AD CS servers, and whether LDAP channel binding and signing policies are enforced
- Document RBCD and MachineAccountQuota values
Record accounts with write access to `msDS-AllowedToActOnBehalfOfOtherIdentity` and the current `MachineAccountQuota` value; serves as a comparison point for persistence detection
- Have escalation and RACI ready
Destructive actions (account disable, machine account password rotation, bulk rotation) require AD owner + IR lead approval; plan the change ticket process in advance; identify affected service accounts and active sessions