NTLM Authentication Attacks: From Pass-the-Hash, NTLM Relay, and Forced Authentication to LLMNR/NBT-NS Poisoning
A comprehensive map of attacks targeting NTLM authentication in on-premises Active Directory environments: LLMNR/NBT-NS poisoning and NetNTLM hash harvesting (Responder), forced authentication (PetitPotam MS-EFSRPC/CVE-2021-36942, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM, ShadowCoerce), NTLM relay (SMB→LDAP/LDAPS/ADCS ntlmrelayx chain), Pass-the-Hash, NTLMv1 downgrade, and countermeasures (SMB signing, EPA, LDAP channel binding, Protected Users, mitm6). The detection-prevention triad for SOC, DFIR, and red/purple teams.
Active exploitation warning
The following vulnerabilities referenced in this content are under active exploitation in the CISA KEV catalog:
Source: CISA KEV ·
Swipe or use the arrows to move between sections
Zafiyet (Vulnerability)
Tehdit bağlamı, zafiyet ve istismar senaryosu
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Prevention & Hardening
Savunma teknolojileri, policy ve sertleştirme
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Detection
Davranış, loglama ve detection kuralları
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →