Enumerating EPA Enforcement for MSSQL and HTTPS
ID: 918b440d-6a9b-56fe-851e-1a6af4f89d8d
STIX ID: report--918b440d-6a9b-56fe-851e-1a6af4f89d8d
Feed Name: SpecterOps Blog
The report presents a practical methodology and tooling (RelayInformer in Python and BOFs) to enumerate Extended Protection for Authentication (EPA) on MSSQL and HTTP/S services, enabling operators to determine whether NTLM relay attacks are viable before investing effort. It explains EPA fundamentals (channel vs service binding), highlights implementation nuances (MSSQL supports both bindings by default; IIS GUI typically protects only HTTPS via channel binding unless service binding is manually configured), and outlines error-driven tests to distinguish disabled/allowed/required enforcement states (some requiring valid credentials). The work complements existing LDAPS checks, improves offensive decision-making, and provides defender guidance to set EPA to allowed or required to reduce relay risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
