logo

Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking

ID: c05e2f91-43dd-54fd-9e9b-b0dcb7750595

STIX ID: report--c05e2f91-43dd-54fd-9e9b-b0dcb7750595

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Mandiant (Google) published a comprehensive Net-NTLMv1 rainbow table dataset that makes recovering Net-NTLMv1-derived credentials feasible on consumer-grade hardware within hours, turning a decades-old cryptographic weakness into a practical high-impact attack vector; the report details the attack chain (coercion tools, preprocessing, cracking tools), detection (Event ID 4624 filtering for "LM"/"NTLMv1") and mitigation (disable Net-NTLMv1 / enforce NTLMv2), and warns organizations to prioritize remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.