Making SMB Accessible with NTLMquic
ID: 53259bc4-a1ba-5233-b991-2bb332c48dae
STIX ID: report--53259bc4-a1ba-5233-b991-2bb332c48dae
Feed Name: TrustedSec blog
This technical write-up demonstrates SMB over QUIC (SMB mapped to TLS/ALPN on UDP/443), including golang and msquic proof-of-concepts that terminate QUIC and relay SMB traffic to legacy tooling (e.g., ntlmrelayx). The author shows how this transport can be used over the Internet with valid certificates, how it may bypass TCP/445 filtering, and how RPC coercion (PetitPotam/AddUsersToFile) can trigger SMB-over-QUIC authentication attempts, highlighting attacker-relevant implications for credential relay and lateral access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
