Practical Attacks against NTLMv1
ID: 63684a24-f36b-500c-a368-6f9a528c446d
STIX ID: report--63684a24-f36b-500c-a368-6f9a528c446d
Feed Name: TrustedSec blog
#### Executive Summary This technical blog details practical exploitation techniques against environments that allow NTLMv1, describing two attack chains — (1) authentication downgrade to capture/crack NTLMv1 hashes and craft Silver Tickets for privilege escalation and DCSync, and (2) LDAP relay with MIC removal to perform RBCD or Shadow Credentials attacks to impersonate domain accounts and extract NT hashes or perform DCSync; it includes tool commands, prerequisites, and recommends disabling NTLMv1 (enforcing NTLMv2) as the primary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
