logo

Practical Attacks against NTLMv1

ID: 63684a24-f36b-500c-a368-6f9a528c446d

STIX ID: report--63684a24-f36b-500c-a368-6f9a528c446d

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

#### Executive Summary This technical blog details practical exploitation techniques against environments that allow NTLMv1, describing two attack chains — (1) authentication downgrade to capture/crack NTLMv1 hashes and craft Silver Tickets for privilege escalation and DCSync, and (2) LDAP relay with MIC removal to perform RBCD or Shadow Credentials attacks to impersonate domain accounts and extract NT hashes or perform DCSync; it includes tool commands, prerequisites, and recommends disabling NTLMv1 (enforcing NTLMv2) as the primary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.