logo

WSUS Is SUS: NTLM Relay Attacks in Plain Sight

ID: bd75961d-6a98-5a52-b3c6-6b48e4c7c7ef

STIX ID: report--bd75961d-6a98-5a52-b3c6-6b48e4c7c7ef

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-09-19

Date Updated: 2026-05-01

...
...

This report demonstrates how WSUS traffic (default ports 8530/8531) can be intercepted on a local network to capture machine and user NTLM hashes and enable NTLM relay attacks; it covers unauthenticated and authenticated enumeration, HTTP exploitation via ARP/DNS spoofing and ntlmrelayx, HTTPS interception by abusing AD CS templates to obtain trusted certificates, and defensive mitigations including HTTPS, AD CS hardening, and SMB/LDAP signing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.