logo

Mandiant Publishes Rainbow Tables That Crack NTLMv1 Admin Passwords 

ID: 7f000d44-093f-5858-8bde-11a779da66ad

STIX ID: report--7f000d44-093f-5858-8bde-11a779da66ad

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** Mandiant published precomputed rainbow tables for Net-NTLMv1 that dramatically lower the barrier to cracking Net-NTLMv1 hashes—allowing recovery of credentials in under 12 hours with consumer-grade hardware—and the report outlines the protocol's known cryptographic weaknesses, common coercion techniques (e.g., Responder, PetitPotam), and the realistic risk of full Active Directory compromise via recovered machine account hashes and subsequent DCSync operations; organizations are urged to disable Net-NTLMv1, enforce NTLMv2, and monitor authentication events for signs of exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.