NTLMquic
ID: 08345331-ddbc-54e5-8fac-58a933edd58f
STIX ID: report--08345331-ddbc-54e5-8fac-58a933edd58f
Feed Name: XPN Infosec Blog
Threat Score
This post explains and demonstrates SMB over QUIC (ALPN "smb" on UDP/443) on Windows 11/Server 2022, provides PoC server code (Go and msquic), and shows how attackers can terminate QUIC and relay it to TCP/445 to reuse existing tooling (ntlmrelayx), coerce authentication via RPC methods like PetitPotam, and bypass traditional TCP/445 network restrictions—highlighting certificate requirements and practical deployment considerations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
