IPv6 attacks: How to harden active directory
ID: 5442884b-e958-52fb-aec0-6d3e10b32cf1
STIX ID: report--5442884b-e958-52fb-aec0-6d3e10b32cf1
Feed Name: ThreatLocker Blog
This article outlines how adversaries can exploit default or unmanaged IPv6 settings to conduct MITM attacks against Active Directory—intercepting NTLM authentication via tools like mitm6 and ntlmrelayx to potentially create domain accounts—and provides mitigations including disabling unused IPv6 and WPAD, enforcing LDAP and SMB signing, and leveraging a configuration policy to disable IPv6 across the environment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
