Relaying credentials everywhere with ntlmrelayx
ID: 86747a75-0e45-5182-825d-59b97f5a3d5d
STIX ID: report--86747a75-0e45-5182-825d-59b97f5a3d5d
Feed Name: Fox-IT blog
This Fox-IT blog explains how legacy NTLM authentication can be abused via relaying attacks using tools like ntlmrelayx to pivot captured credentials to SMB, LDAP, IMAP and MSSQL, demonstrates impacts including data access and domain compromise (including creating Domain Admin accounts), outlines common traffic sources and attack vectors (LLMNR/NBNS/WPAD and MITM), and recommends mitigations such as disabling NTLM, enabling SMB/LDAP signing, enforcing HTTPS, disabling WPAD/LLMNR/NBNS, and other hardening measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
