logo

Relaying credentials everywhere with ntlmrelayx

ID: 86747a75-0e45-5182-825d-59b97f5a3d5d

STIX ID: report--86747a75-0e45-5182-825d-59b97f5a3d5d

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2017-05-09

Date Updated: 2026-04-27

...
...

This Fox-IT blog explains how legacy NTLM authentication can be abused via relaying attacks using tools like ntlmrelayx to pivot captured credentials to SMB, LDAP, IMAP and MSSQL, demonstrates impacts including data access and domain compromise (including creating Domain Admin accounts), outlines common traffic sources and attack vectors (LLMNR/NBNS/WPAD and MITM), and recommends mitigations such as disabling NTLM, enabling SMB/LDAP signing, enforcing HTTPS, disabling WPAD/LLMNR/NBNS, and other hardening measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.