Hunting For Ntlm Relay Attacks

Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.

26zl Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/hunting-for-ntlm-relay-attacks commit f86bae30e7

Frequently asked questions

npx skillmds@latest add 26zl/hunting-for-ntlm-relay-attacks