Hunting For Ntlm Relay Attacks

Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.

autohandai Updated

File contents

autohandai/community-skills/tree/main/hunting-for-ntlm-relay-attacks commit cefc2b632e

Frequently asked questions

npx skillmds@latest add autohandai-community-skills/hunting-for-ntlm-relay-attacks