hunting-for-ntlm-relay-attacks

mukul975/hunting-for-ntlm-relay-attacks · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 4.2 KB
  • 📁scripts
  • ⚙️agent.py 12.7 KB
  • 📄LICENSE 11.0 KB

Related

  1. detecting-ntlm-relay-with-event-correlation · mukul975 bundle
    Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, and auditing SMB and LDAP signing enforcement.
    24.6k
    repo stars
  2. hunting-evtx-with-chainsaw · mukul975 bundle
    Hunt for threats in Windows Event Logs using Chainsaw, a fast Rust-based forensic tool that runs Sigma rules, keyword searches, and artifact analysis offline.
    24.6k
    repo stars
  3. hunting-for-startup-folder-persistence · mukul975 bundle
    Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.
    24.6k
    repo stars
  4. hunting-for-registry-run-key-persistence · mukul975 bundle
    Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.
    24.6k
    repo stars
  5. detecting-living-off-the-land-with-lolbas · mukul975 bundle
    Detect abuse of legitimate Windows binaries (LOLBins) like certutil, regsvr32, mshta, and rundll32 using process telemetry, Sigma rules, and parent-child process analysis.
    24.6k
    repo stars
  6. hunting-for-unusual-service-installations · mukul975 bundle
    Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.
    24.6k
    repo stars

Frequently asked questions

How do I install the hunting-for-ntlm-relay-attacks skill?

Run npx skillmds add mukul975/hunting-for-ntlm-relay-attacks in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the hunting-for-ntlm-relay-attacks skill do?

Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain. It is listed under Security, Coding & Dev Tools, Incident Response, Vulnerability Scanning on SkillMD.

Is hunting-for-ntlm-relay-attacks safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with hunting-for-ntlm-relay-attacks?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is hunting-for-ntlm-relay-attacks free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published hunting-for-ntlm-relay-attacks?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.