Hunting For Ntlm Relay Attacks

Use when detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain. Use when detecting ntlm relay attacks by analyzing windows event 4624 logon.

oyi77 b00c2db 4.1 KB Updated 10 repo stars

File contents

oyi77/1ai-skills/tree/main/cybersecurity/_deprecated/hunting-for-ntlm-relay-attacks commit b00c2db1fd

Frequently asked questions

npx skillmds add oyi77/hunting-for-ntlm-relay-attacks