Hunting For Ntlm Relay Attacks

Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.

theheavenlyd3mon 80d78aa 4 files · 30.1 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/hunting-for-ntlm-relay-attacks commit 80d78aa83f

Frequently asked questions

npx skillmds add theheavenlyd3mon/hunting-for-ntlm-relay-attacks