Ntlm Relay Attacks

Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.

undermybelt Updated

File contents

undermybelt/hermes-skills/tree/main/skills/red-teaming/anthropic-cybersecurity-skills/skills/ntlm-relay-attacks commit 93c0fe688b

Frequently asked questions

npx skillmds@latest add undermybelt/ntlm-relay-attacks