Hunt Ntlm Info

Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange. Anonymous NTLM Type-2 challenge capture leaks NetBIOS domain, internal DNS forest, computer name, AD timestamp via AV_PAIRS structure. Default Windows-installer hostnames (WIN-XXXXXXXXXXX pattern) signal lazy provisioning. Use when target advertises `WWW-Authenticate: NTLM` or `Negotiate` headers anonymously.

uphiago Updated

File contents

uphiago/recon-skills/tree/main/redteam/hunt-ntlm-info commit f2a33a64f1

Frequently asked questions

npx skillmds@latest add uphiago/hunt-ntlm-info