THREAT OPS › Threat News › There and Back Again: An Operators Guide on NTLM Relaying Egress
There and Back Again: An Operators Guide on NTLM Relaying Egress
<p class="wp-block-paragraph"><strong><em>TL;DR</em></strong><em> – What’s old is new again. Remember coercing SMB NTLM egress tradecraft to crack challenge response back in the day? We see a lot of situations in our assessments where relaying NTLM from coerced network egress is ideal when escalating locally over C2 is unattainable or firewall rules are in play preventing WebDav relays to LD
MITRE ATT&CK techniques
Indicators of compromise
- https://tw1sm.github.io/2021-02-15-socks-relay/url
- http://dnstool.pyurl
- workstation.ludus.domain@ludus.domainemail
- administrator@ludus.domainemail
- administrator@workstation.ludus.domainemail
- 40.90.233.199ipv4
- s.w.orgdomain