THREATOPS
THREAT OPSThreat News › There and Back Again: An Operators Guide on NTLM Relaying Egress

There and Back Again: An Operators Guide on NTLM Relaying Egress

medspecteropsPublished 2026-07-15

<p class="wp-block-paragraph"><strong><em>TL;DR</em></strong><em> &#8211; What’s old is new again. Remember coercing SMB NTLM egress tradecraft to crack challenge response back in the day? We see a lot of situations in our assessments where relaying NTLM from coerced network egress is ideal when escalating locally over C2 is unattainable or firewall rules are in play preventing WebDav relays to LD

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://specterops.io/blog/2026/07/15/there-and-back-again-an-operators-guide-on-ntlm-relaying-egress/