BigHugger
sk Skill · mukul975

detecting-ntlm-relay-with-event-correlation

Detect NTLM relay attacks (T1557.001) by correlating Windows Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB/LDAP signing, and flagging NTLMv2-to-NTLMv1 downgrades. Use for hunting credential relay in NTLM-enabled AD, investigating auth-source anomalies, building SIEM correlation rules, or responding to PetitPotam/DFSCoerce/PrinterBug alerts.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
yamlsplthreat-huntingNTLM-relayevent-correlationResponderActive-DirectorykqlT1557.001Event-4624powershellPythonNTLM-downgradeSMB-signingLDAP-signingPetitPotam
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python