BigHugger
sk Skill · mukul975

hunting-for-ntlm-relay-attacks

Detects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures, SMB signing status, and anomalous cross-domain authentication patterns. Use when investigating credential-relay activity in Active Directory or building detections for NTLM relay and coercion-based attacks.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
PythonT1557.001credential-accessSMB-signingActive-DirectoryResponderNTLMSSPEvent-4624Windows-eventsNTLM-relay
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python