sk Skill · mukul975
hunting-for-ntlm-relay-attacks
Detects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures, SMB signing status, and anomalous cross-domain authentication patterns. Use when investigating credential-relay activity in Active Directory or building detections for NTLM relay and coercion-based attacks.
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
PythonT1557.001credential-accessSMB-signingActive-DirectoryResponderNTLMSSPEvent-4624Windows-eventsNTLM-relay
- Host repository
- mukul975/Anthropic-Cybersecurity-Skills
- Version
- 1.0
- Licence
- Apache-2.0
- Host stars
- 33k
- Host language
- Python