Agent Skills: hunting-for-ntlm-relay-attacks

Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.

UncategorizedID: plurigrid/asi/hunting-for-ntlm-relay-attacks

Install this agent skill to your local

pnpm dlx add-skill https://github.com/plurigrid/asi/hunting-for-ntlm-relay-attacks

Skill Files

Browse the full folder contents for hunting-for-ntlm-relay-attacks.

Download Skill

Loading file tree…

Select a file to preview its contents.