Agent Skills: hunting-for-ntlm-relay-attacks
Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.
UncategorizedID: plurigrid/asi/hunting-for-ntlm-relay-attacks
165
Install this agent skill to your local
Skill Files
Browse the full folder contents for hunting-for-ntlm-relay-attacks.
Loading file tree…
Select a file to preview its contents.