Analytics Informational

Potential NTLM Relay Attack

Multiple NTLM authentications were made to the same workstation and user from different IPs. This might indicate a potential NTLM Relay attack.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006) Lateral Movement (TA0008)
ATT&CK techniques: Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001) Use Alternate Authentication Material: Pass the Hash (T1550.002)
Attacker's goals:

The attacker is attempting a man-in-the-middle NTLM relay attack to intercept authentication attempts and move laterally within an environment.

Investigative actions:

Ensure that the alerted host is not a NAT device or proxy that replicates or forwards network traffic as part of its expected operational behavior. Check if the workstation supports weak, outdated versions of NTLM. Check for network activity to and from the suspicious IP address and workstation, to verify if they were compromised. Check for process activity to and from the suspicious IP address to verify if it was compromised. Check for changes in the network configurations, including indicators of poisoning attacks. Monitor closely the actions of the potentially compromised user account for any anomalous behavior.

Test period:
10 Minutes
Deduplication:
1 Day
3 variations:
  • NTLM Relay Attack using a sensitive user and a vulnerable package Medium (parent: Informational)
  • Potential NTLM Relay Attack using a vulnerable package Low (parent: Informational)
  • Potential NTLM Relay Attack using a sensitive user Low (parent: Informational)