There and Back Again: An Operators Guide on NTLM Relaying Egress
SpecterOps details how attackers revive NTLM relay via coerced SMB egress when local escalation is blocked—a reminder that legacy authentication debt still creates real lateral-movement paths.
Summary written by editorial AI · Source link below
TL;DR – What’s old is new again. Remember coercing SMB NTLM egress tradecraft to crack challenge response back in the day? We see a lot of situations in our assessments where relaying NTLM from coerced network egress is ideal when escalating locally over C2 is unattainable or firewall rules are in play preventing WebDav relays […] The post There and Back Again: An Operators Guide on NTLM Relaying Egress appeared first on SpecterOps .
Editorial Analysis
Many European enterprises still carry NTLM legacy debt; this operator guide shows that coerced egress relay remains a practical escalation path even in hardened environments, reinforcing the case for full NTLM deprecation.
Audit outbound SMB/NTLM traffic at the firewall and accelerate NTLM deprecation plans where Kerberos or modern alternatives are available.
Legacy NTLM authentication continues to provide practical attack paths for privilege escalation, underscoring the need to accelerate protocol modernisation.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at SpecterOps in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d