NTLM Relay
Windows Authentication
NTLM Authentication Mechanism




LLMNR & NBT-NS Poisoning

Responder
NTLM Cracking
NTLMv1 (Net-NTLMv1) Crack
NTLMv2 (Net-NTLMv2) Crack
NTLM Relaying
Responder with SMB & HTTP Disabled (in Responder.conf)

Determine the machines that have SMB signing disabled

Powershell Reverse Encoded Shell
Run ntlmrelayx.py script and pass to it the encoded reverse shell.
Metasploit multi handler to receive the shell.
Overall Process Overview

Last updated