Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

There and Back Again: An Operators Guide on NTLM Relaying Egress

SpecterOps details how attackers revive NTLM relay via coerced SMB egress when local escalation is blocked—a reminder that legacy authentication debt still creates real lateral-movement paths.

Summary written by editorial AI · Source link below

Filed by SpecterOps1 min readRead at source ↗

TL;DR – What’s old is new again. Remember coercing SMB NTLM egress tradecraft to crack challenge response back in the day? We see a lot of situations in our assessments where relaying NTLM from coerced network egress is ideal when escalating locally over C2 is unattainable or firewall rules are in play preventing WebDav relays […] The post There and Back Again: An Operators Guide on NTLM Relaying Egress appeared first on SpecterOps .

Editorial Analysis

Why it matters

Many European enterprises still carry NTLM legacy debt; this operator guide shows that coerced egress relay remains a practical escalation path even in hardened environments, reinforcing the case for full NTLM deprecation.

What to do

Audit outbound SMB/NTLM traffic at the firewall and accelerate NTLM deprecation plans where Kerberos or modern alternatives are available.

Board brief

Legacy NTLM authentication continues to provide practical attack paths for privilege escalation, underscoring the need to accelerate protocol modernisation.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at SpecterOps

External link — opens at SpecterOps in a new tab.

§
Continue with

More from the Threat Intel Desk