There and Back Again: An Operators Guide on NTLM Relaying Egress
SpecterOps details how attackers revive NTLM relay via coerced SMB egress when local escalation is blocked—a reminder that legacy authentication debt still creates real lateral-movement paths.
Summary written by editorial AI · Source link below
TL;DR – What’s old is new again. Remember coercing SMB NTLM egress tradecraft to crack challenge response back in the day? We see a lot of situations in our assessments where relaying NTLM from coerced network egress is ideal when escalating locally over C2 is unattainable or firewall rules are in play preventing WebDav relays […] The post There and Back Again: An Operators Guide on NTLM Relaying Egress appeared first on SpecterOps .
Editorial Analysis
Many European enterprises still carry NTLM legacy debt; this operator guide shows that coerced egress relay remains a practical escalation path even in hardened environments, reinforcing the case for full NTLM deprecation.
Audit outbound SMB/NTLM traffic at the firewall and accelerate NTLM deprecation plans where Kerberos or modern alternatives are available.
Legacy NTLM authentication continues to provide practical attack paths for privilege escalation, underscoring the need to accelerate protocol modernisation.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at SpecterOps in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul