← All walkthroughs

LLMNR/NBT-NS poisoning to an SMB relay foothold

Answering broadcast name-resolution queries captures Windows authentication, which is then relayed to a host that lacks SMB signing — a foothold without cracking a single password.

On-prem Windows / Active Directory LAN Intermediate Active DirectoryNetworkRelay
Authorized testing only. This is a conceptual, defensive-aware walkthrough that maps an attack path to MITRE ATT&CK, detection and mitigation, and links to references for the detail. It is not a copy-paste playbook. Use it only against systems you own or are explicitly permitted to test.

Scenario

An authorized internal engagement with a foothold on the LAN (a drop box or VLAN port). The objective is to show whether broadcast name resolution and missing SMB signing let captured authentication be relayed into access.

  1. 1

    Collection

    Poison broadcast name resolution

    When a client mistypes a share or DNS fails, Windows falls back to LLMNR/NBT-NS broadcasts. Answer those queries so clients authenticate to you, capturing NetNTLM material — passively, without touching the client.

    Detection

    A host answering LLMNR/NBT-NS for many names, and unexpected authentication to a non-server workstation, are strong signals.

    Mitigation

    Disable LLMNR and NBT-NS via policy and rely on DNS, which removes the poisonable fallback entirely.

  2. 2

    Credential Access

    Coerce more authentication

    Where in scope, nudge clients or services into authenticating (for example via a UNC path reference) to broaden the set of captured identities, documenting what responded.

    Detection

    Spikes in authentication to an unexpected host, and access attempts to crafted UNC paths, show in logs.

    Mitigation

    Restrict outbound SMB, filter crafted UNC references, and alert on forced-authentication patterns.

    References responder · ntlm-relay
  3. 3

    Lateral Movement

    Relay the authentication to a host

    Rather than crack the hash, relay the captured NetNTLM to a target that does not enforce SMB signing, authenticating as the victim and gaining access to that host — the finding is the missing signing, not the password.

    Detection

    Authentication arriving from a relay host (source mismatch) and new admin sessions on the target are detectable with logon auditing.

    Mitigation

    Enforce SMB signing everywhere, enable Extended Protection for Authentication, and tier administrative accounts.

    References ntlm-relay · impacket
  4. 4

    Credential Access

    Expand from the foothold

    Where the relayed identity has local admin, demonstrate that further credentials could be recovered from memory to show the blast radius, then document for clean-up.

    Detection

    Access to LSASS and new credential use across hosts are high-value alerts for EDR.

    Mitigation

    Credential Guard, LSASS protection, least-privilege local admin, and LAPS for unique local passwords.

    References mimikatz · bloodhound

Key takeaways

  • Relaying beats cracking: with SMB signing off, captured authentication is used directly — no password needed.
  • Disabling LLMNR/NBT-NS removes the poisoning fallback; enforcing SMB signing removes the relay target.
  • Unique local-admin passwords (LAPS) and tiering stop one relayed host from becoming many.