LLMNR/NBT-NS poisoning to an SMB relay foothold
Answering broadcast name-resolution queries captures Windows authentication, which is then relayed to a host that lacks SMB signing — a foothold without cracking a single password.
Scenario
An authorized internal engagement with a foothold on the LAN (a drop box or VLAN port). The objective is to show whether broadcast name resolution and missing SMB signing let captured authentication be relayed into access.
- 1
Collection
Poison broadcast name resolution
When a client mistypes a share or DNS fails, Windows falls back to LLMNR/NBT-NS broadcasts. Answer those queries so clients authenticate to you, capturing NetNTLM material — passively, without touching the client.
DetectionA host answering LLMNR/NBT-NS for many names, and unexpected authentication to a non-server workstation, are strong signals.
MitigationDisable LLMNR and NBT-NS via policy and rely on DNS, which removes the poisonable fallback entirely.
- 2
Credential Access
Coerce more authentication
Where in scope, nudge clients or services into authenticating (for example via a UNC path reference) to broaden the set of captured identities, documenting what responded.
DetectionSpikes in authentication to an unexpected host, and access attempts to crafted UNC paths, show in logs.
MitigationRestrict outbound SMB, filter crafted UNC references, and alert on forced-authentication patterns.
- 3
Lateral Movement
Relay the authentication to a host
T1557.001 Adversary-in-the-Middle: Name Resolution Poisoning and SMB RelayT1021.002 Remote Services: SMB/Windows Admin SharesRather than crack the hash, relay the captured NetNTLM to a target that does not enforce SMB signing, authenticating as the victim and gaining access to that host — the finding is the missing signing, not the password.
DetectionAuthentication arriving from a relay host (source mismatch) and new admin sessions on the target are detectable with logon auditing.
MitigationEnforce SMB signing everywhere, enable Extended Protection for Authentication, and tier administrative accounts.
- 4
Credential Access
Expand from the foothold
Where the relayed identity has local admin, demonstrate that further credentials could be recovered from memory to show the blast radius, then document for clean-up.
DetectionAccess to LSASS and new credential use across hosts are high-value alerts for EDR.
MitigationCredential Guard, LSASS protection, least-privilege local admin, and LAPS for unique local passwords.
Key takeaways
- Relaying beats cracking: with SMB signing off, captured authentication is used directly — no password needed.
- Disabling LLMNR/NBT-NS removes the poisoning fallback; enforcing SMB signing removes the relay target.
- Unique local-admin passwords (LAPS) and tiering stop one relayed host from becoming many.