CTD-000165

AD domain allowing multicast name resolution (LLMNR)

Medium
Active Directory
Credential Access Discovery Lateral Movement
v15

Signature Identity

CTD-000165
Threat ID
15
Version
IOE
Indicator Type

Threat Description

Multicast Name Resolution (LLMNR) is a legacy protocol for name resolution in networks without DNS servers. In an Active Directory domain, LLMNR can expose the environment to spoofing and credential-harvesting attacks, such as responder attacks. Attackers can intercept and manipulate LLMNR requests to gain user credentials or redirect traffic.

Disabling LLMNR mitigates these security risks by preventing unauthorized interception of name resolution requests. However, this change may impact legacy applications or older systems that rely on LLMNR or NetBIOS for network communication.

MITRE ATT&CK: Attack Tactics

Credential Access Discovery Lateral Movement

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

  1. Open Group Policy Management (gpmc.msc).
  2. In the console tree, expand Forest > Domains.
  3. Expand your domain.
  4. Right-click the Default Domain Policy shortcut.
  5. Select Edit to open the Group Policy Management Editor window.
  6. Select Computer Configuration > Policies > Administrative Templates > Network > DNS Client.
  7. Set Turn off Multicast Name Resolution to Enabled.
  8. Apply the GPO by running the following command: gpupdate /force

Frequently Asked Questions

What does AD domain allowing multicast name resolution (LLMNR) mean?

Enabling LLMNR in an Active Directory domain allows devices without a DNS server to resolve names using Multicast Name Resolution. However, this also enables attackers to intercept and manipulate these requests.

The risk associated with LLMNR in an Active Directory domain is rated medium because it allows attackers to intercept DNS requests, but does not grant them administrative control. Attackers can use this information to plan more serious intrusions by gathering details about the environment.

Attackers can exploit LLMNR-enabled Active Directory domains by intercepting and manipulating DNS requests, which allows them to gather user credentials or redirect traffic. This can be used as a stepping stone for more severe attacks.

Cayosoft Guardian continuously monitors the state of LLMNR in Active Directory domains and flags it as a security issue when enabled, alerting administrators to potential risks.

Cayosoft Guardian helps mitigate the risk by providing visibility into LLMNR-enabled Active Directory domains, supporting investigation and response efforts to disable LLMNR and prevent attackers from intercepting and manipulating DNS requests.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure
Attack Tactics
Credential Access Discovery Lateral Movement
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical