CTD-000076

AD CS server vulnerable to NTLM relay attacks

High
Active Directory
Credential Access Privilege Escalation
v25

Signature Identity

CTD-000076
Threat ID
25
Version
IOC
Indicator Type

Threat Description

An NTLM relay attack exploits the NTLM challenge-response mechanism. A threat actor intercepts legitimate authentication requests and then forwards them to the server. The client who originally sent the request receives the appropriate challenges, but the threat actor intercepts the responses and forwards them to the server, which then authenticates the attacker rather than the person or device that made the request.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To prevent NTLM Relay Attacks on networks with NTLM enabled, follow mitigation steps described in KB5005413: Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS).

Frequently Asked Questions

What does AD CS server vulnerable to NTLM relay attacks mean?

AD CS server vulnerable to NTLM relay attacks means that an attacker can intercept and replay NTLM authentication requests, causing the server to authenticate the attacker instead of the intended user. This allows attackers to bypass NTLM authentication and gain unauthorized access.

This vulnerability is rated high severity because it enables attackers with network access to authenticate as legitimate users, potentially leading to unauthorized access to sensitive data. The attacker can then use this access to support later activity, such as lateral movement or data exfiltration.

Attackers can use this vulnerability to authenticate themselves as legitimate users by intercepting and replaying NTLM authentication requests. This allows them to access sensitive areas of the network, which can then be used to support later attacker activity, such as data theft or system compromise.

Cayosoft Guardian detects this vulnerability by monitoring Active Directory Certificate Services (AD CS) servers for insecure configurations and behavior, such as the use of NTLM authentication without secure settings. This allows administrators to identify potential vulnerabilities and take corrective action.

Cayosoft Guardian helps reduce the risk by monitoring AD CS server configurations, detecting potential vulnerabilities, and alerting administrators to enable them to take corrective action. This provides visibility into potential attack paths and enables administrators to respond quickly to prevent NTLM relay attacks.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical