AN1274
Analytic 1274
Windows
Detects anomalous network traffic on UDP 5355 (LLMNR) and UDP 137 (NBT-NS) combined with unauthorized SMB relay attempts, registry modifications re-enabling multicast name resolution, or suspicious service creation indicative of adversary-in-the-middle credential interception.
WinEventLog:Security
EventCode=4697
WinEventLog:Security
Registry key modification HKLM\Software\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
NSM:Flow
Unusual responses to LLMNR (UDP 5355) or NBT-NS (UDP 137) queries from unauthorized hosts
NSM:Flow
Abnormal SMB authentication attempts correlated with poisoned LLMNR/NBT-NS sessions
[TrustedResponderList]
Defines expected LLMNR/NBT-NS responders to tune out legitimate services.
[TimeWindow]
Correlation period for linking poisoned name resolution with SMB relay attempts.
[SMBServiceBaseline]
Normal services and SMB relay patterns in the enterprise environment.