Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0462 — Detect LLMNR/NBT-NS Poisoning and SMB Relay on Windows
DET0462

Detect LLMNR/NBT-NS Poisoning and SMB Relay on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1274 Analytic 1274
Windows

Detects anomalous network traffic on UDP 5355 (LLMNR) and UDP 137 (NBT-NS) combined with unauthorized SMB relay attempts, registry modifications re-enabling multicast name resolution, or suspicious service creation indicative of adversary-in-the-middle credential interception.

WinEventLog:Security EventCode=4697 WinEventLog:Security Registry key modification HKLM\Software\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast NSM:Flow Unusual responses to LLMNR (UDP 5355) or NBT-NS (UDP 137) queries from unauthorized hosts NSM:Flow Abnormal SMB authentication attempts correlated with poisoned LLMNR/NBT-NS sessions
[TrustedResponderList] Defines expected LLMNR/NBT-NS responders to tune out legitimate services.
[TimeWindow] Correlation period for linking poisoned name resolution with SMB relay attempts.
[SMBServiceBaseline] Normal services and SMB relay patterns in the enterprise environment.

Detected Techniques

1

Details

MITRE ID
DET0462
STIX ID
x-mitre-detection-strategy--2db51eaa-3407-4ad0-a45e-86ebf5f2abac
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.