Skip to main content
AD Academy
Advanced Protocols and Infrastructure
Advanced13 minLast updated: Topic 1 of 4

NTLM — the old protocol that's still alive

Challenge-Response, why it's weak, and how to mitigate it.

Not read

What you will learn here

  • How Challenge-Response works
  • Why NTLM is considered weak
  • How to reduce its use

is an old authentication protocol that's still active in almost every domain. It works via Challenge-Response: the server sends a challenge, the client encrypts it with the password's Hash.

  • No full Mutual Authentication — the client doesn't really verify the server's identity.
  • Vulnerable to Relay: an attacker forwards your authentication to another server on your behalf.
  • The Hash is equivalent to the password — hence .
# Documenting NTLM usage before blocking (Audit)
# GPO: Network security: Restrict NTLM: Audit NTLM authentication in this domain
Get-WinEvent -LogName "Microsoft-Windows-NTLM/Operational" -MaxEvents 50

# Enforcing SMB signing - central protection against Relay
Set-SmbServerConfiguration -RequireSecuritySignature $true -Force
powershell
Architecture and Theory — Under the Hood

is Challenge/Response: the server sends a challenge, the client encrypts it with the password's hash and returns it. There is no KDC, no tickets — therefore no way to prevent Relay at the protocol level.

  • NTLMv1 — completely broken (DES). Must be blocked.
  • NTLMv2 — more robust, but still vulnerable to Relay and offline cracking.
  • + Signing/Channel Binding = the primary protection against Relay.
Practical Configuration (PowerShell / GUI)
# NTLM Monitoring Before Blocking (GPO)
# Computer > Security Settings > Local Policies > Security Options:
#   Network security: Restrict NTLM: Audit Incoming NTLM Traffic = Enable auditing for all accounts
# Check Event 8001-8004 in Applications and Services Logs > Microsoft > Windows > NTLM

# NTLMv1 Blocking
# LmCompatibilityLevel = 5 (Send NTLMv2 response only. Refuse LM & NTLM)
powershell
Real-world organizational scenarios
  • SMB Relay from a fake printer to a DC — a classic PetitPotam/PrinterBug.
  • Old internal applications do not support — require + host header.
Troubleshooting
  • Event 4624 Auth Package = when the target is FQDN → likely missing .
  • Event 4625 Sub Status 0xC000006A = incorrect password.
  • Restrict Events 8001-8004 show NTLM source/target.
Glossary and Quick Command Line
  • Challenge/Response.
  • NetNTLMv2 — the format cracked by hashcat mode 5600.
  • PetitPotam — a famous relay technique.

Check yourself

Which protection significantly reduces NTLM Relay?

Was this page helpful?