LLMNR/NBT-NS Poisoning and SMB Relay
By responding to LLMNR/NBT-NS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system. This activity may be used to collect or relay authentication materials. Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) are Microsoft Windows components that serve as alternate methods of host identification. LLMNR is based upon the Domain Name System (DNS) format and allows hosts on the same ...
BY SOURCE
PROCEDURES (18)
Auto-extracted: 3 detections for network connection monitoring
Auto-extracted: 2 detections for privilege
Auto-extracted: 2 detections for base64
Auto-extracted: 1 detections for process creation monitoring
Auto-extracted: 1 detections for general monitoring
Auto-extracted: 1 detections for privilege
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for script execution monitoring
Auto-extracted: 1 detections for authentication monitoring
Auto-extracted: 1 detections for base64
Auto-extracted: 1 detections for inject
Auto-extracted: 1 detections for inject
Auto-extracted: 1 detections for inject
Auto-extracted: 1 detections for base64
Auto-extracted: 1 detections for dns
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for inject