{"id":"T1557.001","name":"Name Resolution Poisoning and SMB Relay","url":"https://attack.mitre.org/techniques/T1557/001","tactics":["credential-access","collection"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0462","stix_id":"x-mitre-detection-strategy--2db51eaa-3407-4ad0-a45e-86ebf5f2abac","name":"Detect LLMNR/NBT-NS Poisoning and SMB Relay on Windows","url":"https://attack.mitre.org/detectionstrategies/DET0462","analytics":[{"id":"AN1274","stix_id":"x-mitre-analytic--eb031858-bf91-476e-8248-2c54ef0f0864","name":"Analytic 1274","description":"Detects anomalous network traffic on UDP 5355 (LLMNR) and UDP 137 (NBT-NS) combined with unauthorized SMB relay attempts, registry modifications re-enabling multicast name resolution, or suspicious service creation indicative of adversary-in-the-middle credential interception.","url":"https://attack.mitre.org/detectionstrategies/DET0462#AN1274","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4697","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"Registry key modification HKLM\\Software\\Policies\\Microsoft\\Windows NT\\DNSClient\\EnableMulticast","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"NSM:Flow","channel":"Unusual responses to LLMNR (UDP 5355) or NBT-NS (UDP 137) queries from unauthorized hosts","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"NSM:Flow","channel":"Abnormal SMB authentication attempts correlated with poisoned LLMNR/NBT-NS sessions","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TrustedResponderList","description":"Defines expected LLMNR/NBT-NS responders to tune out legitimate services."},{"field":"TimeWindow","description":"Correlation period for linking poisoned name resolution with SMB relay attempts."},{"field":"SMBServiceBaseline","description":"Normal services and SMB relay patterns in the enterprise environment."}],"live":true,"detection_strategies":["DET0462"],"techniques":["T1557.001"]}],"live":true,"version":"1.0","techniques":["T1557.001"]}],"sigma_rules":[{"id":"0ed99dda-6a35-11ef-8c99-0242ac120002","title":"Attempts of Kerberos Coercion Via DNS SPN Spoofing","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-06-20","modified":null,"description":"Detects the presence of \"UWhRC....AAYBAAAA\" pattern in command line.\nThe pattern \"1UWhRCAAAAA..BAAAA\" is a base64-encoded signature that corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure.\nAttackers can use this technique to coerce authentication from victim systems to attacker-controlled hosts.\nIt is one of the strong indicators of a Kerberos coercion attack, where adversaries manipulate DNS records\nto spoof Service Principal Names (SPNs) and redirect authentication requests like in CVE-2025-33073.\nIf you see this pattern in the command line, it is likely an attempt to add spoofed Service Principal Names (SPNs) to DNS records,\nor checking for the presence of such records through the `nslookup` command.\n","references":["https://www.synacktiv.com/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025","https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.credential-access","attack.persistence","attack.privilege-escalation","attack.t1557.001","attack.t1187"],"path":"rules/windows/process_creation/proc_creation_win_kerberos_coercion_via_dns_spn_spoofing.yml","techniques":["T1557.001","T1187"],"cves":[]},{"id":"16f5d8ca-44bd-47c8-acbe-6fc95a16c12f","title":"RottenPotato Like Attack Pattern","author":"@SBousseaden, Florian Roth","status":"test","level":"high","date":"2019-11-15","modified":"2022-12-22","description":"Detects logon events that have characteristics of events generated during an attack with RottenPotato and the like","references":["https://twitter.com/SBousseaden/status/1195284233729777665"],"logsource":{"product":"windows","service":"security"},"tags":["attack.collection","attack.privilege-escalation","attack.credential-access","attack.t1557.001"],"path":"rules/windows/builtin/security/account_management/win_security_susp_rottenpotato.yml","techniques":["T1557.001"],"cves":[]},{"id":"4096842a-8f9f-4d36-92b4-d0b2a62f9b2a","title":"Potential PetitPotam Attack Via EFS RPC Calls","author":"@neu5ron, @Antonlovesdnb, Mike Remen","status":"test","level":"medium","date":"2021-08-17","modified":"2022-11-28","description":"Detects usage of the windows RPC library Encrypting File System Remote Protocol (MS-EFSRPC). Variations of this RPC are used within the attack refereed to as PetitPotam.\nThe usage of this RPC function should be rare if ever used at all.\nThus usage of this function is uncommon enough that any usage of this RPC function should warrant further investigation to determine if it is legitimate.\n View surrounding logs (within a few minutes before and after) from the Source IP to. Logs from from the Source IP would include dce_rpc, smb_mapping, smb_files, rdp, ntlm, kerberos, etc..'\n","references":["https://github.com/topotam/PetitPotam/blob/d83ac8f2dd34654628c17490f99106eb128e7d1e/PetitPotam/PetitPotam.cpp","https://msrc.microsoft.com/update-guide/vulnerability/ADV210003","https://vx-underground.org/archive/Symantec/windows-vista-network-attack-07-en.pdf","https://threatpost.com/microsoft-petitpotam-poc/168163/"],"logsource":{"product":"zeek","service":"dce_rpc"},"tags":["attack.collection","attack.credential-access","attack.t1557.001","attack.t1187"],"path":"rules/network/zeek/zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml","techniques":["T1557.001","T1187"],"cves":[]},{"id":"4627c6ae-6899-46e2-aa0c-6ebcb1becd19","title":"HackTool - Impacket Tools Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-07-24","modified":"2023-02-07","description":"Detects the execution of different compiled Windows binaries of the impacket toolset (based on names or part of their names - could lead to false positives)","references":["https://github.com/ropnop/impacket_static_binaries/releases/tag/0.9.21-dev-binaries"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.execution","attack.credential-access","attack.t1557.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_impacket_tools.yml","techniques":["T1557.001"],"cves":[]},{"id":"5588576c-5898-4fac-bcdd-7475a60e8f43","title":"Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-06-20","modified":null,"description":"Detects DNS queries containing patterns associated with Kerberos coercion attacks via DNS object spoofing.\nThe pattern \"1UWhRCAAAAA..BAAAA\" is a base64-encoded signature that corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure.\nAttackers can use this technique to coerce authentication from victim systems to attacker-controlled hosts.\nIt is one of the strong indicators of a Kerberos coercion attack, where adversaries manipulate DNS records\nto spoof Service Principal Names (SPNs) and redirect authentication requests like CVE-2025-33073.\n","references":["https://www.synacktiv.com/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025","https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html"],"logsource":{"product":"zeek","service":"dns"},"tags":["attack.collection","attack.credential-access","attack.persistence","attack.privilege-escalation","attack.t1557.001","attack.t1187"],"path":"rules/network/zeek/zeek_dns_kerberos_coercion_via_dns_object_spn_spoofing.yml","techniques":["T1557.001","T1187"],"cves":[]},{"id":"5589ab4f-a767-433c-961d-c91f3f704db1","title":"Potential SMB Relay Attack Tool Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-07-24","modified":"2023-02-14","description":"Detects different hacktools used for relay attacks on Windows for privilege escalation","references":["https://foxglovesecurity.com/2016/09/26/rotten-potato-privilege-escalation-from-service-accounts-to-system/","https://pentestlab.blog/2017/04/13/hot-potato/","https://github.com/ohpe/juicy-potato","https://hunter2.gitbook.io/darthsidious/other/war-stories/domain-admin-in-30-minutes","https://hunter2.gitbook.io/darthsidious/execution/responder-with-ntlm-relay-and-empire","https://www.localpotato.com/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.execution","attack.credential-access","attack.t1557.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_relay_attacks_tools.yml","techniques":["T1557.001"],"cves":[]},{"id":"679085d5-f427-4484-9f58-1dc30a7c426d","title":"WinDivert Driver Load","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-07-30","modified":"2024-11-23","description":"Detects the load of the Windiver driver, a powerful user-mode capture/sniffing/modification/blocking/re-injection package for Windows","references":["https://reqrypt.org/windivert-doc.html","https://rastamouse.me/ntlm-relaying-via-cobalt-strike/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.credential-access","attack.collection","attack.defense-impairment","attack.t1599.001","attack.t1557.001"],"path":"rules/windows/driver_load/driver_load_win_windivert.yml","techniques":["T1599.001","T1557.001"],"cves":[]},{"id":"bc2e25ed-b92b-4daa-b074-b502bdd1982b","title":"Local Privilege Escalation Indicator TabTip","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-10-07","modified":"2023-04-14","description":"Detects the invocation of TabTip via CLSID as seen when JuicyPotatoNG is used on a system in brute force mode","references":["https://github.com/antonioCoco/JuicyPotatoNG"],"logsource":{"product":"windows","service":"system"},"tags":["attack.collection","attack.execution","attack.credential-access","attack.t1557.001"],"path":"rules/windows/builtin/system/microsoft_windows_distributed_com/win_system_lpe_indicators_tabtip.yml","techniques":["T1557.001"],"cves":[]},{"id":"cd8c163e-a19b-402e-bdd5-419ff5859f12","title":"HackTool - ADCSPwn Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-07-31","modified":"2023-02-04","description":"Detects command line parameters used by ADCSPwn, a tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service","references":["https://github.com/bats3c/ADCSPwn"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.credential-access","attack.t1557.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_adcspwn.yml","techniques":["T1557.001"],"cves":[]},{"id":"e7a21b5f-d8c4-4ae5-b8d9-93c5d3f28e1c","title":"Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-06-20","modified":null,"description":"Detects DNS queries containing patterns associated with Kerberos coercion attacks via DNS object spoofing.\nThe pattern \"1UWhRCAAAAA..BAAAA\" is a base64-encoded signature that corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure.\nAttackers can use this technique to coerce authentication from victim systems to attacker-controlled hosts.\nIt is one of the strong indicators of a Kerberos coercion attack, where adversaries manipulate DNS records\nto spoof Service Principal Names (SPNs) and redirect authentication requests like CVE-2025-33073.\n","references":["https://www.synacktiv.com/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025","https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.collection","attack.credential-access","attack.persistence","attack.privilege-escalation","attack.t1557.001","attack.t1187"],"path":"rules/windows/dns_query/dns_query_win_kerberos_coercion_via_dns_object_spoofing.yml","techniques":["T1557.001","T1187"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-38035","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}