Skip to main content
LLMNR and NBT-NS Poisoning: NTLM Relay to SMB operation cover
COMING SOONIntermediatePRO

LLMNR and NBT-NS Poisoning: NTLM Relay to SMB

A workstation on the Vantara Solutions network mistyped a file server name. DNS had no answer. Windows broadcast the query over LLMNR -- and something on the network answered. Reconstruct the poisoning, the credential capture, and the relay that followed using SIEM events, endpoint telemetry, and a raw packet capture.

40m
7 tasks
50 points
Pro

Launches in 2 days

Sep 22, 2026

Tuesday, September 22, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMXDRQuery

What you'll investigate

7 objectives unlock when this operation goes live.

1Scope the incident
2Find the name that started the chain
3Find the relay destination
4Confirm the precondition that allowed relay
5Locate the captured hash on disk
6Identify the credential-extraction method
7Classify the poisoning and relay as a MITRE technique

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Sep 22, 2026, you can jump straight in.

Get Started Free