Skip to content
← LibraryTechnique entry
T1557.001Credential Access

LLMNR/NBT-NS Poisoning and SMB Relay

Spoof name resolution to coerce victims to authenticate, then relay or crack the captured NetNTLMv2.

§ Where this technique fits

T1557.001 is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 7 approved dossiers in the registry, typically at step 3.3 on average.

Authoritative reference: attack.mitre.org/techniques/T1557/001/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Authentication Coercion
    AD-COERCE · Initial Access
    seen 1×
  2. 02
    Brute Force
    T1110 · Credential Access
    seen 1×
  3. 03seen 1×
  4. 04
    SCCM Client Push Installation Abuse
    AD-SCCM-CLIENTPUSH · Privilege Escalation
    seen 1×
  5. 05
    SMB/Windows Admin Shares
    T1021.002 · Lateral Movement
    seen 1×
  6. 06
    WSUS Update Injection (HTTP)
    AD-WSUS · Privilege Escalation
    seen 1×