Skip to content

Glossary

LLMNR poisoning

LLMNR poisoning answers broadcast name lookups on the local network to trick Windows hosts into sending NTLM authentication to an attacker.

When DNS cannot resolve a name, Windows falls back to multicast and broadcast protocols: Link-Local Multicast Name Resolution (LLMNR), NetBIOS Name Service (NBT-NS) and, on newer systems, mDNS. Any host on the same network segment can answer those queries. An attacker running a poisoning tool simply replies "that's me" to mistyped share names or stale drive mappings, and the victim then tries to authenticate — usually with NTLM. WPAD auto-proxy discovery can be abused in the same way to capture web authentication.

It matters because it is one of the most reliable first steps in an internal compromise: captured NTLMv2 responses can be cracked offline if passwords are weak, or relayed in real time to SMB, LDAP or AD CS endpoints that do not enforce signing or channel binding. Disable LLMNR through Group Policy, turn off NetBIOS over TCP/IP via DHCP or adapter settings, restrict mDNS where it is not needed, keep WPAD on the DNS global query block list, and enforce SMB and LDAP signing so relayed authentication fails.

See Disabling LLMNR, NBT-NS, mDNS and WPAD and Stop NTLM relay.