Area 04 / 12
NTLM & Legacy Protocols
Relay attacks turn one unsigned protocol into domain compromise. This area enforces LDAP signing and channel binding, requires SMB signing, kills LLMNR/NBT-NS name poisoning, and moves NTLM from default-on to audited-and-restricted.
Start the pathLearning path
0/5 done- 01Stop NTLM relay: LDAP, SMB signing and LLMNRHarden LDAP signing, LDAP channel binding, SMB signing, and disable LLMNR/NBT-NS to shut down NTLM relay paths against domain controllers.
- 02Enforce LDAP signing and channel binding on DCsRoll out LDAP signing and channel binding with evidence: collect events 2887, 2889 and 3039, fix clients, then set LdapEnforceChannelBinding safely.
- 03Require SMB signing and disable SMBv1 domain-wideEnforce SMB signing on clients and servers, understand Windows 11 24H2 and Server 2025 defaults, audit SMBv1 use, and remove it without breaking file access.
- 04Audit and restrict NTLM in Active DirectoryA step-by-step NTLM reduction plan: audit with events 8001-8004, fix the causes, build an exception list, remove NTLMv1 and set LmCompatibilityLevel 5.
- 05Disable LLMNR, NBT-NS, mDNS and WPAD in ADRemove the name-resolution fallbacks attackers poison: disable LLMNR, NetBIOS and mDNS by GPO and DHCP, and block WPAD with the DNS global query block list.