LLMNR / NBT-NS poisoning
TL;DR
When Windows can’t resolve a name normally it falls back to broadcast protocols (LLMNR, NBT-NS, mDNS) that anyone on the network can answer. An attacker who answers can capture authentication material. The fix is to turn these fallbacks off and enforce SMB signing.
What it is
LLMNR and NBT-NS are legacy name-resolution fallbacks. If a machine mistypes a share name or DNS fails, it shouts “who is FILESERVR?” to the whole local network. Nothing verifies who answers.
How it works
A tool like Responder simply replies “that’s me” to those broadcasts. The victim then tries to authenticate to the attacker, handing over a challenge/response that can be taken away and cracked offline, or relayed onward. It’s one of the most reliable ways to get a first foothold on an internal test.
How to detect it
- Watch for hosts answering LLMNR/NBT-NS that shouldn’t be.
- Inject a canary name that doesn’t exist and alert if anything responds.
How to defend
- Disable LLMNR and NBT-NS via Group Policy — the single biggest win.
- Enforce SMB signing so captured authentication can’t simply be relayed.
Reference: MITRE ATT&CK T1557.001.