Forced Authentication

T1187

Technique.View on attack.mitre.org

About this technique

Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept.

The Server Message Block (SMB) protocol is commonly used in Windows networks for authentication and communication between systems for access to resources and file sharing. When a Windows system attempts to connect to an SMB resource it will automatically attempt to authenticate and send credential information for the current user to the remote system. This behavior is typical in enterprise environments so that users do not need to enter credentials to access network resources.

Web Distributed Authoring and Versioning (WebDAV) is also typically used by Windows systems as a backup protocol when SMB is blocked or fails. WebDAV is an extension of HTTP and will typically operate over TCP ports 80 and 443.

Adversaries may take advantage of this behavior to gain access to user account hashes through forced SMB/WebDAV authentication. An adversary can send an attachment to a user through spearphishing that contains a resource link to an external server controlled by the adversary (i.e. Template Injection), or place a specially crafted file on navigation path for privileged accounts (e.g. .SCF file placed on desktop) or on a publicly accessible share to be accessed by victim(s). When the user's system accesses the untrusted resource, it will attempt authentication and send information, including the user's hashed credentials, over SMB to the adversary-controlled server. With access to the credential hash, an adversary can perform off-line Brute Force cracking to gain access to plaintext credentials.

There are several different ways this can occur. Some specifics from in-the-wild use include:

* A spearphishing attachment containing a document with a resource that is automatically loaded when the document is opened (i.e. Template Injection). The document can include, for example, a request similar to file[:]//[remote address]/Normal.dotm to trigger the SMB request.
* A modified .LNK or .SCF file with the icon filename pointing to an external reference such as \\[remote address]\pic.png that will force the system to load the resource when the icon is rendered to repeatedly gather credentials.

Alternatively, by leveraging the EfsRpcOpenFileRaw function, an adversary can send SMB requests to a remote system's MS-EFSRPC interface and force the victim computer to initiate an authentication procedure and share its authentication details. The Encrypting File System Remote Protocol (EFSRPC) is a protocol used in Windows networks for maintenance and management operations on encrypted data that is stored remotely to be accessed over a network. Utilization of EfsRpcOpenFileRaw function in EFSRPC is used to open an encrypted object on the server for backup or restore. Adversaries can collect this data and abuse it as part of a NTLM relay attack to gain access to remote systems on the same internal network.

Detection rules13

Rules on DetectionCode tagged with T1187.

Sigma7

Splunk6

RuleTypeRiskData source
DNS Kerberos CoercionTTPNULLSuricata, Sysmon EventID 22
PetitPotam Network Share Access RequestTTPNULLWindows Event Log Security 5145
Windows Credential Target Information Structure in CommandlineTTPNULLSysmon EventID 1
Windows Kerberos Coercion via DNSTTPNULLWindows Event Log Security 4662, Windows Event Log Security 5136, Windows Event Log Security 5137
Windows Short Lived DNS RecordTTPNULLWindows Event Log Security 5136, Windows Event Log Security 5137
Windows Theme File Creation in Unusual LocationAnomalyNULLSysmon EventID 11

Groups2

Software1

Campaigns0

None recorded.

Procedure examples3

Groups2

Used byProcedure example
GroupDarkHydrus

DarkHydrus used Template Injection to launch an authentication window for users to enter their credentials.

GroupDragonfly

Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems.

Software1

Used byProcedure example
MalwareEnvyScout

EnvyScout can use protocol handlers to coax the operating system to send NTLMv2 authentication responses to attacker-controlled infrastructure.

References9

  1. Cylance Redirect to SMB Open source
    Cylance. (2015, April 13). Redirect to SMB. Retrieved December 21, 2017.
  2. Didier Stevens WebDAV Traffic Open source
    Stevens, D. (2017, November 13). WebDAV Traffic To Malicious Sites. Retrieved December 21, 2017.
  3. GitHub Open source
    topotam. (2021, July 18). PetitPotam. PoC tool to coerce Windows hosts to authenticate to other machines. Retrieved May 30, 2025.
  4. GitHub Hashjacking Open source
    Dunning, J. (2016, August 1). Hashjacking. Retrieved December 21, 2017.
  5. Microsoft Managing WebDAV Security Open source
    Microsoft. (n.d.). Managing WebDAV Security (IIS 6.0). Retrieved November 17, 2024.
  6. Osanda Stealing NetNTLM Hashes Open source
    Osanda Malith Jayathissa. (2017, March 24). Places of Interest in Stealing NetNTLM Hashes. Retrieved January 26, 2018.
  7. Rapid7 Open source
    Condon, Caitlin. (2022, April 24). PetitPotam: Novel Attack Chain Can Fully Compromise Windows Domains. Retrieved May 30, 2025.
  8. US-CERT APT Energy Oct 2017 Open source
    US-CERT. (2017, October 20). Alert (TA17-293A): Advanced Persistent Threat Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved November 2, 2017.
  9. Wikipedia Server Message Block Open source
    Wikipedia. (2017, December 16). Server Message Block. Retrieved December 21, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.