Name Resolution Poisoning and SMB Relay

T1557.001

Sub-technique of T1557 Adversary-in-the-Middle.View on attack.mitre.org

About this technique

By responding to LLMNR/NBT-NS/mDNS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system. This activity may be used to collect or relay authentication materials.

Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) are Microsoft Windows components that serve as alternate methods of host identification. LLMNR is based upon the Domain Name System (DNS) format and allows hosts on the same local link to perform name resolution for other hosts. NBT-NS identifies systems on a local network by their NetBIOS name.

Multicast Domain Name System(mDNS) is a zero-configuration service used to resolve hostnames to IP addresses with “.local” as a top-level domain. MDNS is based upon Domain Name System (DNS) format and allows hosts on the same network segment to perform name resolution for other hosts, using multicast.

Adversaries can spoof an authoritative source for name resolution on a victim network by responding to LLMNR (UDP 5355)/NBT-NS (UDP 137)/mDNS (UDP 5353) traffic as if they know the identity of the requested host, effectively poisoning the service so that the victims will communicate with the adversary controlled system. If the requested host belongs to a resource that requires identification/authentication, the username and NTLMv2 hash will then be sent to the adversary controlled system. The adversary can then collect the hash information sent over the wire through tools that monitor the ports for traffic or through Network Sniffing and crack the hashes offline through Brute Force to obtain the plaintext passwords.

In some cases where an adversary has access to a system that is in the authentication path between systems or when automated scans that use credentials attempt to authenticate to an adversary controlled system, the NTLMv1/v2 hashes can be intercepted and relayed to access and execute code against a target system. The relay step can happen in conjunction with poisoning but may also be independent of it. Additionally, adversaries may encapsulate the NTLMv1/v2 hashes into various other protocols, such as LDAP, MSSQL and HTTP, to expand and use multiple services with the valid NTLM response.

Several tools may be used to poison name services within local networks such as NBNSpoof, Metasploit, and Responder.

Detection rules15

Rules on DetectionCode tagged with T1557.001.

Sigma10

Splunk5

RuleTypeRiskData source
DNS Kerberos CoercionTTPNULLSuricata, Sysmon EventID 22
Windows Credential Target Information Structure in CommandlineTTPNULLSysmon EventID 1
Windows Kerberos Coercion via DNSTTPNULLWindows Event Log Security 4662, Windows Event Log Security 5136, Windows Event Log Security 5137
Windows Short Lived DNS RecordTTPNULLWindows Event Log Security 5136, Windows Event Log Security 5137
Windows Theme File Creation in Unusual LocationAnomalyNULLSysmon EventID 11

Groups2

Software5

Campaigns0

None recorded.

Procedure examples7

Groups2

Used byProcedure example
GroupLazarus Group

Lazarus Group executed Responder using the command [Responder file path] -i [IP address] -rPv on a compromised host to harvest credentials and move laterally.

GroupWizard Spider

Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning.

Software5

Used byProcedure example
ToolEmpire

Empire can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks.

ToolImpacket

Impacket modules like ntlmrelayx and smbrelayx can be used in conjunction with Network Sniffing and Name Resolution Poisoning and SMB Relay to gather NetNTLM credentials for Brute Force or relay attacks that can gain code execution.

ToolPoshC2

PoshC2 can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks.

ToolPupy

Pupy can sniff plaintext network credentials and use NBNS Spoofing to poison name services.

ToolResponder

Responder is used to poison name services to gather hashes and credentials from systems within a local network.

References9

  1. BlackCat ransomware Open source
    Lucas Silva, Leandro Froes. (2022, April 18). An Investigation of the BlackCat Ransomware via Trend Micro Vision One. Retrieved February 2, 2026.
  2. GitHub NBNSpoof Open source
    Nomex. (2014, February 7). NBNSpoof. Retrieved November 17, 2017.
  3. GitHub Responder Open source
    Gaffie, L. (2016, August 25). Responder. Retrieved November 17, 2017.
  4. Rapid7 LLMNR Spoofer Open source
    Francois, R. (n.d.). LLMNR Spoofer. Retrieved November 17, 2017.
  5. Secure Ideas SMB Relay Open source
    Kuehn, E. (2018, April 11). Ever Run a Relay? Why SMB Relays Should Be On Your Mind. Retrieved February 7, 2019.
  6. TechNet NetBIOS Open source
    Microsoft. (n.d.). NetBIOS Name Resolution. Retrieved November 17, 2017.
  7. Wikipedia LLMNR Open source
    Wikipedia. (2016, July 7). Link-Local Multicast Name Resolution. Retrieved November 17, 2017.
  8. byt3bl33d3r NTLM Relaying Open source
    Salvati, M. (2017, June 2). Practical guide to NTLM Relaying in 2017 (A.K.A getting a foothold in under 5 minutes). Retrieved February 7, 2019.
  9. mDNS RFC Open source
    S. Cheshire, M. Krochmal. (2013, February). Multicast DNS. Retrieved February 2, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.