Responder/MultiRelay NTLM Relay & LLMNR/NBT-NS Poisoning Detection
Detects the execution of known network exploitation tools like Responder.py or MultiRelay.py, as well as unauthorized processes binding to ports used for LLMNR (UDP 5355) and NBT-NS (UDP 137), which are classic indicators of potential adversary-in-the-middle attacks.
SentinelOne

