• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    NTLM Relay Pass-the-Token Access Token Manipulation via SMB - T1134

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated Jun 30, 2026•0•0•2

    Detects anomalous SMB NTLM authentication traffic indicative of relay attacks, where an attacker intercepts an authentication request and relays it to another SMB service.

    Suricata

    Tags

    T1557.001 - LLMNR/NBT-NS Poisoning and SMB RelayT1187 - Forced AuthenticationTA0006 - Credential AccessTA0009 - CollectionNetwork Connection InboundAuthentication AttemptIDS IPS AlertWindowsNetwork GenericSuricata IDSSnort IDSWindows Smb ClientWindows Ntlm AuthTCPTrojan Activity

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?