Top 2026 2FA & AiTM Detection: NTLM/Kerberos Relay Supporting On-Prem AiTM Posit
This rule detects activities indicative of an attacker attempting to establish an adversary-in-the-middle (AiTM) position within an on-premises network. It flags potential NTLM relay attempts (via loopback or invalid workstation indicators) and unauthorized name resolution spoofing (LLMNR/NBT-NS) used to intercept and relay authentication traffic for MFA bypass or credential theft.
Sigma

