Which attack involves an attacker capturing NTLM authentication traffic from a user and relaying it to another machine to gain unauthorized access?
NTLM Relay is the process of intercepting authentication requests and forwarding them to a target machine. If successful, the attacker gains access to the target host with the privileges of the authenticated user. This attack is highly effective against environments where SMB signing is not enforced on network servers.
Why this answer
NTLM Relay involves capturing authentication requests from a client and forwarding them to a target server. If the target server allows NTLM authentication and does not have protections like SMB signing enabled, the server will accept the relayed authentication as if it came from the original user. This allows the attacker to impersonate the user and execute commands or access files on the target server.
Exam trap
Candidates often confuse NTLM relaying with credential harvesting. Relaying is a real-time attack that forwards authentication traffic to a target, whereas harvesting involves offline cracking of captured hashes.