Threat reportAdvisoryTL-2026-0009

Microsoft NTLM Phase-Out: Detection & Migration Guidance

mediumACTIVE

Microsoft NTLM Phase-Out (TL-2026-0009), also tracked as NTLM Relay, is a medium-severity advisory threat scored CVSS 6.5, first published 2026-02-02. It has no confirmed attribution, affects Microsoft Windows, maps to 29 MITRE ATT&CK techniques (T1003, T1003.003, T1018), and is covered by 17 detection rules and 36 indicators of compromise.

CVSS
6.5/10Medium
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
0Not attributed
Detection rules
17SPL · KQL · Sigma
IOCs
36Indicators of compromise

Key facts for TL-2026-0009

Threat ID
TL-2026-0009
Also known as
NTLM Relay, Pass-the-Hash, NTLM Deprecation
Severity
MEDIUM
CVSS
6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Status
ACTIVE
Category
ADVISORY
First published
Last reviewed
Attribution confidence
NONE
Motivation
Espionage
Target sectors
All Sectors, Enterprise, Government, Healthcare, Financial Services, Education
Target regions
Global
Detection rules
17
Indicators of compromise
36

Malware and tooling in Microsoft NTLM Phase-Out

Malware and tooling: Responder tool signatures: LLMNR poisoning + HTTP/SMB/MSSQL NTLM capture servers, ntlmrelayx.py — Impacket NTLM relay tool targeting SMB/LDAP/HTTP/MSSQL/ADCS

How Microsoft NTLM Phase-Out works

As Microsoft enforces NTLM deprecation across Windows environments (beginning Windows Server 2025 and Windows 11 24H2), organizations face a critical transition-period security gap where NTLM relay, downgrade, and pass-the-hash attacks intensify against remaining NTLM dependencies. This threat focuses on DETECTION and MONITORING guidance: how defenders identify residual NTLM usage, discover legacy application dependencies, detect active NTLM relay/downgrade attacks, and build security monitoring rules that protect the environment DURING the multi-year migration from NTLM to Kerberos/certificate-based authentication. The transition period (2025-2028) is the most dangerous phase — attackers know NTLM is being phased out and are accelerating exploitation before the window closes. Distinct from TL-0018 (migration planning/enterprise enforcement), this threat covers the defensive monitoring and attack detection dimension.

NTLM Detection & Monitoring During Deprecation: The Transition-Period Threat Surface

Why the Transition Period is the Most Dangerous Phase:

Microsoft's NTLM deprecation creates a paradox: the announcement signals to attackers that NTLM's days are numbered, accelerating exploitation of remaining NTLM dependencies before migration is complete. Organizations that have not yet migrated face concentrated attack pressure from adversaries racing to exploit NTLM before the window closes. Meanwhile, the migration itself introduces detection blind spots as authentication flows change.

NTLM Attack Surface — What Defenders Must Detect:

1. NTLM Relay Attacks (T1557.001): - Attacker intercepts NTLM authentication handshake and relays it to another service - Tools: Responder, ntlmrelayx, MultiRelay, PetitPotam, Inveigh - Targets: SMB, LDAP, LDAPS, HTTP, MSSQL, ADCS (ESC8 — web enrollment relay) - Detection: NTLM authentication where source IP ≠ expected client IP - Critical: NTLM relay to ADCS (Active Directory Certificate Services) enables domain escalation - PetitPotam forces domain controllers to authenticate to attacker-controlled SMB share

2. NTLM Downgrade Attacks: - Attacker forces NTLMv2 authentication to downgrade to NTLMv1 (weaker, crackable) - NTLMv1 uses DES encryption — crackable in hours on modern GPUs - Group Policy: LmCompatibilityLevel controls NTLMv1 vs NTLMv2 enforcement - Detection: Event ID 4624 with NtlmV1 in AuthenticationPackageName field - Any NTLMv1 in a modern environment = either misconfiguration or active downgrade attack

3. Pass-the-Hash (T1550.002): - Attacker uses captured NTLM hash directly for authentication without cracking - Tools: Mimikatz, CrackMapExec, Evil-WinRM, Impacket - NTLM hash extracted via LSASS dump, SAM database, DCSync, or network capture - Detection: NTLM LogonType 3 (network) from workstation to server with no preceding interactive logon - Kerberos migration eliminates PtH entirely — NTLM hash is useless against Kerberos-only systems

4. LLMNR/NBT-NS Poisoning (T1557.001): - Attacker responds to LLMNR (UDP 5355) and NBT-NS (UDP 137) broadcast queries - Victim sends NTLM credentials to attacker-controlled system - Tools: Responder, Inveigh — capture NTLMv2 hashes for offline cracking or relay - Detection: LLMNR/NBT-NS responses from non-DNS servers - Mitigation: Disable LLMNR and NBT-NS via GPO (first step in NTLM hardening)

5. Coerced Authentication (PetitPotam, PrinterBug, DFSCoerce): - Attacker forces a Windows service to authenticate to attacker-controlled share - PetitPotam: MS-EFSRPC → forces machine account NTLM auth - PrinterBug: MS-RPRN → forces print spooler NTLM auth - DFSCoerce: MS-DFSNM → forces DFS NTLM auth - ShadowCoerce: MS-FSRVP → forces file server NTLM auth - Detection: Outbound NTLM authentication from domain controllers/servers to workstation IPs

6. NTLM Hash Harvesting via Malicious Documents/Links: - UNC path in document (\\attacker\share) forces NTLM authentication - .URL, .LNK, .SCF files with UNC paths trigger automatic NTLM auth - Outlook preview pane rendering remote images triggers NTLM auth - Detection: Outbound SMB connections (port 445) to external/unusual IPs

Legacy NTLM Dependency Discovery:

Before disabling NTLM, organizations must discover what still requires it:

1. NTLM Authentication Auditing: - Enable: Audit Policy → Logon/Logoff → Audit Logon Events (Success + Failure) - Event ID 4624 with AuthenticationPackageName 'NTLM' = active NTLM usage - Windows Server 2025: NTLM audit mode logs all NTLM without blocking - Group Policy: Network security: Restrict NTLM → Audit all in this domain

2. Common Legacy NTLM Dependencies: - Older web applications using Windows Integrated Authentication (NTLM instead of Negotiate) - Legacy printers and multifunction devices using NTLM for scan-to-folder - Older NAS/SAN devices authenticating via NTLM - Non-domain-joined devices that can only use NTLM (not Kerberos) - Cross-forest trusts using NTLM when Kerberos trust is not configured - Legacy SQL Server instances using NTLM authentication - Third-party VPN clients using NTLM for Windows SSO - Custom line-of-business applications hardcoded for NTLM

3. NTLM Traffic Baseline: - Establish baseline NTLM authentication volume per service/application - Track NTLM reduction over time as migration progresses - Identify the 'NTLM long tail' — devices/apps that will be last to migrate - Goal: NTLM volume trending to zero, with exceptions documented and compensated

Transition-Period Detection Strategy:

Phase 1 (Audit): Enable NTLM auditing, discover all NTLM usage, baseline volume Phase 2 (Restrict): Block NTLM for new services, enforce Kerberos where possible Phase 3 (Detect): Deploy detection rules for NTLM relay/downgrade/PtH on remaining NTLM Phase 4 (Enforce): Block NTLM entirely, monitor for authentication failures Phase 5 (Verify): Confirm zero NTLM usage, disable NTLM at domain level

Windows Security Event IDs for NTLM Monitoring: - 4624: Successful logon (check AuthenticationPackageName for NTLM) - 4625: Failed logon (NTLM failures during migration = legacy dependency) - 4648: Explicit credential logon (NTLM explicit credential use) - 8001: NTLM authentication request in domain (Server 2025 audit) - 8002: NTLM authentication blocked (Server 2025 enforcement) - 8003: NTLM audit-only mode log (Server 2025 transition) - 4776: Domain controller credential validation (NTLM) - 4769: Kerberos service ticket requested (should increase as NTLM decreases)

MITRE ATT&CK techniques used in TL-2026-0009

credential-access

T1003 OS Credential Dumping; T1003.003 NTDS; T1040 Network Sniffing; T1110 Brute Force; T1187 Forced Authentication; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1556 Modify Authentication Process; T1557 Adversary-in-the-Middle; T1557.001 Name Resolution Poisoning and SMB Relay; T1649 Steal or Forge Authentication Certificates

discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1069 Permission Groups Discovery; T1087 Account Discovery

lateral-movement

T1021 Remote Services

collection

T1039 Data from Network Shared Drive

execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter

privilege-escalation

T1068 Exploitation for Privilege Escalation

defense-evasion

T1070 Indicator Removal; T1078 Valid Accounts; T1134 Access Token Manipulation; T1550 Use Alternate Authentication Material; T1550.002 Pass the Hash

persistence

T1098 Account Manipulation

impact

T1531 Account Access Removal

initial-access

T1566 Phishing

resource-development

T1588 Obtain Capabilities

Affected products and versions in Microsoft NTLM Phase-Out

  • Microsoft — Windows
    Vulnerable versions: All versions using NTLM authentication
    Fixed in: Versions with NTLM disabled and Kerberos enforced

Remediation for Microsoft NTLM Phase-Out

Patches

  • Windows Server 2025 — native NTLM audit and enforcement modes
  • Windows 11 24H2 — NTLM deprecation enforcement
  • KB5005413 — PetitPotam mitigation for ADCS NTLM relay

Immediate actions

  • Enable NTLM auditing domain-wide: Group Policy → Network Security: Restrict NTLM → Audit All in this domain
  • Deploy Event ID 4624 monitoring with AuthenticationPackageName='NTLM' filter to identify all NTLM usage
  • Disable LLMNR (GPO: Turn off Multicast Name Resolution) and NBT-NS (disable NetBIOS over TCP/IP on all NICs) immediately
  • Enable SMB signing on all systems: RequireSecuritySignature=True — prevents NTLM relay via SMB
  • Enable EPA (Extended Protection for Authentication) on all IIS/web services — prevents NTLM relay to HTTP/HTTPS

Workarounds

  • Network segmentation isolating legacy NTLM systems from Kerberos-only segments
  • IP-based restrictions on NTLM authentication — limit NTLM to specific legacy device IPs
  • Deploy honeypot NTLM services to detect relay attempts during transition
  • Monitor NTLM volume trend — should decrease steadily toward zero during migration

Longer-term hardening

  • Migrate all applications from NTLM to Kerberos or certificate-based authentication (3-phase approach: audit → restrict → enforce)
  • Deploy Windows Server 2025 NTLM audit mode to discover remaining NTLM dependencies before enforcement
  • Implement Credential Guard on all endpoints to protect NTLM hashes from LSASS extraction
  • Deploy LAPS (Local Administrator Password Solution) to eliminate shared local admin passwords used in PtH
  • Configure ADCS to require EPA and disable NTLM authentication on certificate enrollment pages (prevents ESC8)
  • Replace legacy devices/applications that cannot migrate from NTLM — budget for hardware/software upgrades

Weaknesses (CWE) in Microsoft NTLM Phase-Out

CWE-287, CWE-294, CWE-327

Timeline of Microsoft NTLM Phase-Out

  • Microsoft introduces NTLM (NT LAN Manager) authentication protocol for Windows NT. Challenge-response authentication using MD4 hash of password. Replaces LAN Manager (LM) hashes. No mutual authentication, no session encryption in base protocol.
  • Windows 2000 introduces NTLMv2 (stronger challenge-response with HMAC-MD5) and makes Kerberos the default authentication protocol for Active Directory domains. NTLM remains as fallback for non-Kerberos-capable systems.
  • Pass-the-hash attacks become mainstream penetration testing technique. Mimikatz and similar tools extract NTLM hashes from LSASS memory. Hash reuse enables lateral movement without knowing plaintext passwords. NTLM's hash-based auth enables PtH by design.
  • NTLM relay attack tooling matures: Responder for LLMNR/NBT-NS poisoning, ntlmrelayx for relay to SMB/LDAP/HTTP, MultiRelay for multi-service relay. Practical exploitation of NTLM relay becomes routine in penetration tests and real attacks.
  • PetitPotam (CVE-2021-36942) discovered: MS-EFSRPC coerced authentication forces domain controllers to authenticate via NTLM to attacker-controlled share. Combined with ADCS relay (ESC8) enables domain compromise. Microsoft releases KB5005413 mitigation.
  • CVE-2023-23397: Microsoft Outlook NTLM credential theft via calendar appointment. Attacker sends appointment with UNC path — Outlook automatically authenticates via NTLM without user interaction. Exploited by APT28/Forest Blizzard against NATO/Ukraine targets.
  • Coerced authentication techniques proliferate: PetitPotam, PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP). All force NTLM authentication from servers to attacker-controlled endpoints. Detection requires monitoring outbound NTLM from servers.
  • Microsoft officially announces NTLM deprecation. Windows Server 2025 and Windows 11 24H2 will include NTLM audit mode (log all NTLM without blocking) and enforcement mode (block NTLM with exceptions). Multi-year transition begins.
  • Windows Server 2025 GA with NTLM audit and enforcement modes. Event IDs 8001 (NTLM request), 8002 (NTLM blocked), 8003 (NTLM audit-only). Enterprises begin logging all NTLM usage to discover legacy dependencies before enforcement.
  • Transition-period attacks accelerate. Attackers race to exploit remaining NTLM before migration completes. NTLM relay to ADCS, PetitPotam variants, and NTLM downgrade attacks increase. Organizations with slow migration are priority targets.
  • Enterprise NTLM volume tracking becomes standard practice. Organizations measure NTLM authentication events per week, tracking decline toward zero. The 'NTLM long tail' — legacy devices and apps — identified as persistent risk requiring compensating controls.
  • Early adopters begin NTLM enforcement (blocking). Authentication failures reveal undiscovered NTLM dependencies. Detection rules shift from 'find NTLM usage' to 'find NTLM authentication bypass attempts' as enforcement creates new alert patterns.
  • Threadlinqs Intelligence analysis: The NTLM deprecation transition period (2025-2028) is the most dangerous phase. Attackers accelerate exploitation before the window closes. Defenders must detect NTLM relay/downgrade/PtH on the shrinking NTLM surface while simultaneously migrating to Kerberos. The detection rules ARE the migration roadmap — every NTLM event detected is a system that needs migration.
  • As of 2026-05-29, this NTLM-deprecation advisory remains ACTIVE: Microsoft's phase-out is mid-flight (Phase 2 IAKerb/Local-KDC in H2 2026, NTLMv1 SSO enforcement Oct 2026, full disable undated), so NTLM stays a live attack surface. CISA-KEV CVE-2025-24054 saw exploitation 8 days post-patch and the Coercion-to-Relay-to-ADCS chain still yields domain admin in most enterprises.

Sources cited for Microsoft NTLM Phase-Out

Detection coverage for TL-2026-0009

As of 2026-02-02, Threadlinqs Intelligence publishes 17 detection rule(s) for TL-2026-0009 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

17 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
36 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats