Skip to content

Latest commit

 

History

History
28 lines (18 loc) · 1.41 KB

prevent-2_description.md

File metadata and controls

28 lines (18 loc) · 1.41 KB

PREVENT-2

Description

Disable Fallback to NTLM

Summary

Within SCCM's client push installation properties, there exists a setting to "Allow connection fallback to NTLM." This setting allows the site server to fallback to NTLM if Kerberos fails (Figure 1).

Figure 1

Figure 1 - Client Push Installation Properties

Adversaries commonly abuse NTLM authentication by coercing computers to authenticate to an attacker-controlled machine then either capturing or relaying the authentication to another resource.

Disabling this setting prevents the use of NTLM authentication and coercion.

NOTE: This technique must be used in conjunction with PREVENT-1.

Linked Defensive IDs

Associated Offensive IDs

References