What problem does it solve?
This Skill helps you quickly identify and capture NTLM/Negotiate information disclosure from internet-reachable IIS/SharePoint/Exchange endpoints, turning opaque authentication handshakes into actionable reconnaissance.
Core Features & Use Cases
- Anonymous NTLM Type-2 capture: Detects
WWW-Authenticate: NTLM / Negotiate responses and captures the NTLMSSP Type-2 challenge.
- AV_PAIRS decoding: Parses the
AV_PAIRS structure to extract NetBIOS name/domain, DNS domain/forest tree, computer name, and timestamp.
- Environment prioritization: Flags higher-value disclosures such as default Windows hostnames (
WIN-XXXXXXXXXXX) and forest/topology leaks for triage and report-ready output.
- Target patterns & signals: Guides probing across common endpoints like SharePoint REST, EWS autodiscover/EWS ASMX, OWA paths, and WSUS locations.
Quick Start
Use the hunt-ntlm-info skill to probe an internet-exposed SharePoint or Exchange URL and decode the returned NTLM Type-2 AV_PAIRS into a short recon summary.