What problem does it solve?
This Skill solves the problem of missing critical reconnaissance data for internet-exposed enterprise infrastructure such as IIS, SharePoint, and Exchange that leaks internal Active Directory topology, hostname provisioning details, and system timestamp data via anonymous NTLM authentication challenges.
Core Features & Use Cases
- Anonymous NTLM Challenge Detection: Identifies internet-facing endpoints that expose NTLM or Negotiate authentication headers to unauthenticated users.
- AV_PAIR Intelligence Extraction: Parses NTLM Type-2 challenge responses to extract NetBIOS domain names, DNS forest structure, default Windows hostnames, and system timestamps.
- Use Case: For a penetration test targeting a customer's public SharePoint portal, use this Skill to quickly confirm if anonymous NTLM challenges are exposed, extract the internal AD forest name and default hostname to inform subsequent credential spraying and attack chain planning.
Quick Start
Use the hunt-ntlm-info skill to probe the target's public SharePoint API endpoint for anonymous NTLM Type-2 challenges and extract all available Active Directory topology and hostname intelligence from the response.