NTLM
New Technology LAN Manager
A legacy Windows authentication protocol vulnerable to relay and pass-the-hash.
New Technology LAN Manager is a challenge-response authentication suite that Microsoft retained for backward compatibility long after Kerberos became the default in Windows domains. It is susceptible to NTLM relay, where an attacker forwards a victim's authentication to another service, and to pass-the-hash, where a captured password hash is reused without cracking it. Because the hash functions as a credential, stealing it from memory grants access directly. Kerberos is preferred since it uses time-limited tickets and mutual authentication, and disabling legacy NTLM reduces these attack paths.
Looking NTLM up is step one. Getting tested on it is step two.
A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.
Not affiliated with or endorsed by CompTIA.
