kevmap

TechniquesT1557.001 › AN1274

AN1274 Analytic 1274

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects anomalous network traffic on UDP 5355 (LLMNR) and UDP 137 (NBT-NS) combined with unauthorized SMB relay attempts, registry modifications re-enabling multicast name resolution, or suspicious service creation indicative of adversary-in-the-middle credential interception.</p>
Detects
T1557.001 Name Resolution Poisoning and SMB Relay
Part of
DET0462 Detect LLMNR/NBT-NS Poisoning and SMB Relay on Windows

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4697DC0060 Service Creation
WinEventLog:SecurityRegistry key modification HKLM\Software\Policies\Microsoft\Windows NT\DNSClient\EnableMulticastDC0063 Windows Registry Key Modification
NSM:FlowUnusual responses to LLMNR (UDP 5355) or NBT-NS (UDP 137) queries from unauthorized hostsDC0085 Network Traffic Content
NSM:FlowAbnormal SMB authentication attempts correlated with poisoned LLMNR/NBT-NS sessionsDC0078 Network Traffic Flow

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TrustedResponderListDefines expected LLMNR/NBT-NS responders to tune out legitimate services.
TimeWindowCorrelation period for linking poisoned name resolution with SMB relay attempts.
SMBServiceBaselineNormal services and SMB relay patterns in the enterprise environment.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2023-38035Ivanti SentryMapped