hunt-ntlm-info — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited hunt-ntlm-info (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
NTLM info disclosure is a Medium-severity finding when chained to context — the leak itself is intentional protocol behavior (RFC-compliant NTLMSSP challenge), but on internet-exposed enterprise infrastructure it provides exact reconnaissance for the next stage of an attack. Highest-value targets:
What makes this pay:
customer.parent-corp.example → tenant inside corporate-AD tree)WIN-XXXXXXXXXXX pattern signals rushed provisioning → likely default service-account passwords)hunt-auth-bypass Legacy-Protocol MatrixResponse headers signaling NTLM availability:
WWW-Authenticate: NTLM
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM, Negotiate
WWW-Authenticate: Negotiate, NTLMURL patterns where NTLM is commonly exposed:
/_api/web/CurrentUser (SharePoint REST)
/_vti_bin/*.asmx (SharePoint legacy SOAP)
/EWS/Exchange.asmx (Exchange Web Services)
/Autodiscover/Autodiscover.xml (Exchange autodiscover)
/owa/ (Outlook Web App)
/Microsoft-Server-ActiveSync (ActiveSync)
/PowerShell (Exchange Mgmt Shell over HTTPS)
/api/v3/ (TeamCity, Atlassian)
/wsus/ (Windows Server Update Services)
/manager/html (some Tomcat behind IIS)
/iisstart.htm (default IIS, sometimes reveals NTLM upstream)Tech-stack signals:
Microsoft-HTTPAPI/2.0, Microsoft-IIS/*, IIS/* Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==This is the standard test Type-1 with negotiate flags NTLMSSP_NEGOTIATE_UNICODE | NTLMSSP_NEGOTIATE_OEM | NTLMSSP_NEGOTIATE_NTLM | NTLMSSP_NEGOTIATE_ALWAYS_SIGN | NTLMSSP_NEGOTIATE_KEY_EXCH | NTLMSSP_NEGOTIATE_56 | NTLMSSP_NEGOTIATE_128 | NTLMSSP_NEGOTIATE_TARGET_INFO. The OS Version field (06 01 B1 1D 00 00 00 0F) is Windows 7 build 7601 — accepted by virtually every NTLM responder.
Connection: keep-alive set explicitlymcp__burp__send_http1_request (handles keep-alive natively)socket + ssl.wrap_socket (see Payload section)NTLMSSP\0\x02\x00\x00\x00AV_PAIRS array of (AvId u16, AvLen u16, Value)1 = NetBIOS Computer Name2 = NetBIOS Domain Name3 = DNS Computer Name (FQDN of the responding server)4 = DNS Domain Name (the AD domain)5 = DNS Tree Name (the AD forest root)7 = Timestamp (FILETIME, useful for NTLMv2 hash relay / cracking)9 = Target Name (in newer NTLMSSP)WIN-XXXXXXXXXXX hostname + corporate-AD-tree disclosure → MediumSPWEB01.corp.example) + corporate-AD-tree → Low-Mediumhunt-auth-bypass Legacy-Protocol Matrix findings on the same host → upgrade the auth-bypass finding's severity since the attacker has UPN/SAM format readyAV[7] returns a current FILETIME within ~5s of Date: header, the system clock is synced — useful intel for Kerberos golden-ticket forging (out of bug-bounty scope but red-team relevant).customer.parent-corp.example reveals the customer is a sub-domain INSIDE corporate-parent AD, not a separate tenant. This is a privacy / topology-disclosure escalation that programs sometimes accept as Medium.Generic NTLM Type-1 anonymous probe (curl + raw socket fallback):
# Most one-shot curl runs DON'T return Type-2 because the connection closes.
# Use this as a quick probe to confirm NTLM is offered:
curl -sk -I -H "Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==" \
"https://target.example/_api/web/CurrentUser" 2>&1 | grep -i "WWW-Authenticate"Burp `send_http1_request` (recommended for full Type-2 capture):
GET /_api/web/CurrentUser HTTP/1.1
Host: target.example
Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==
Connection: keep-alive
User-Agent: Mozilla/5.0
Python raw socket + AV_PAIR decoder:
import socket, ssl, base64, struct, re
from datetime import datetime, timezone
HOST = "target.example"
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE
s = ctx.wrap_socket(socket.create_connection((HOST, 443)), server_hostname=HOST)
s.sendall(
f"GET /_api/web/CurrentUser HTTP/1.1\r\n"
f"Host: {HOST}\r\n"
"Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==\r\n"
"User-Agent: Mozilla/5.0\r\nConnection: keep-alive\r\n\r\n".encode()
)
data = b""
while True:
chunk = s.recv(8192)
if not chunk: break
data += chunk
if b"\r\n\r\n" in data: break
m = re.search(rb"WWW-Authenticate:\s*NTLM\s+([A-Za-z0-9+/=]{20,})", data, re.I)
if m:
b = base64.b64decode(m.group(1).decode("ascii"))
assert b[:8] == b"NTLMSSP\x00"
tn_len, _, tn_off = struct.unpack_from('<HHI', b, 12)
ti_len, _, ti_off = struct.unpack_from('<HHI', b, 40)
print(f"TargetName: {b[tn_off:tn_off+tn_len].decode('utf-16-le', errors='ignore')!r}")
av_types = {1:'NetBIOS Computer Name', 2:'NetBIOS Domain Name',
3:'DNS Computer Name', 4:'DNS Domain Name',
5:'DNS Tree Name', 7:'Timestamp', 9:'Target Name'}
i = 0
ti = b[ti_off:ti_off+ti_len]
while i < len(ti):
av_id, av_len = struct.unpack_from('<HH', ti, i)
if av_id == 0: break
val = ti[i+4:i+4+av_len]
if av_id == 7:
ts = struct.unpack('<Q', val[:8])[0]
secs = (ts - 116444736000000000) / 10000000
vs = datetime.fromtimestamp(secs, tz=timezone.utc).isoformat()
else:
vs = val.decode('utf-16-le', errors='ignore')
print(f" AV[{av_id}] {av_types.get(av_id, '?'):28s}: {vs!r}")
i += 4 + av_lenBurp Collaborator NOT needed for this finding class — the data leak is in the synchronous response, not via OOB.
WIN-XXXXXXXXXXX 11-character pattern is the immediate tell. Sometimes also WORKGROUP\WIN-... in older boxes.customer.parent-corp.example to be operationally separate but the NTLM Type-2 reveals the forest membership to anyone who probes.<system.webServer><security><authentication><windowsAuthentication extendedProtection> is None (the default), the NTLM challenge is sent to any anonymous client. When set to Required, NTLM is restricted to authenticated callers — and the AV-pair leak is mitigated.This skill describes a disclosure leak, not an authentication bypass. The "bypass" question is: how do defenders block this AV-pair leak while still allowing legitimate NTLM auth?
| Defense | Effectiveness |
|---|---|
| Disable NTLM on the public IIS binding entirely (Forms-only) | Best — eliminates the surface |
| IIS Extended Protection = Required | Restricts NTLM challenge to authenticated callers; AV-pair leak mitigated |
| Reverse-proxy strip `WWW-Authenticate` from anonymous responses | Sometimes works but breaks legitimate clients |
| Rate-limit the Type-1 → Type-2 endpoint | Doesn't prevent disclosure, only slows enumeration |
| Rename the Windows host from `WIN-XXXXXXXXXXX` | Removes the "lazy provisioning" tell; doesn't stop the leak |
| Move the SP/Exchange farm to a child AD with no cross-trust to corporate | Mitigates the forest disclosure; doesn't stop the leak |
For the attacker: there's no "bypass" needed — the leak is the finding.
Before writing the report, confirm:
hunt-auth-bypass matrix probes, plus knows server has likely-default service accounts.hunt-auth-bypass.Target: https://target-portal.example/ — a enterprise dealer portal (test mirror) operated by a system integrator.
Sending the anonymous Type-1 message to /_api/web/CurrentUser returned a Type-2 challenge whose AV_PAIRS decoded to:
NetBIOS Domain Name: <CustomerName>
NetBIOS Computer Name: WIN-XXXXXXXXXXX
DNS Domain Name: customer.parent-corp.example
DNS Computer Name: WIN-XXXXXXXXXXX.customer.parent-corp.example
DNS Tree Name: customer.parent-corp.example
Timestamp: 2026-05-13T15:55:37.922ZThree escalation paths:
hunt-auth-bypass's discovery of an anonymous brute-force endpoint on /_vti_bin/Authentication.asmx, the attacker has both the credential format ([email protected] or <CustomerName>\firstname.lastname) and the unlimited submission endpoint.Reported severity: Medium, with a note that the chain with the Authentication.asmx anonymous brute-force makes the combined attack Critical.
Target: https://mail.example.com/EWS/Exchange.asmx. Type-1 probe returns Type-2 with DNS Tree Name corp.example.com and DNS Computer Name MAIL01.corp.example.com. Confirms the Exchange edge is domain-joined to corporate AD (rather than running in a DMZ-isolated AD). For an attacker with the matching hunt-mfa-bypass / hunt-auth-bypass chain, the leaked UPN format and server-name format accelerate credential spraying by removing the recon step. Reported severity: Low-Medium depending on program.
Target: https://intranet.corp.example (clearly internal, behind VPN). Type-1 returns full AV-pair set. Not reportable — this is intended NTLM behavior on intranet, and the disclosure is to authenticated VPN users who already see the same data via nltest /dsgetdc:corp.example.com. Recognize and drop.
/_vti_bin/ by default; this is one of the most reliable ways to get internal AD topology. Chain primitive: SharePoint discovered → NTLM Type-2 capture on /_vti_bin/Lists.asmx → hunt-ntlm-info AV_PAIR decode → internal forest name → m365-entra-attack ROPC spray on Entra tenant tied to that forest.corp.example.com DNS tree → cross-reference Entra tenant via https://login.microsoftonline.com/corp.example.com/.well-known/openid-configuration → m365-entra-attack AADSTS error-differential username enumeration on resolved tenant./owa/, /ecp/, /rpc/, /aspnet_client/ → confirm IIS + ASP.NET version → hunt-aspnet ViewState / .axd enumeration on same host.WIN-XXXXXXXXXXX signals lazy provisioning and predicts other weak hygiene. Chain primitive: NTLM Type-2 returns default-installer hostname → flag as low-maturity environment → offensive-osint deep recon (cert transparency, GitHub leakage, breach corpus correlation) is high-yield on this org.triage-validation BEFORE writing it up; only report if (a) leaks UPN format that accelerates spray, or (b) leaks production hostname mapping (redteam-report-template for the chain-narrative).~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.