Urgent Threat from NTLMv1 Exploitation via Rainbow Tables

Urgent Threat from NTLMv1 Exploitation via Rainbow Tables

First seen 8 Sep 2026, 21:14 UTC Outflank.Nladscanpro.comsupport.microsoft.com 70.2

Article Content

Browse articles
ThreatCluster

In 2026, Mandiant released 8.6 terabytes of NTLMv1 rainbow tables, making it feasible to crack NTLMv1 hashes from Domain Controllers using consumer hardware. Attackers can now convert captured NTLMv1 hashes to NT hashes in under twelve hours, significantly lowering the barrier for exploitation. The vulnerability has existed since 1999, but the recent availability of these tables has escalated the urgency of the threat. Despite Microsoft deprecating NTLMv1 in Windows 11 24H2 and Windows Server 2025, many legacy systems still support it due to outdated configurations. Tools like ntlmv1.py and crackalack_lookup facilitate the attack process, allowing attackers to extract and crack hashes efficiently. Organizations running older versions of Windows Server are particularly at risk, as they may still have NTLMv1 enabled due to legacy settings or application compatibility issues. The threat landscape is compounded by the fact that NTLMv1 is still active in many environments, despite its known vulnerabilities.

Key Points: • Mandiant's release of 8.6 TB of rainbow tables enables rapid NTLMv1 hash cracking. • Attacks can be executed on consumer hardware, reducing costs and time significantly. • Legacy systems still supporting NTLMv1 pose a serious risk despite its deprecation by Microsoft.

Ask AI about this cluster

Timeline

2026-09-08
Mandiant releases NTLMv1 rainbow tables
8.6 terabytes of rainbow tables made publicly available, allowing easier NTLMv1 hash cracking.
adscanpro.com
2026-09-08
Outflank releases ntlmrain tool
A new tool for cracking NetNTLMv1 hashes is released, utilizing optimized rainbow tables and WebGPU.
Outflank.Nl
2026-09-08
NTLMv1 vulnerabilities highlighted
The ongoing relevance of NTLMv1 is discussed, emphasizing its risks in legacy systems.
adscanpro.com