DFSCoerce - Tool

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
January 15, 2026
Last Seen
January 30, 2026

DFSCoerce is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed January 15, 2026; most recent activity January 30, 2026.

Overview

DFSCoerce is described in connection with efforts to deprecate Net-NTLMv1 by releasing rainbow tables that accelerate offline cracking of Net-NTLMv1 hashes. The approach uses precomputed hash tables to test credential exposure and motivate migration to more secure authentication, highlighting a shift toward NTLMv2 or Kerberos. This development is significant for both defense (testing and remediation) and potential adversaries (faster verification of legacy credentials).

Related Threat Clusters

Recent Intelligence Reports

  • Microsoft to disable NTLM by default in future Windows releases — Bleepingcomputer · January 30, 2026
  • Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation — Mandiant · January 15, 2026

CVSS v3.1 Breakdown