DFSCoerce is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed January 15, 2026; most recent activity January 30, 2026.
DFSCoerce is described in connection with efforts to deprecate Net-NTLMv1 by releasing rainbow tables that accelerate offline cracking of Net-NTLMv1 hashes. The approach uses precomputed hash tables to test credential exposure and motivate migration to more secure authentication, highlighting a shift toward NTLMv2 or Kerberos. This development is significant for both defense (testing and remediation) and potential adversaries (faster verification of legacy credentials).
Mandiant has released rainbow tables that can crack credentials using the Net-NTLMv1 protocol within 12 hours. This legacy Microsoft authentication protocol has been known to expose users to credential theft for over 20…
Microsoft announced plans to disable the NTLM authentication protocol by default in future Windows releases due to its security vulnerabilities that have been exploited in cyberattacks. NTLM, introduced in 1993, has…