PetitPotam - Tool

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
January 15, 2026
Last Seen
June 30, 2026

PetitPotam is a tool tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed January 15, 2026; most recent activity June 30, 2026.

Overview

PetitPotam is a Windows NTLM relay attack technique that exploits the MS-EFSRPC interface to coerce a target to authenticate to an attacker-controlled service, enabling relay-based lateral movement and potential domain compromise without stolen credentials. Its significance lies in its use of legacy NTLM protocols to pivot within Active Directory environments, spurring defensive measures such as deprecating Net-NTLMv1 and moving toward disabling NTLM by default.

Related Threat Clusters

Recent Intelligence Reports

  • PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on ... — Gbhackers · June 30, 2026
  • Microsoft to disable NTLM by default in future Windows releases — Bleepingcomputer · January 30, 2026
  • Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation — Mandiant · January 15, 2026

CVSS v3.1 Breakdown