Skip to content

PetitPotam

Tool

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
January 15, 2026
Last Seen
September 8, 2026
API

PetitPotam is a Windows NTLM relay attack technique that exploits the MS-EFSRPC interface to coerce a target to authenticate to an attacker-controlled service, enabling relay-based lateral movement and potential domain compromise without stolen credentials.

Overview

Recent Events

Relationships

The full threat graph for this incident is free in the 7-day Starter trial.

Create free account

No card · 30 seconds

See everything included

Related Articles (8)

1 / 2