PetitPotam is a tool tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed January 15, 2026; most recent activity June 30, 2026.
PetitPotam is a Windows NTLM relay attack technique that exploits the MS-EFSRPC interface to coerce a target to authenticate to an attacker-controlled service, enabling relay-based lateral movement and potential domain compromise without stolen credentials. Its significance lies in its use of legacy NTLM protocols to pivot within Active Directory environments, spurring defensive measures such as deprecating Net-NTLMv1 and moving toward disabling NTLM by default.
A proof-of-concept (PoC) exploit has been released for a NTLM reflection bypass vulnerability, tracked as CVE-2026-24294, which allows attackers to gain SYSTEM-level access on Windows Server 2025. This vulnerability…
Mandiant has released rainbow tables that can crack credentials using the Net-NTLMv1 protocol within 12 hours. This legacy Microsoft authentication protocol has been known to expose users to credential theft for over 20…
Microsoft announced plans to disable the NTLM authentication protocol by default in future Windows releases due to its security vulnerabilities that have been exploited in cyberattacks. NTLM, introduced in 1993, has…