hunt-ntlm-info
Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange. Anonymous NTLM Type-2 challenge capture leaks NetBIOS domain, internal DNS forest, computer name, AD timestamp via AV_PAIRS structure.
Install / Use
npx skills add elementalsouls/Claude-BugHunter --skill hunt-ntlm-infoInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of hunt-ntlm-info
hunt-ntlm-info scores 96/100 on our quality scale, 201st of 3,168 Development & Engineering skills we index (top 7%).
Its SKILL.md is 16 KB long, well organised into 14 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.
With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so hunt-ntlm-info is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hunt-ntlm-info compared with similar skills
All 4 of these similar skills score higher than hunt-ntlm-info; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-ntlm-info (this skill)by elementalsouls | 96 | 4.7k | 2d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 85.9k | 13d ago | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 44.3k | today | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 2d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
Frequently asked questions
- How do I install hunt-ntlm-info?
- Run
npx skills add elementalsouls/Claude-BugHunter --skill hunt-ntlm-info. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-ntlm-info work with?
- It is written for Zed, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-ntlm-info safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-ntlm-info still maintained?
- The repository was last updated 2 days ago, so hunt-ntlm-info is actively maintained.
Skill content
View source on GitHubname: hunt-ntlm-info
description: "Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange. Anonymous NTLM Type-2 challenge capture leaks NetBIOS domain, internal DNS forest, computer name, AD timestamp via AV_PAIRS structure. Default Windows-installer hostnames (WIN-XXXXXXXXXXX pattern) signal lazy provisioning. Use when target advertises WWW-Authenticate: NTLM or Negotiate headers anonymously."
sources: github, authorized-engagement
report_count: 1
Crown Jewel Targets
NTLM info disclosure is a Medium-severity finding when chained to context — the leak itself is intentional protocol behavior (RFC-compliant NTLMSSP challenge), but on internet-exposed enterprise infrastructure it provides exact reconnaissance for the next stage of an attack. Highest-value targets:
- Internet-reachable IIS / SharePoint / Exchange / OWA with dual-auth (Forms + NTLM, or NTLM + Kerberos)
- Citrix NetScaler / VMware Horizon View internet-facing gateways with NTLM-backed AD auth
- Lync / Skype for Business / Teams On-Prem edge servers
- WSUS / Windows Update Services with NTLM-protected admin paths
- CIFS-style fileshare proxies (HCL Sametime, IBM Notes Domino) that proxy NTLM
- Legacy SharePoint farms that left NTLM enabled on the public-zone IIS binding
What makes this pay:
- Internal AD domain disclosure (parent-forest mapping, e.g.
customer.parent-corp.example→ tenant inside corporate-AD tree) - Default-Windows-hostname disclosure (
WIN-XXXXXXXXXXXpattern signals rushed provisioning → likely default service-account passwords) - Timestamp leak (used in NTLMv2 hash cracking acceleration)
- Direct attack-map enrichment for credential spraying combined with
hunt-auth-bypassLegacy-Protocol Matrix
Attack Surface Signals
Response headers signaling NTLM availability:
WWW-Authenticate: NTLM
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM, Negotiate
WWW-Authenticate: Negotiate, NTLM
URL patterns where NTLM is commonly exposed:
/_api/web/CurrentUser (SharePoint REST)
/_vti_bin/*.asmx (SharePoint legacy SOAP)
/EWS/Exchange.asmx (Exchange Web Services)
/Autodiscover/Autodiscover.xml (Exchange autodiscover)
/owa/ (Outlook Web App)
/Microsoft-Server-ActiveSync (ActiveSync)
/PowerShell (Exchange Mgmt Shell over HTTPS)
/api/v3/ (TeamCity, Atlassian)
/wsus/ (Windows Server Update Services)
/manager/html (some Tomcat behind IIS)
/iisstart.htm (default IIS, sometimes reveals NTLM upstream)
Tech-stack signals:
- IIS on the public internet (almost always NTLM-capable, even if Forms is the front)
- SharePoint Web Front End (almost always dual-auth Forms + NTLM)
- Exchange edge transport
- Server header
Microsoft-HTTPAPI/2.0,Microsoft-IIS/*,IIS/*
Step-by-Step Hunting Methodology
-
Probe every anonymous endpoint for
WWW-Authenticate: NTLM. Send a vanilla GET and inspect response headers. If NTLM is offered, proceed. -
Send a valid NTLMSSP Type-1 message anonymously. The Type-1 base64 below requests NetBIOS-domain and Workstation info from the server:
Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==This is the standard test Type-1 with negotiate flags
NTLMSSP_NEGOTIATE_UNICODE | NTLMSSP_NEGOTIATE_OEM | NTLMSSP_NEGOTIATE_NTLM | NTLMSSP_NEGOTIATE_ALWAYS_SIGN | NTLMSSP_NEGOTIATE_KEY_EXCH | NTLMSSP_NEGOTIATE_56 | NTLMSSP_NEGOTIATE_128 | NTLMSSP_NEGOTIATE_TARGET_INFO. TheOS Versionfield (06 01 B1 1D 00 00 00 0F) is Windows 7 build 7601 — accepted by virtually every NTLM responder. -
Use a keep-alive raw socket, not Python requests / curl one-shot. Most HTTP libraries close the connection between the Type-1 send and Type-2 reception. Use one of:
- Burp Repeater with
Connection: keep-aliveset explicitly - Burp
mcp__burp__send_http1_request(handles keep-alive natively) - Python raw
socket+ssl.wrap_socket(see Payload section)
- Burp Repeater with
-
Parse the Type-2 challenge from the
WWW-Authenticate: NTLM <base64>response header. Base64-decode the value. The structure is NTLMSSP per MS-NLMP:- Bytes 0-7: literal
NTLMSSP\0 - Bytes 8-11: MessageType =
\x02\x00\x00\x00 - Bytes 12-19: TargetName SecurityBuffer (len, alloc, offset)
- Bytes 20-23: NegotiateFlags
- Bytes 24-31: Server Challenge (8 bytes — useful for offline cracking)
- Bytes 40-47: TargetInfo SecurityBuffer (len, alloc, offset)
- TargetInfo body:
AV_PAIRSarray of (AvId u16, AvLen u16, Value)
- Bytes 0-7: literal
-
Decode the AV_PAIRS. The AvIds you care about:
1= NetBIOS Computer Name2= NetBIOS Domain Name3= DNS Computer Name (FQDN of the responding server)4= DNS Domain Name (the AD domain)5= DNS Tree Name (the AD forest root)7= Timestamp (FILETIME, useful for NTLMv2 hash relay / cracking)9= Target Name (in newer NTLMSSP)
-
Map findings to severity tier:
- Internet-exposed + default
WIN-XXXXXXXXXXXhostname + corporate-AD-tree disclosure → Medium - Internet-exposed + named-server hostname (
SPWEB01.corp.example) + corporate-AD-tree → Low-Medium - Intranet-only + any disclosure → Informational
- Combine with
hunt-auth-bypassLegacy-Protocol Matrix findings on the same host → upgrade the auth-bypass finding's severity since the attacker has UPN/SAM format ready
- Internet-exposed + default
-
Check the timestamp. If
AV[7]returns a current FILETIME within ~5s ofDate:header, the system clock is synced — useful intel for Kerberos golden-ticket forging (out of bug-bounty scope but red-team relevant). -
Cross-reference with subdomain enum. The DNS Tree name often reveals the parent forest — e.g.
customer.parent-corp.examplereveals the customer is a sub-domain INSIDE corporate-parent AD, not a separate tenant. This is a privacy / topology-disclosure escalation that programs sometimes accept as Medium.
Payload & Detection Patterns
Generic NTLM Type-1 anonymous probe (curl + raw socket fallback):
# Most one-shot curl runs DON'T return Type-2 because the connection closes.
# Use this as a quick probe to confirm NTLM is offered:
curl -sk -I -H "Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==" \
"https://target.example/_api/web/CurrentUser" 2>&1 | grep -i "WWW-Authenticate"
Burp send_http1_request (recommended for full Type-2 capture):
GET /_api/web/CurrentUser HTTP/1.1
Host: target.example
Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==
Connection: keep-alive
User-Agent: Mozilla/5.0
Python raw socket + AV_PAIR decoder:
import socket, ssl, base64, struct, re
from datetime import datetime, timezone
HOST = "target.example"
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE
s = ctx.wrap_socket(socket.create_connection((HOST, 443)), server_hostname=HOST)
s.sendall(
f"GET /_api/web/CurrentUser HTTP/1.1\r\n"
f"Host: {HOST}\r\n"
"Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==\r\n"
"User-Agent: Mozilla/5.0\r\nConnection: keep-alive\r\n\r\n".encode()
)
data = b""
while True:
chunk = s.recv(8192)
if not chunk: break
data += chunk
if b"\r\n\r\n" in data: break
m = re.search(rb"WWW-Authenticate:\s*NTLM\s+([A-Za-z0-9+/=]{20,})", data, re.I)
if m:
b = base64.b64decode(m.group(1).decode("ascii"))
assert b[:8] == b"NTLMSSP\x00"
tn_len, _, tn_off = struct.unpack_from('<HHI', b, 12)
ti_len, _, ti_off = struct.unpack_from('<HHI', b, 40)
print(f"TargetName: {b[tn_off:tn_off+tn_len].decode('utf-16-le', errors='ignore')!r}")
av_types = {1:'NetBIOS Computer Name', 2:'NetBIOS Domain Name',
3:'DNS Computer Name', 4:'DNS Domain Name',
5:'DNS Tree Name', 7:'Timestamp', 9:'Target Name'}
i = 0
ti = b[ti_off:ti_off+ti_len]
while i < len(ti):
av_id, av_len = struct.unpack_from('<HH', ti, i)
if av_id == 0: break
val = ti[i+4:i+4+av_len]
if av_id == 7:
ts = struct.unpack('<Q', val[:8])[0]
secs = (ts - 116444736000000000) / 10000000
vs = datetime.fromtimestamp(secs, tz=timezone.utc).isoformat()
else:
vs = val.decode('utf-16-le', errors='ignore')
print(f" AV[{av_id}] {av_types.get(av_id, '?'):28s}: {vs!r}")
i += 4 + av_len
Burp Collaborator NOT needed for this finding class — the data leak is in the synchronous response, not via OOB.
Common Root Causes
-
Dual-auth IIS bindings on the public zone. Administrators leave NTLM enabled on the public-facing IIS site even when Forms auth is the intended entry point. Internal users get SSO; external attackers get the AD topology leak.
-
Default IIS Application Pool identity left as
ApplicationPoolIdentity. Combined with default hostname, signals provisioning never went past first-boot. -
Server never renamed from Windows-installer-generated hostname. Microsoft's default
WIN-XXXXXXXXXXX11-character pattern is the immediate tell. Sometimes alsoWORKGROUP\WIN-...in older boxes. -
Sub-domain joined to corporate forest without zone-isolation. European-integrator case: a a European importer's SharePoint test environment is a child domain inside a corporate global AD, disclosed via NTLM DNS Tree Name. The customer probably intends
customer.parent-corp.exampleto be operationally separate but the NTLM Type-2 reveals the forest membership to anyone who probes. -
IIS Extended Protection NOT enabled. When
<system.webServer><security><authentication><windowsAuthentication extendedProtection>isNone(the default), the NTLM challenge is sent to any anonymous client. When set toRequired, NTLM is restricted to authenticated callers — and the AV-pair leak is mitigated. -
No
WindowsAuthenticationremoved fromapplicationHost.configfor internet-exposed sites. SharePoint Central Admin sometimes leaves this enabled even when SP zone configuration only enables Forms.
Bypass Techniques
This skill describes a disclosure leak, not an authentication bypass. The "bypass" question is: how do defenders block this AV-pair leak while still allowing legitimate NTLM auth?
| Defense | Effectiveness |
|---|---|
| Disable NTLM on the public IIS binding entirely (Forms-only) | Best — eliminates the surface |
| IIS Extended Protection = Required | Restricts NTLM challenge to authenticated callers; AV-pair leak mitigated |
| Reverse-proxy strip WWW-Authenticate from anonymous responses | Sometimes works but breaks legitimate clients |
| Rate-limit the Type-1 → Type-2 endpoint | Doesn't prevent disclosure, only slows enumeration |
| Rename the Windows host from WIN-XXXXXXXXXXX | Removes the "lazy provisioning" tell; doesn't stop the leak |
| Move the SP/Exchange farm to a child AD with no cross-trust to corporate | Mitigates the forest disclosure; doesn't stop the leak |
For the attacker: there's no "bypass" needed — the leak is the finding.
Gate 0 Validation
Before writing the report, confirm:
-
What can the attacker do RIGHT NOW with this disclosure?
- Internet-exposed + default hostname + corporate forest disclosed → Medium: attacker has UPN format for
hunt-auth-bypassmatrix probes, plus knows server has likely-default service accounts. - Intranet-only or only NetBIOS name → Informational.
- Internet-exposed + default hostname + corporate forest disclosed → Medium: attacker has UPN format for
-
Does the program accept information-disclosure findings without a chained impact?
- Many programs (Microsoft, large enterprise VDPs) DO accept this when the leaked info includes inte
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
85.9kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
ai-job-search
44.3kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
