Adversary in the Middle: LLMNR/NBT-NS Poisoning and SMB Relay

By responding to LLMNR/NBT-NS network traffic, Threat Actors may spoof an authoritative source for name resolution to force communication with Threat Actors controlled system. This activity may be used to collect or relay authentication materials. 

ID: ATAGS-T1111.005
Sub-technique of:  ATAGS-T1111
Targeted Components: Mission, Personnel & Identity
Responsibility: Shared
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.