Google-owned Mandiant released a public dataset of Net-NTLMv1 rainbow tables intended to make the long-known weakness of Microsoft’s legacy Net-NTLMv1 authentication protocol easy to demonstrate and harder to ignore. Mandiant stated the dataset enables defenders and researchers to recover Net-NTLMv1 key material in under ~12 hours using consumer hardware costing under ~$600, significantly lowering the barrier to proving real-world credential exposure. The release is positioned as a push to accelerate retirement of Net-NTLMv1, which has been considered cryptographically broken for decades yet is still observed in active enterprise environments.
The practical risk highlighted is that once an attacker captures a Net-NTLMv1 hash (notably in scenarios lacking Extended Session Security (ESS) and involving a known plaintext value such as 1122334455667788), they can apply known-plaintext techniques to recover key material equivalent to the password hash for the authenticating Active Directory object. Reporting also notes common attack paths that can precede hash capture, including authentication coercion against privileged systems (e.g., domain controllers) using tools such as PetitPotam or DFSCoerce. Mandiant’s guidance is explicit: organizations should immediately disable Net-NTLMv1 and migrate away from the protocol to reduce credential-theft and lateral-movement risk.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Mandiant recommended immediate mitigation by disabling NTLMv1 and enforcing NTLMv2-only settings through Group Policy, while warning that local settings can be downgraded after compromise. The guidance also pointed defenders to monitoring opportunities such as Windows Event ID 4624 to detect NTLMv1 use.
With the release, Mandiant highlighted that captured Net-NTLMv1 challenge-response material can be used to recover keys in under 12 hours using less than $600 of consumer hardware, substantially lowering the cost and complexity of credential recovery. The material also described how this could enable privilege escalation, including recovery of domain controller machine account hashes and DCSync against Active Directory.
Mandiant publicly released a comprehensive, downloadable dataset of Net-NTLMv1 rainbow tables, along with documentation and workflow guidance for common cracking tools. The release was intended to help defenders demonstrate the risk of the legacy protocol and accelerate its retirement.
The references state that Net-NTLMv1 has been cryptographically broken since 1999 and has long been recognized as insecure, yet it is still present in some enterprise environments. This longstanding weakness set the stage for later efforts to force its retirement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.