Sophos published a CPU-based method and released the v1-nightshift tool to accelerate recovery of NetNTLMv1 credentials from captured challenge-response data, reducing lookups that previously consumed GPUs for up to eight hours to under 20 minutes on a single 64-core EPYC server. The approach uses bitsliced DES with AVX2, removes repeated DES key-schedule generation, and splits processing into precompute, search, and check phases, with a separate brute-force step for the low-entropy third NetNTLMv1 block. Sophos said the design reaches roughly 2.1 billion DES operations per second and can scale across multiple CPU servers without requiring dedicated GPUs.
The work builds on Mandiant's public release of Net-NTLMv1 DES rainbow tables, which was intended to demonstrate the protocol's long-known weakness and push organizations to retire it. Mandiant warned that when Net-NTLMv1 is used without ESS and a known challenge can be obtained, attackers can recover NTLM hash material tied to Active Directory user or computer accounts, enabling privilege escalation after coerced authentications captured with tools such as Responder, PetitPotam, or DFSCoerce. Together, the table release and Sophos's faster CPU-only lookup workflow further lower the cost of exploiting legacy NetNTLMv1, reinforcing the need to disable the protocol and close authentication-coercion paths.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
Mandiant publicly released a comprehensive Net-NTLMv1 rainbow-table dataset to demonstrate the protocol's insecurity and accelerate migration away from it.
Hashcat added support for cracking DES keys using known plaintext, which Mandiant cited as increasing the practicality of attacking Net-NTLMv1.
Mandiant noted that Net-NTLMv1 insecurity was widely discussed by at least 2012, including presentations at DEFCON 20.
Philippe Oechslin described rainbow tables in a 2003 paper, providing the lookup approach later applied to Net-NTLMv1 DES key recovery.
Mandiant said Net-NTLMv1 had been known to be insecure for over two decades, with relevant cryptanalysis dating back to at least 1999.
Martin Hellman described the time-memory trade-off concept that later underpinned rainbow-table techniques referenced in the Net-NTLMv1 story.
Sophos reported that the optimized workflow reduced a NetNTLMv1 downgrade lookup from up to eight hours on GPUs to under 20 minutes on a single server, with faster runtimes on small clusters.
Sophos described a CPU-based approach using bitsliced DES, AVX2, and key-schedule elimination to accelerate NetNTLMv1 rainbow-table lookups without GPUs.
Mandiant published guidance for downloading the Net-NTLMv1 tables from Google Cloud Storage, verifying SHA-512 checksums, and using the data with existing lookup tools.
Sophos published v1-nightshift, a CPU-only NetNTLMv1 rainbow-table lookup toolset built for Mandiant's tables and supporting single-machine and distributed workflows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
sophos.com
Open sourcesophos.com
Open sourcecloud.google.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.