TGViewer
Sec Note Sec Note @secnote · 2.88K subscribers
Post #364 1.04K
HashSiphon
NTLM hash extraction through HTTP-layer authentication proxying, zero SSPI calls from the attacker process
.

HashSiphon extracts the current user's NetNTLMv2 hash by manipulating HTTP authentication flows instead of calling SSPI APIs directly. It ships two variants: v1 routes NTLM auth through .NET's HTTP stack within the same process, and v2 delegates authentication entirely to the BITS service (svchost.exe) in a different PID, breaking process-level attribution altogether.


#AD
  • 👍 3
  • 🔥 2
More from @secnote
  1. Sep 25, 2026سلام و درود لنگ ظهر جمعه تون بخیر فایل 4 دوره #SEC530 خدمت شما. واقعا طولانی شد 😅
  2. Sep 24, 2026Sec Note pinned a photo
  3. Sep 24, 2026My New Blog Post Evading Sysmon Dns Monitoring In 2026 | binary-win DNSevade : https://git…
  4. Sep 23, 2026Did Sysmon miss the DNS event?👀
  5. Sep 22, 2026fbi job portal defaced and compromised? oh yeah, it's a silly tuesday
  6. Sep 22, 2026HyperDbg نسخه ۰.۲۴ منتشر شد! این نسخه شامل نه دستور جدید، پشتیبانی از آرایه‌ها به عنوان پا…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →