Detecting and Mitigating the PetitPotam Attack on Windows Domains
Summary
How the PetitPotam attack works: EFSRPC authentication coercion relayed via NTLM to AD CS Web Enrollment (ESC8) can yield Domain Admin; the post maps the full chain and covers detection plus mitigations like disabling NTLM or enabling EPA.
- Published
- Collected
Skip to content