Remove 2028 Remove Backups Remove Social Engineering
article thumbnail

The Renaissance of NTLM Relay Attacks: Everything You Need to Know

Security Boulevard

PetitPotam abuses several functions in the Encrypting File System (EFS) service, such as EfsRpcOpenFileRaw, which opens a file in an arbitrary path for backup/restore. These techniques result in an immediate authentication attempt from the victim computer account without user interaction.