pcap_llmnr_ntlm
Analyze PCAP files to detect LLMNR poisoning attacks and extract NTLM credentials from SMB traffic for network security investigations.
Instructions
Detect LLMNR poisoning and extract NTLM credentials from SMB. Returns llmnr_queries, ntlm_auth_entries, counts, and poisoning_indicators. Read-only file analysis.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| pcap_path | Yes | Path to the PCAP file |