Skip to content

Conversation

@bcampbell-wsecure
Copy link

Flag could also be renamed to /nocanonicalize or something generic.

This allows a Kerberos ticket to be created with most of the OPSEC features, but still perform the BM attack.

@CCob
Copy link
Contributor

CCob commented Sep 8, 2025

Not sure if it's really worth adding another parameter to the gazillion that are already there. By requesting no canonicalization, you've already wandered off what a genuine LSASS login request looks like anyway. Windows always requests canonicalization.

@bcampbell-wsecure
Copy link
Author

Doesn't matter what Windows does, matters what the EDR tooling actually checks :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants