Description
PetitPotam is a public tool that coerces Windows hosts to authenticate to cyberattacker controlled systems through the MS-EFSRPC protocol, enabling NTLM relay attacks against Active Directory certificate services. Cyberattackers use it to take over domain environments, so its detections warrant careful verification against authorized testing.
Stats
- First seen
- April 2022
- Last seen
- October 2026
Also known as
Petitpotam
Alert name variants
| Alert Name |
|---|
| Generic.Exploit.PetitPotam.A.92794BB2 |
| Generic.Exploit.PY.PetitPotam.A.05E32B02 |
| Generic.Exploit.PY.PetitPotam.A.602E294D |
| Generic.Exploit.PY.PetitPotam.A.6A473141 |
| Generic.Exploit.PY.PetitPotam.A.6AEFC4BC |
| Generic.Exploit.PY.PetitPotam.A.85D9D10F |
| Generic.Exploit.PY.PetitPotam.A.B5A06E8D |
| Generic.Exploit.PY.PetitPotam.A.ECACD692 |
| Script-Python.Exploit.PetitPotam |
| Script.Exploit.Petitpotam |