Netskope Threat Labs

PetitPotam

ATP Sandbox Adv. HeuristicsAV

PetitPotam is a public tool that coerces Windows hosts to authenticate to cyberattacker controlled systems through the MS-EFSRPC protocol, enabling NTLM relay attacks against Active Directory certificate services. Cyberattackers use it to take over domain environments, so its detections warrant careful verification against authorized testing.

First seen
April 2022
Last seen
October 2026
Petitpotam
Alert Name
Generic.Exploit.PetitPotam.A.92794BB2
Generic.Exploit.PY.PetitPotam.A.05E32B02
Generic.Exploit.PY.PetitPotam.A.602E294D
Generic.Exploit.PY.PetitPotam.A.6A473141
Generic.Exploit.PY.PetitPotam.A.6AEFC4BC
Generic.Exploit.PY.PetitPotam.A.85D9D10F
Generic.Exploit.PY.PetitPotam.A.B5A06E8D
Generic.Exploit.PY.PetitPotam.A.ECACD692
Script-Python.Exploit.PetitPotam
Script.Exploit.Petitpotam