Product
Threat actors are exploiting legacy NetNTLMv1 authentication by coercing hosts to downgrade to weak 56-bit DES encryption and utilizing CPU-optimized rainbow table lookups to recover NT hashes.