Potential NTLM hash leak via MS Photos

Detects a potential NTLM hash disclosure via abuse of the ms-photos: URI scheme with a UNC path parameter. An attacker can craft a specially formatted link that, when opened, launches Microsoft Photos directly from a browser and triggers outbound authentication, potentially leaking NTLM credentials.

Back to all rules