Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

The Gentlemen – Coerced Authentication (PetitPotam) Chained to NTLM Relay

Thegentlemen Lateral Movement Sentinel
MITRE ATT&CK
Adversary-in-the-Middle
Data Source
DeviceProcessEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group_tools dataset (thegentlemen)
What This Detects
The Gentlemen's intrusion set is built around forcing machine authentication (PetitPotam) and relaying it with ntlmrelayx/Responder to seize domain-level credentials – among the more distinctive tool chains in the dataset for this group.
Query
DeviceProcessEvents
| where Timestamp > ago(1d)
| where ProcessCommandLine has_any ("PetitPotam","ntlmrelayx","Responder.py")
| project Timestamp, DeviceName, ProcessCommandLine, AccountName, InitiatingProcessFileName

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.