NTLM Relay & Coercion Commands
18 NTLM Relay & Coercion commands from the Credential Attacks category, each with its placeholders, supported authentication methods and upstream references.
Tools covered: coercer, impacket-ntlmrelayx, nxc, python3, responder
- Coercer Coerce NTLM authentication using multiple RPC protocols
- Coercer Scan (Find Coercion Vectors) Probe a target for every known authentication-coercion RPC method (PetitPotam, PrinterBug, DFSCoerce,…
- DFSCoerce Coerce NTLM authentication using MS-DFSNM (Distributed File System)
- NetExec coerce_plus Module Unified coercion module — replaces the individual petitpotam/printerbug/dfscoerce/shadowcoerce/mserven…
- NetExec Generate Relay Target List Scan a subnet over SMB and write a file containing every host with SMB signing disabled. The resulting list…
- NetExec mssql_coerce Module Coerce the MSSQL service account to authenticate to your relay listener via xp_dirtree / xp_subdirs /…
- NetExec PetitPotam Coercion Coerce a Windows host (typically a DC) to authenticate back to the attacker via the EFSRPC interface…
- NetExec SMB Coerce Plus Trigger NTLM authentication coercion using multiple methods (PetitPotam, PrinterBug, etc.) without credentials
- NetExec SMB NTLMv1 Check Check if NTLMv1 authentication is accepted on remote hosts (enables downgrade attacks)
- NetExec SMB ShadowCoerce Coerce NTLM authentication via the VSS shadow copy API (ShadowCoerce)
- NTLM Relay to ADCS Relay NTLM authentication to ADCS web enrollment to obtain a certificate
- NTLM Relay to LDAP Relay NTLM authentication to LDAP to configure RBCD delegation
- NTLM Relay to SMB NTLM relay attack targeting SMB service
- ntlmrelayx → LDAPS (Add Computer / RBCD / Shadow Creds) Relay coerced authentication to LDAPS — required when MIC and channel binding force LDAP signing. Common…
- ntlmrelayx SOCKS Proxy Run ntlmrelayx in SOCKS mode to keep relayed sessions alive after the initial authentication. Drive them…
- PetitPotam Coercion Coerce NTLM authentication from a target using MS-EFSRPC (PetitPotam)
- PrinterBug / SpoolSample Coerce NTLM authentication using the Print Spooler service (MS-RPRN)
- Responder Poison LLMNR, NBT-NS, and mDNS to capture NTLM hashes on the network