Skip to main content

Overview

Capture NTLM authentication and relay to another service. Attacker acts as MITM — victim authenticates to attacker, attacker forwards to target.

Check SMB Signing

Targets with SMB signing disabled or not required are relayable.

ntlmrelayx — SMB Relay

Basic (SAM Dump)

Execute Command

Interactive Shell

Execute Binary


ntlmrelayx — LDAP Relay

Create Machine Account (RBCD)

Dump LDAP

Add User to Group


ntlmrelayx — MSSQL


ntlmrelayx — ADCS (ESC8)


Coerce Authentication

Trigger victim to authenticate to attacker:

Typical Attack Flow

Responder Config


Quick Reference