Skip to main content

Overview

Abuse MS-EFSRPC to coerce target (typically DC) to authenticate to attacker. Relay authentication to ADCS (ESC8) or LDAP for domain takeover.

Coerce Authentication

Unauthenticated (Unpatched)

Authenticated


Relay to ADCS (ESC8) — Full Domain Takeover

Setup ntlmrelayx

Trigger PetitPotam

Use Certificate


Relay to LDAP (RBCD)


Other Coercion Methods

PrinterBug

DFSCoerce


Quick Reference