NTLM Relay Attack Module
Versionv1.6
Difficulty Intermediate
Updated2025-03-20
CategoryRed Team Tools

NTLM Relay Attack Module

$79.99

NTLM Relay Attack Module

n

Standalone implementation of NTLM relay basada in impacket:

n
    n
  • Listener multi-protocol — Captura authentications NTLM entrantes via SMB, HTTP, and WebDAV.
  • n
  • Relay targets — Retransmite a SMB (psexec, secretsdump), LDAP (modify ACLs, add computer), HTTP (Exchange EWS), MSSQL (xp_cmdshell).
  • n
  • Coercion triggers — Scripts for forzar authentication: PetitPotam, PrinterBug, DFSCoerce, ShadowCoerce.
  • n
  • Filtrado — Relay selectivo by user (only relay Domain Admins, ignorar machine accounts).
  • n
  • Logging — Registro detallado of each intento of relay with result (success/fallo and reason).
  • n
n

Requirements: Python 3 + impacket. Position of red that permita intercept or coercionar authentications NTLM.