{"enrichment":{"faq":[{"a":"ntlm-relay-coercion teaches NTLM relay attacks\u2014capturing and forwarding authentication tokens across protocols (SMB, LDAP, HTTP, MSSQL) to escalate privileges. The skill covers relay targets, signing bypass techniques, coercion methods like PetitPotam and PrinterBug, and tools like Responder and ntlmrelayx to execute cross-protocol relay chains for domain compromise.","q":"What is ntlm-relay-coercion and how does it enable privilege escalation?"},{"a":"ntlm-relay-coercion covers relaying NTLM by intercepting authentication and forwarding it to target services. Success depends on bypassing SMB signing and EPA/channel binding protections. The skill teaches which protocols enforce signing, how to identify vulnerable configurations, and techniques to relay tokens when signing is disabled or misconfigured.","q":"How do you relay NTLM authentication and what are the signing requirements?"},{"a":"ntlm-relay-coercion explains PetitPotam and PrinterBug as primary coercion techniques. PetitPotam exploits the MS-EFSRPC protocol to force authentication from domain controllers or servers. PrinterBug abuses the Print Spooler service. Both methods force targets to initiate NTLM authentication toward attacker-controlled systems, enabling relay capture.","q":"What coercion methods trigger NTLM authentication in ntlm-relay-coercion?"},{"a":"ntlm-relay-coercion teaches chaining relays across protocols\u2014for example, capturing SMB authentication and relaying it to LDAP or WebDAV services. The skill covers protocol-specific relay targets, service account privileges, and how to chain multiple relays (SMB\u2192LDAP, WebDAV\u2192LDAP) to escalate from initial compromise to domain controller access.","q":"How does ntlm-relay-coercion set up cross-protocol relay chains like SMB to LDAP?"},{"a":"ntlm-relay-coercion covers Responder for LLMNR/mDNS poisoning and passive credential capture, and mitm6 for IPv6 DNS takeover. Both tools intercept authentication traffic and feed it to ntlmrelayx for relay execution. The skill teaches configuring these tools together for combined passive/active capture and relay workflows to compromise Active Directory environments.","q":"What role do Responder and mitm6 play in ntlm-relay-coercion attacks?"},{"a":"ntlm-relay-coercion covers advanced relay targets including ADCS certificate enrollment and computer account creation. The skill teaches relaying to domain controllers for account manipulation, using RBCD (Resource-Based Constrained Delegation) and shadow credentials, and leveraging WebClient/WebDAV coercion to reach services that enable privilege escalation beyond initial relay.","q":"Can ntlm-relay-coercion relay NTLM to add computer accounts or enroll certificates?"}],"shadow_tags":["relay-attack","authentication-coercion","privilege-escalation","cross-protocol-relay","active-directory-attack","credential-capture","lateral-movement","domain-takeover","network-poisoning","certificate-abuse"],"summary_rewrite":"Master NTLM relay attacks to capture and forward authentication across multiple protocols for privilege escalation. Learn relay targets, signing requirements, Responder poisoning, ntlmrelayx execution, mitm6 DNS takeover, and cross-protocol techniques including WebDAV coercion to bypass defenses."},"files":[{"bytes":8968,"path":"skills/ntlm-relay-coercion/SKILL.md","sha256":"ef1cddcca318f3a2439d97bdcd4429cc615287b4058ef8ba4513a7b6cb5aa919","url":"https://skillfed.io/files/yaklang/hack-skills/ntlm-relay-coercion/c24d1bd0/SKILL.md"}],"id":"yaklang/hack-skills/ntlm-relay-coercion","links":{"html":"https://skillfed.io/yaklang/hack-skills/ntlm-relay-coercion","md":"https://skillfed.io/yaklang/hack-skills/ntlm-relay-coercion.md","repo":"https://github.com/yaklang/hack-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":196,"language":"CSS","last_updated":"2026-06-16","license":"MIT","name":"ntlm-relay-coercion","publisher":"yaklang","stars":1480},"relations":{"similar":[{"id":"blacklanternsecurity/red-run/auth-coercion-relay"},{"id":"hypnguyen1209/offensive-claude/network-attack"},{"id":"yaklang/hack-skills/network-protocol-attacks"},{"id":"blacklanternsecurity/red-run/adcs-access-and-relay"},{"id":"zebbern/claude-code-guide/active-directory-attacks"},{"id":"hypnguyen1209/offensive-claude/active-directory-attack"},{"id":"blacklanternsecurity/red-run/ad-discovery"},{"id":"blacklanternsecurity/red-run/sccm-exploitation"},{"id":"yaklang/hack-skills/active-directory-certificate-services"},{"id":"zebbern/claude-code-guide/privilege-escalation-methods"}]},"slug":{"owner":"yaklang","repo":"hack-skills","skill":"ntlm-relay-coercion"},"version":"c24d1bd0"}
