$npx skillfedfor your agent

Auth Coercion Relay

Auth Coercion Relay guides penetration testers through forcing authentication from remote systems via coercion techniques like PetitPotam and PrinterBug, then relaying those credentials through NTLM or Kerberos to escalate privileges or move laterally. It covers relay targets (SMB, LDAP, AD CS), feasibility checks, and both credential capture and exploitation paths.

Auth Coercion Relay forces remote systems to authenticate to attacker listeners and relays captured credentials for privilege escalation.

AI-generated summary based on this skill's SKILL.md

★ 241  34 GPL-3.0updated by blacklanternsecurity

Decision gist · record as of 2026-04-01

Auth Coercion Relay forces remote systems to authenticate to attacker listeners and relays captured credentials for privilege escalation. Auth Coercion Relay guides penetration testers through forcing authentication from remote systems via coercion techniques like PetitPotam and PrinterBug, then relaying those credentials through NTLM or Kerberos to escalate privileges or move laterally. It covers relay targets (SMB, LDAP, AD CS), feasibility checks, and both credential capture and exploitation paths.

manual: git clone https://github.com/blacklanternsecurity/red-run → cp -r red-run ~/.claude/skills/auth-coercion-relay

Use it when

  • Auth Coercion Relay works by first coercing a remote system to authenticate using techniques like PetitPotam or PrinterBug.
  • Auth Coercion Relay supports multiple relay targets including SMB (Server Message Block), LDAP (Lightweight Directory Access Protocol).
Same gist for agents: .md · .json

Install

blacklanternsecurity/red-run/auth-coercion-relay · repository language: Python

generated, unverified - the skill's exact subdirectory could not be determined; check the repository on GitHub

Open directory. Skills are indexed for reading, not audited. Review a skill's body before installing it.

Frequently asked questions

AI-generated answers based on this skill's SKILL.md and metadata

What is Auth Coercion Relay and what does it do?

Auth Coercion Relay guides penetration testers through forcing authentication from remote systems via coercion techniques like PetitPotam and PrinterBug, then relaying those credentials through NTLM or Kerberos to escalate privileges or move laterally. It covers relay targets (SMB, LDAP, AD CS), feasibility checks, and both credential capture and exploitation paths.

How does auth coercion relay work in penetration testing?

Auth Coercion Relay works by first coercing a remote system to authenticate using techniques like PetitPotam or PrinterBug, capturing those authentication credentials, and then relaying them through NTLM or Kerberos protocols to targets such as SMB, LDAP, or AD CS. This allows testers to escalate privileges or move laterally without cracking passwords.

What relay targets does Auth Coercion Relay support?

Auth Coercion Relay supports multiple relay targets including SMB (Server Message Block), LDAP (Lightweight Directory Access Protocol), and AD CS (Active Directory Certificate Services). Each target presents different exploitation opportunities depending on the environment and the tester's objectives.

Can Auth Coercion Relay test authentication security?

Yes, Auth Coercion Relay includes capabilities to test authentication security by simulating coerced auth scenarios. Testers can use it to identify vulnerabilities in how systems handle forced authentication and relay attacks, helping organizations strengthen their defenses against these attack vectors.

What coercion techniques does Auth Coercion Relay employ?

Auth Coercion Relay employs coercion techniques such as PetitPotam and PrinterBug to force remote systems into authenticating. These techniques exploit legitimate system functions to trigger authentication attempts that can then be captured and relayed for lateral movement or privilege escalation.

Under what license is Auth Coercion Relay distributed?

Auth Coercion Relay is distributed under the GPL-3.0 license, which permits use, modification, and distribution while requiring that derivative works also be licensed under GPL-3.0.

Let your AI agent find skills like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 56,283 agent skills by what they can do, searchable in plain language.

wish › “Relay or force authentication credentials through coercion techniques”

Give your agent the search over MCP, or paste the wish link into any chat. No install? Search from any chat →

Related skills

ntlm-relay-coercion
by yaklang · yaklang/hack-skills

Master NTLM relay attacks to capture and forward authentication across multiple protocols for privilege escalation. Learn relay targets, signing requirements, Responder poisoning, ntlmrelayx execution, mitm6 DNS takeover, and cross-protocol techniques including WebDAV coercion to bypass defenses.

MITupdated Jun 2026
★ 1,480repo stars
active-directory-attacks
by zebbern · zebbern/claude-code-guide

This skill covers offensive techniques for compromising Active Directory environments, including reconnaissance with BloodHound, credential extraction via Kerberoasting and AS-REP roasting, ticket forgery, and lateral movement. Learn pass-the-hash, DCSync, NTLM relay, and exploitation of AD Certificate Services vulnerabilities alongside critical CVE tactics.

MITupdated Jul 2026
★ 4,440repo stars
active-directory-attack
by hypnguyen1209 · hypnguyen1209/offensive-claude

Orchestrate post-compromise domain exploitation through Kerberos attacks, coercion-relay chains, certificate template abuse, and BloodHound-guided lateral movement. Covers roasting, delegation abuse, NTLM reflection, ADCS ESC variants, ticket forgery, DCSync, and dMSA BadSuccessor attacks with integrated OPSEC and detection guidance.

MITupdated Jul 2026
★ 326repo stars
network-attack
by hypnguyen1209 · hypnguyen1209/offensive-claude

Network Attack covers layer-2 and layer-3 poisoning (LLMNR, ARP, DHCPv6), NTLM relay with coercion, traffic interception, and network-service exploitation for lateral movement. It includes TUN-based pivoting with tools like Ligolo-ng and Chisel, plus wireless assessment for WPA2/WPA3. Hand off AD-specific relay work and Kerberos attacks to the active-directory-attack skill.

MITupdated Jul 2026
★ 326repo stars
network-protocol-attacks
by yaklang · yaklang/hack-skills

Network Protocol Attacks provides hands-on techniques for exploiting layer 2 and layer 3 protocols to establish man-in-the-middle positions and capture credentials. Covers ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 takeover, VLAN hopping, STP manipulation, DNS spoofing, IPv6 attacks, and IDS/IPS evasion with practical tool workflows and relay chaining.

MITupdated Jun 2026
★ 1,480repo stars
Pivoting Tunneling
by blacklanternsecurity · blacklanternsecurity/red-run

This skill guides you through pivoting and tunneling strategies to reach internal networks from a compromised host during authorized penetration tests. It covers SSH port forwarding, SOCKS proxies, and specialized tools like Chisel, Ligolo-ng, and sshuttle, with a decision tree to select the right approach based on available access and network constraints.

GPL-3.0updated Apr 2026
★ 241repo stars

More skills tunneling-and-pivoting (MIT) · Windows Token Impersonation (GPL-3.0)

Tags
auth-forcingcredential-relayauthentication-attackcoercion-mechanismsecurity-testingauth-bypassrelay-attackforced-authentication