Hunting Ntlm Coercion And Relay

Hunt authentication coercion and relay on a Windows network, where an attacker induces a privileged machine or account to authenticate to a host it controls and forwards that authentication to a service that does not bind or verify the channel, authenticating as the coerced identity because signing is not enforced and channel binding is absent. Use when services accept network authentication without mandatory signing or channel binding and a privileged host can be induced to authenticate outbound. Covers coercion triggers, relay to directory, certificate, and file services, missing signing, and absent channel binding. The coerced outbound authentication is the source, the relaying service accepting it is the sink, and acting as the coerced privileged identity is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-ntlm-coercion-and-relay commit 92a3df563a

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-ntlm-coercion-and-relay