ntlm-relay-coercion

Relay NTLM authentication to SMB, LDAP, HTTP, and MSSQL targets.

Updated Jun 11, 2026
One-click install
npx skills add https://github.com/utsavthakur/agenticskills --skill ntlm-relay-coercion-utsavthakur
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ntlm-relay-coercion
Source: https://github.com/utsavthakur/agenticskills/tree/main/ntlm-relay-coercion
Command: npx skills add https://github.com/utsavthakur/agenticskills --skill ntlm-relay-coercion-utsavthakur

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides expert-level NTLM relay and authentication coercion methods to exploit system vulnerabilities and escalate privileges.

Core Features & Use Cases

  • NTLM Relay: Captures and relays NTLM authentication to escalate privileges via SMB, LDAP, HTTP, or MSSQL relay targets.
  • Coercion Methods: Implements PetitPotam, PrinterBug, and other major coercion methods for domain controllers, file servers, and workstations.
  • Use Case: When you need to conduct advanced NTLM relay attacks to bypass authentication and gain unauthorized access to systems.

Quick Start

Load the skill and execute the ntlmrelayx.py script to relay NTLM authentication and escalate privileges.

Frequently Asked Questions about ntlm-relay-coercion

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How does NTLM relay exploitation work for privilege escalation?

NTLM relay exploitation works by intercepting authentication attempts and forwarding them to downstream services like SMB, LDAP, or HTTP to bypass access controls and escalate privileges.

What coercion methods can force NTLM authentication from domain controllers?

Coercion methods like PetitPotam and PrinterBug force domain controllers, file servers, and workstations to initiate NTLM authentication, allowing the relay to capture and forward the traffic.

How do I relay NTLM authentication to an SMB or LDAP target?

You can relay NTLM authentication by loading the skill and executing the ntlmrelayx.py script to intercept traffic and forward it to SMB, LDAP, HTTP, or MSSQL relay targets.

Does this NTLM relay approach work with MSSQL and HTTP targets?

Yes, the NTLM relay techniques support MSSQL and HTTP relay targets, alongside SMB and LDAP, allowing you to exploit authentication across multiple service protocols.

What do I need to know before using NTLM relay and coercion techniques?

You need advanced knowledge of NTLM authentication mechanisms, system vulnerabilities, and exploitation methods to effectively use these relay and coercion techniques.