Active Directory
ntlmrelayx (Impacket)
Relays NTLM authentications to other services for auth abuse.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Combined with Responder/coercion when signing is disabled.
How
Disable SMB on Responder; run ntlmrelayx to targets; execute or dump.
Why
One of the most important internal AD attack techniques to understand.
Commands & usage
impacket-ntlmrelayx -tf targets.txt -smb2support -i
impacket-ntlmrelayx -t ldap://dc01 -wh attacker --delegate-access
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Active Directory
Impacket
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
CrackMapExec / NetExec
Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).
BloodHound / SharpHound / AzureHound
Maps Active Directory attack paths using graph theory.
Rubeus
C# toolset for Kerberos abuse (AS-REP, kerberoast, tickets, etc.).
enum4linux-ng
SMB/Windows enumeration tool wrapping common Samba tools.
SMBMap
Enumerates Samba share drives across networks with permissions.