Install the "coercion-ntlm-relay" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/coercion-ntlm-relay into .claude/skills/coercion-ntlm-relay/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coercion-ntlm-relay", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "coercion-ntlm-relay" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/coercion-ntlm-relay into .agents/skills/coercion-ntlm-relay/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coercion-ntlm-relay", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "coercion-ntlm-relay" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/coercion-ntlm-relay into .cursor/skills/coercion-ntlm-relay/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coercion-ntlm-relay", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "coercion-ntlm-relay" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/coercion-ntlm-relay into .gemini/skills/coercion-ntlm-relay/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coercion-ntlm-relay", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "coercion-ntlm-relay" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/coercion-ntlm-relay into .github/skills/coercion-ntlm-relay/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coercion-ntlm-relay", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "coercion-ntlm-relay" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/coercion-ntlm-relay into .opencode/skills/coercion-ntlm-relay/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coercion-ntlm-relay", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
coercion-ntlm-relay
GitHub stars
211
Token cost
~1.9k tokens
SKILL.md length
819 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT
At a glance
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.
Works in 4 steps: Confirm an unprotected relay target… → Start ntlmrelayx.py pointed at LDAP / AD… → Coerce the DC (or other privileged host)… → …
SMB signing is not enforced
SKILL.md covers Part 1: Coercion, Part 2: NTLM Relay (impacket…, Full chain (order of operations) and Detection (Event IDs), plus 2 more sections
Calls python3
What it does
Coercion Ntlm Relay is an agent skill from ADScanPro/Claude-AD. Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Use when SMB signing is not enforced or LDAP channel binding is missing, and you want to force a privileged machine account to authenticate to your relay and turn that into RBCD, a DCSync-capable ACL grant, or a certificate. Includes the exact Coercer/ntlmrelayx commands, requirements, detection, and remediation.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing, Red teaming and adversary simulation and Authentication. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.
When your agent uses it
SMB signing is not enforced
LDAP channel binding is missing
You want to force a privileged machine account to authenticate to your relay and turn that into RBCD
A DCSync-capable ACL grant
Example prompts
“/coercion-ntlm-relay”
Requirements
Python 3
Workflow steps
4 steps, taken from the first numbered list in SKILL.md.
1Confirm an unprotected relay target (--gen-relay-list, LDAP signing/CBT check).
2Start ntlmrelayx.py pointed at LDAP / AD CS / SMB.
3Coerce the DC (or other privileged host) to authenticate to your relay IP with Coercer/PetitPotam/PrinterBug/DFSCoerce.
4Consume the result: RBCD → S4U (Kerberos skill), ESC8 cert → PKINIT (AD CS skill), or SMB action.
What it can do on your machine
Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
python3
From the folder's file list and the shell code blocks in SKILL.md.
Network
Links to these hosts (documentation or services it may open):
thehacker.recipes
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Coercion Ntlm Relay loads about 1.9k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 819 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~129
When it runs· the whole SKILL.md, loaded when a task matches
~1.9k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/coercion-ntlm-relay/SKILL.md (or your agent's skills folder).
name
coercion-ntlm-relay
description
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Use when SMB signing is not enforced or LDAP channel binding is missing, and you want to force a privileged machine account to authenticate to your relay and turn that into RBCD, a DCSync-capable ACL grant, or a certificate. Includes the exact Coercer/ntlmrelayx commands, requirements, detection, and remediation.
Coercion + NTLM Relay
Two techniques that combine into one of the most reliable domain-compromise chains: force a target (usually a Domain Controller's machine account) to authenticate to a host you control, then relay that authentication to a service that lacks the protection to reject it. No credential cracking involved; you are borrowing a live authentication.
The chain only works when a relay target is unprotected:
Relay to LDAP/LDAPS requires LDAP signing not enforced and channel binding (EPA) absent.
Relay to SMB requires SMB signing not enforced on the destination.
Relay to AD CS web enrollment (ESC8) requires the HTTP enrollment endpoint up without EPA.
Check signing posture first:
nxc smb 10.0.0.0/24 --gen-relay-list relay_targets.txt # hosts without SMB signing
nxc ldap 10.0.0.10 -u user -p 'Password123' -M ldap-checker # LDAP signing / channel binding state
Part 1: Coercion
You need a way to make a privileged account authenticate outbound to your IP. Three RPC-based coercion methods, each abusing a different protocol. All fire the target's machine account ($) authentication at you.
PetitPotam: MS-EFSR (Encrypting File System Remote)
MITRE ATT&CK: T1187 (Forced Authentication)
Abuses the EFSRPC interface (EfsRpcOpenFileRaw and related). Often works unauthenticated against unpatched DCs; authenticated on patched ones.
Relaying a DC's machine account to LDAP lets you write directory objects as that machine. The --delegate-access flow configures RBCD so you can then S4U to the coerced host (Kerberos skill). Requires LDAP signing not enforced and channel binding absent.
After the relay writes RBCD, S4U (see Kerberos skill). A relayed DC can also be pushed to grant a controlled principal replication rights (the WriteDACL-on-domain-head path in the ACL skill), which then enables DCSync as a post-compromise step.
Relay to AD CS web enrollment: ESC8
MITRE ATT&CK: T1557.001 / T1187
Relay the coerced DC machine account to the CA's HTTP web-enrollment endpoint and enroll a certificate as that DC. Then PKINIT the cert to a TGT (AD CS skill). Requires the web-enrollment endpoint up without EPA.
Confirm an unprotected relay target (--gen-relay-list, LDAP signing/CBT check).
Start ntlmrelayx.py pointed at LDAP / AD CS / SMB.
Coerce the DC (or other privileged host) to authenticate to your relay IP with Coercer/PetitPotam/PrinterBug/DFSCoerce.
Consume the result: RBCD → S4U (Kerberos skill), ESC8 cert → PKINIT (AD CS skill), or SMB action.
Show full SKILL.md (300 more words)Show less
Detection (Event IDs)
4624 (successful logon) with Logon Type 3 and NTLM authentication package, where the account is a machine account ($) authenticating to a host it has no business reaching (the relay endpoint). Machine-to-machine NTLM to a non-standard destination is the core signal.
4662 on the domain object if the relay wrote replication rights; 5136 for the RBCD / DACL / owner writes the relayed session performs (see ACL skill).
4886/4887 on the CA for the ESC8 certificate request/issuance.
5145 (network share object checked) and Spooler/DFS RPC activity on the coerced host around the coercion call.
Defender for Identity raises alerts for suspected NTLM relay and for the coercion RPC patterns.
Remediation to write up
Enforce SMB signing (require, not just enable) on all hosts, DCs included. This alone breaks SMB relay.
Enforce LDAP signing and enable LDAP channel binding (EPA) on Domain Controllers. This breaks the LDAP relay path (Microsoft's hardening, e.g. the LDAP channel-binding/signing enforcement updates).
Enable EPA and require HTTPS on AD CS web enrollment; disable HTTP; disable web enrollment if unused. This closes ESC8.
Restrict/patch the coercion surface: apply the PetitPotam patch, disable the Print Spooler on DCs and servers that do not print, and apply DFSCoerce mitigations. Coercion methods are many, so relay-target hardening (signing/EPA) is the durable fix.
RestrictReceivingNTLMTraffic / RestrictSendingNTLMTraffic GPOs to constrain NTLM, and ultimately move toward disabling NTLM where feasible.
Put Tier-0 accounts in Protected Users so their NTLM cannot be relayed.
Alert on machine-account NTLM logons to unexpected hosts (4624 type 3 NTLM from $ accounts).
Only run coercion and relay against systems you are explicitly authorized to test. Coercion generates real authentication traffic and can disrupt services. Use lab/generic IPs, hostnames and CA names in write-ups.
Coercion Ntlm Relay next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync…
Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…
Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…
Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…
Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…
Deploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment…
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…
The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Coercion Ntlm Relay is an agent skill from ADScanPro/Claude-AD. Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.
When should I use Coercion Ntlm Relay?
Coercion Ntlm Relay fits situations like: SMB signing is not enforced; LDAP channel binding is missing; you want to force a privileged machine account to authenticate to your relay and turn that into RBCD; A DCSync-capable ACL grant.
How do I install Coercion Ntlm Relay in Claude Code?
Run `npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a claude-code`. Or copy the skill folder (skills/coercion-ntlm-relay in ADScanPro/Claude-AD) into .claude/skills/coercion-ntlm-relay in your project. Claude Code loads it when a task matches its description.
How do I install Coercion Ntlm Relay in Codex?
Run `npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a codex`. Or copy the skill folder (skills/coercion-ntlm-relay in ADScanPro/Claude-AD) into .agents/skills/coercion-ntlm-relay in your project. Codex loads it when a task matches its description.
Can I use Coercion Ntlm Relay in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill coercion-ntlm-relay -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/coercion-ntlm-relay, .gemini/skills/coercion-ntlm-relay, .github/skills/coercion-ntlm-relay and .opencode/skills/coercion-ntlm-relay in your project.
What does Coercion Ntlm Relay need to run?
Going by SKILL.md and its folder, Coercion Ntlm Relay needs the command-line tools its instructions call (python3). Our summary lists: Python 3.
Does Coercion Ntlm Relay access the network?
SKILL.md names 1 domain. As links in the text: thehacker.recipes. This is read from the text; nothing was executed.
Is Coercion Ntlm Relay safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Coercion Ntlm Relay use?
Coercion Ntlm Relay is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Coercion Ntlm Relay use?
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Coercion Ntlm Relay?
Skills that share tags, products or a category with Coercion Ntlm Relay: Building Identity Federation With Saml Azure Ad (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Cybersecurity (ohmyjahh/xquads-squads, 277 stars), Detecting T1548 Abuse Elevation Control Mechanism (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Exploiting Vulnerabilities With Metasploit Framework (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Coercion Ntlm Relay?
ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 211 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.
Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.