logo

Operating Outside the Box: NTLM Relaying Low-Privilege HTTP Auth to LDAP

ID: 373c05b2-f69e-5d0a-ad5e-e20bba8e52ac

STIX ID: report--373c05b2-f69e-5d0a-ad5e-e20bba8e52ac

Feed Name: SpecterOps Blog

Date Published: 2025-08-22

Date Updated: 2026-04-30

Author: Logan Goins

...
...

This report details a technique to harvest NTLM HTTP authentication from a low-privileged Windows user and relay it to LDAP via Impacket ntlmrelayx’s SOCKS capability, enabling off-host LDAP operations from Linux tooling (e.g., certipy) through a C2 SOCKS5 proxy; it provides implementation steps (Mythic/Apollo, proxychains), a small C# utility to trigger Windows auth, and concludes with defensive recommendations to require LDAP signing and LDAPS channel binding to prevent such relays.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.