Operating Outside the Box: NTLM Relaying Low-Privilege HTTP Auth to LDAP
ID: 373c05b2-f69e-5d0a-ad5e-e20bba8e52ac
STIX ID: report--373c05b2-f69e-5d0a-ad5e-e20bba8e52ac
Feed Name: SpecterOps Blog
This report details a technique to harvest NTLM HTTP authentication from a low-privileged Windows user and relay it to LDAP via Impacket ntlmrelayx’s SOCKS capability, enabling off-host LDAP operations from Linux tooling (e.g., certipy) through a C2 SOCKS5 proxy; it provides implementation steps (Mythic/Apollo, proxychains), a small C# utility to trigger Windows auth, and concludes with defensive recommendations to require LDAP signing and LDAPS channel binding to prevent such relays.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
