There and Back Again: An Operators Guide on NTLM Relaying Egress
ID: 68d723d0-cd07-5ab8-82ea-33473ad7e7f7
STIX ID: report--68d723d0-cd07-5ab8-82ea-33473ad7e7f7
Feed Name: SpecterOps Blog
This SpecterOps blog describes the "There and Back Again" NTLM relay technique: coercing NTLM (SMB/WebDAV) authentication to an internet-facing cloud VM, capturing the challenge/response, and proxying it back into a target network to relay to LDAP or ADCS endpoints for certificate issuance, PKINIT/S4U-based ticket abuse, and ultimately domain compromise. The post includes operational steps, tooling and configuration examples (Azure VM forwarding, iptables, SSH reverse tunnels, ntlmrelayx, PetitPotam, certipy), real-world considerations (firewall egress, WebClient/EFS requirements), and defensive guidance (enable LDAP signing/channel binding, ADCS EPA, restrict SMB egress).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
