logo

Enumerating EPA Enforcement for MSSQL and HTTPS

ID: 918b440d-6a9b-56fe-851e-1a6af4f89d8d

STIX ID: report--918b440d-6a9b-56fe-851e-1a6af4f89d8d

Feed Name: SpecterOps Blog

Date Published: 2025-11-25

Date Updated: 2026-04-30

Author: Nick Powers; Matt Creel

...
...

The report presents a practical methodology and tooling (RelayInformer in Python and BOFs) to enumerate Extended Protection for Authentication (EPA) on MSSQL and HTTP/S services, enabling operators to determine whether NTLM relay attacks are viable before investing effort. It explains EPA fundamentals (channel vs service binding), highlights implementation nuances (MSSQL supports both bindings by default; IIS GUI typically protects only HTTPS via channel binding unless service binding is manually configured), and outlines error-driven tests to distinguish disabled/allowed/required enforcement states (some requiring valid credentials). The work complements existing LDAPS checks, improves offensive decision-making, and provides defender guidance to set EPA to allowed or required to reduce relay risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.