logo

ghostsurf: From NTLM Relay to Browser Session Hijacking

ID: aaed5fb4-0c00-52a4-ae13-f5e2327ddb08

STIX ID: report--aaed5fb4-0c00-52a4-ae13-f5e2327ddb08

Feed Name: SpecterOps Blog

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-05-01

...
...

**Ghostsurf** is a fork of `ntlmrelayx` that reworks the relay and SOCKS proxy to support interactive browser access through relayed NTLM-authenticated sessions. The author explains why the original `ntlmrelayx` SOCKS plugin fails with browsers (stateful NTLM tied to TCP, request collisions, and the tool’s basic-auth session-selection UX), introduces serialization of requests via a mutex, preserves browser headers, and implements an IIS/HTTP.sys kernel-mode workaround that probes paths to avoid dropping authenticated sessions; usage guidance, caveats (single TCP session, no WebSocket support), and example targets (enterprise password managers and other IIS sites) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.