Escaping the Confines of Port 445
ID: d8bd3a34-4817-5b15-a94d-205ceb941481
STIX ID: report--d8bd3a34-4817-5b15-a94d-205ceb941481
Feed Name: SpecterOps Blog
This post outlines a technique to break out of SMB/445-only constraints during NTLM relay by using the Service Control Manager to remotely start the WebClient service via a relayed admin session, enabling WebDAV-based coercion that can be relayed to LDAP on domain controllers lacking LDAP signing/channel binding, and facilitating computer account takeover through RBCD or Shadow Credentials. It demonstrates using ntlmrelayx’s SOCKS to proxy native Windows service tools (services.msc/sc.exe) for lower detection risk, thereby expanding lateral movement options beyond SMB while avoiding common EDR alerts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
