logo

I’m bringing relaying back: A comprehensive guide on…

ID: 33088bd2-fd8d-5fd3-8469-b9112f1d21de

STIX ID: report--33088bd2-fd8d-5fd3-8469-b9112f1d21de

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This blog post provides a comprehensive, hands-on walkthrough of NTLM relaying and Active Directory abuse techniques. Using a Windows lab, the author demonstrates reconnaissance with Responder and CrackMapExec, classic SMB-to-SMB relays, SOCKS proxy chaining, LDAP/LDAPS relays (including creating computer accounts), resource-based constrained delegation abuse, shadow-credential PKINIT attacks, and certificate-enrollment (ESC8) abuse — illustrating how broadcast protocols, coerced authentication (PetitPotam/printerbug), and AD misconfigurations can enable domain compromise. The post lists required tools, demonstrates exploit sequences, and concludes with defensive advice such as disabling broadcast protocols and patching tier-0 systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.