小豆罐强制认证
原名:coercing-authentication-with-coercer-petitpotam
通过Coercer扫描/强制/模糊模式触发PetitPotam及MS-RPRN等协议的机器账户认证,将NTLM中继至AD CS、LDAP或SMB,用于授权渗透中完成DC强制中继链或验证检测与签名缓解措施。
- 分类
- 学习研究
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-25
- TRACE 评分
- 2.8 / 5
内容概览
Legal Notice: This skill is for authorized security testing and educational purposes only. Authentication coercion combined with NTLM relay can yield domain compromise. Use only against systems you own or have explicit written authorization to test. Unauthorized use is illegal. Many Windows RPC interfaces expose methods that take a UNC path and cause the receiving server to authenticate to that path using its machine account . An attacker who can reach these interfaces can force a target (commonly a Domain Controller) to authenticate to an attacker-controlled host. On its own this is "Forced Authentication"; combined with an NTLM relay , the coerced machine credential is relayed to a service that does not enforce signing/EPA, most famously AD CS Web Enrollment ( ESC8 ), yielding a certificate for the Domain Controller and ultimately domain compromise. PetitPotam (Gilles Lionel / topotam)…