Skip to content

Glossary

NTLM relay

NTLM relay forwards a captured NTLM authentication attempt to another server in real time, authenticating as the victim without their password.

NTLM relay is an attack that exploits NTLM's challenge-response design by capturing an authentication attempt from a victim, whether triggered by tricking them into connecting to an attacker-controlled listener or by coercing a machine account to authenticate, and forwarding that exchange live to a different target server. Because the relayed server sees a valid response to its own challenge, it accepts the session as though the victim had authenticated directly, all without the attacker ever learning a password or hash.

This matters because it turns any exposed protocol that accepts NTLM (LDAP, SMB, HTTP, and others) into a potential privilege escalation path, and coercion techniques mean an attacker doesn't even need a victim to click anything. Mitigation includes enforcing SMB and LDAP signing plus LDAP channel binding, disabling NTLM where feasible in favor of Kerberos, and enabling Extended Protection for Authentication on services that must retain NTLM support.

See NTLM, LDAP, and SMB hardening.