Skip to content

Glossary

PetitPotam

PetitPotam is an authentication coercion technique that abuses the MS-EFSR protocol to force a Windows host, often a DC, to authenticate elsewhere.

PetitPotam, disclosed in 2021, abuses functions of the Encrypting File System Remote Protocol (MS-EFSR) to make a Windows machine connect to an attacker-chosen host and authenticate with its machine account. Early variants required no credentials at all. It belongs to a family of coercion techniques alongside the Print Spooler "PrinterBug", DFSCoerce and ShadowCoerce. On its own, coercion only produces an authentication attempt; the danger comes from relaying that NTLM authentication to a service that accepts it.

It matters because coercing a domain controller and relaying its authentication to AD CS web enrollment (ESC8) or to LDAP can yield a certificate or rights for the DC's computer account, which leads straight to DCSync and full domain compromise. Defend in layers: install current patches, block unnecessary EFS and other coercible RPC interfaces with RPC filters, disable the Print Spooler on DCs, enforce Extended Protection for Authentication and HTTPS on AD CS endpoints, and require LDAP signing and channel binding so relayed authentication fails.

See Blocking authentication coercion and Securing AD CS web enrollment.