πŸ”—
Automation

Coercion And NTLM Relay

by ADScanPro

Coercion And NTLM Relay is an Automation skill for Claude Code, published by ADScanPro in Claude-AD.

176 stars28 forkson ADScanPro/Claude-ADAdded 2026/09/08+5% in starsRepository updated 2026/08/24
active-directoryactive-directory-securityadcsbloodhoundclaudeclaude-codeclaude-code-pluginclaude-skillsdcsynckerberoastingkerberosntlm-relayoffensive-securitypenetration-testingpentestingred-team
Install in seconds
Install Coercion And NTLM Relay
Copy Coercion And NTLM Relay into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/ADScanPro/Claude-AD/tree/main/skills/coercion-ntlm-relay ~/.claude/skills/coercion-ntlm-relay

Requires Node.js. Downloads this skill only β€” not the rest of the repository β€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/ADScanPro/Claude-AD.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/coercion-ntlm-relay/SKILL.md in ADScanPro/Claude-AD
Installs to
~/.claude/skills/coercion-ntlm-relay
Collection
One of 8 skills cataloged from this repository
Category
Automation β€” 2226 skills

What Coercion And NTLM Relay does

Coercion And NTLM Relay forces a privileged Windows account to authenticate outward, then relays NTLM to LDAP, SMB, or AD CS web enrollment. Use it for RBCD, DCSync-capable ACL writes, certificates, detection, and hardening checks.

Coercion And NTLM Relay is cataloged under Automation on DirSkills. Coercion And NTLM Relay comes from a repository tagged active-directory, active-directory-security, adcs, bloodhound and claude.

Documentation

README

Coercion + NTLM Relay

Two techniques that combine into one of the most reliable domain-compromise chains: force a target (usually a Domain Controller's machine account) to authenticate to a host you control, then relay that authentication to a service that lacks the protection to reject it. No credential cracking involved; you are borrowing a live authentication.

The chain only works when a relay target is unprotected:

  • Relay to LDAP/LDAPS requires LDAP signing not enforced and channel binding (EPA) absent.
  • Relay to SMB requires SMB signing not enforced on the destination.
  • Relay to AD CS web enrollment (ESC8) requires the HTTP enrollment endpoint up without EPA.

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Coercion And NTLM Relay

  • What else does ADScanPro publish alongside Coercion And NTLM Relay?

    Coercion And NTLM Relay is one of 8 skills that DirSkills catalogs from ADScanPro/Claude-AD, the repository it ships in. Its siblings there include AD CS Attacks, AD Environment Constraints and AD Methodology. Each one is a separate skill with its own page in this directory, installs the same way Coercion And NTLM Relay does, and is maintained by ADScanPro in that same repository. The rest of the collection is listed on the ADScanPro/Claude-AD page.

  • How does Coercion And NTLM Relay compare to other Automation skills?

    Coercion And NTLM Relay ranks #1938 by stars among the 2226 Automation skills in this catalog. The most-starred ones next to it are Autonomous Loops, Autonomous Agent Harness and Automation Audit Ops. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Coercion And NTLM Relay against them. Open each page to compare what they document and how they install.

More from ADScanPro/Claude-AD

Coercion And NTLM Relay is one of 8 skills cataloged on DirSkills from ADScanPro/Claude-AD.

See all 8 skills β†’
πŸͺͺ
1h ago

AD CS Attacks

AD CS Attacks covers Active Directory Certificate Services escalation paths ESC1 through ESC17 using Certipy. Use it to enumerate vulnerable templates or CA settings, request impersonation certificates, and review checks, event IDs, and remediation.
AI Engineering
17628
πŸ›‘οΈ
1h ago

AD Environment Constraints

AD Environment Constraints lists common Active Directory hardening checks that break NTLM, Kerberos, LDAP, and SMB operations. Use it to fingerprint domain posture and choose the right auth path, transport, and host naming before running AD tools.
AI Engineering
17628
πŸͺŸ
1h ago

AD Methodology

AD Methodology gives the phase order for an Active Directory assessment: setup, collection, exploitation, and post-processing. Use it to decide what to run next, avoid lockouts, and collect the right data before attacking.
AI Engineering
17628
πŸ›‘οΈ
1h ago

AD OPSEC Telemetry

AD OPSEC Telemetry explains the Windows events and defender alerts generated by common Active Directory techniques like Kerberoasting, AS-REP roasting, DCSync, LSASS dumping, and lateral movement. Use it to document engagement noise or to decide what to monitor.
Quality
17628
πŸ”
1h ago

Acl Abuse

Acl Abuse turns dangerous Active Directory ACLs and ownership rights into exact bloodyAD and impacket commands for privilege escalation, lateral movement, and DCSync after compromise. Use it when BloodHound CE shows an outbound control edge such as GenericAll, WriteDACL, or AddMember.
Automation
17628
πŸ—ΊοΈ
1h ago

Compliance Mapping

Compliance Mapping provides a conceptual map from Active Directory attack techniques to related compliance control families. Use it to orient a technical finding toward ENS, NIS2, or DORA without treating it as an auditor-grade control matrix.
Writing
17628