← All Lessons
Premium
TechniqueActive Directory
NTLM Relay Attacks
NTLM relay attacks intercept a legitimate NTLM authentication exchange and forward it to a different target, gaining authenticated access as the relayed identity without knowing the password or cracking the hash. This lesson explains why relay works, what conditions enable it, what the attacker gains, and how to communicate the risk clearly in interviews, reports, and stakeholder conversations.
Sign in or upgrade to unlock the full premium library.
What you'll learn
- Relay versus cracking
- NTLM lacks mutual authentication
- SMB signing
- LDAP signing and channel binding
- Extended Protection for Authentication (EPA)
- Authentication coercion
What premium includes
- All 68 lessons: AD techniques, professional skills, each with interview answers and study kits
- Complete study kit for every lesson: quizzes, flashcards, and briefs
- Every learning track with full structured progression
- All 12 attack paths: full compromise walkthroughs for interviews and reports
- New lessons and attack paths added regularly