← All Lessons
Premium

TechniqueActive Directory

NTLM Relay to Kerberos (Coercion Chain)

Relaying coerced NTLM authentication to LDAP lets an attacker write a directory attribute instead of merely opening a session, turning one borrowed authentication into a durable Kerberos primitive. This lesson explains how the RBCD and Shadow Credentials writes work, why the access survives a password change, and how to communicate the risk clearly in interviews, reports, and stakeholder conversations.

Sign in or upgrade to unlock the full premium library.

What you'll learn

  • Relay over LDAP
  • Resource-based constrained delegation (RBCD)
  • Shadow Credentials
  • Kerberos as the payoff
  • Signing forces the HTTP path
  • Attacker computer account

What premium includes

  • All 78 lessons: AD techniques, professional skills, each with interview answers and study kits
  • Complete study kit for every lesson: quizzes, flashcards, and briefs
  • Every learning track with full structured progression
  • All 12 attack paths: full compromise walkthroughs for interviews and reports
  • New lessons and attack paths added regularly

Continue with free content