← All Lessons
Premium
TechniqueActive Directory
NTLM Relay to Kerberos (Coercion Chain)
Relaying coerced NTLM authentication to LDAP lets an attacker write a directory attribute instead of merely opening a session, turning one borrowed authentication into a durable Kerberos primitive. This lesson explains how the RBCD and Shadow Credentials writes work, why the access survives a password change, and how to communicate the risk clearly in interviews, reports, and stakeholder conversations.
Sign in or upgrade to unlock the full premium library.
What you'll learn
- Relay over LDAP
- Resource-based constrained delegation (RBCD)
- Shadow Credentials
- Kerberos as the payoff
- Signing forces the HTTP path
- Attacker computer account
What premium includes
- All 78 lessons: AD techniques, professional skills, each with interview answers and study kits
- Complete study kit for every lesson: quizzes, flashcards, and briefs
- Every learning track with full structured progression
- All 12 attack paths: full compromise walkthroughs for interviews and reports
- New lessons and attack paths added regularly