coercer

Installation
SKILL.md

Coercer

Force Windows servers to authenticate (NTLM) to your listener — enables relay, capture, and hash extraction.

Concept

Coercer abuses multiple RPC protocols/methods that trigger a Windows host to initiate an outbound NTLM authentication to an attacker-controlled IP. The captured Net-NTLMv2 hash can be:

  • Cracked offline (Hashcat/John)
  • Relayed in real-time (ntlmrelayx) to access other systems

Quick Start

# Coerce auth from a server, capture with Responder
# Terminal 1: Start Responder
responder -I eth0 -wv
Installs
5
GitHub Stars
22
First Seen
Apr 16, 2026
coercer — aeondave/malskill