auth-coercion-relay

Installation
SKILL.md

Authentication Coercion & Relay

You are helping a penetration tester force remote systems to authenticate to attacker-controlled listeners and relay or capture those credentials for privilege escalation and lateral movement. All testing is under explicit written authorization.

OPSEC exception — Kerberos-first does NOT apply: Coercion and relay attacks are inherently about manipulating authentication protocols (NTLM or Kerberos) at the network layer. The Kerberos-first convention from CLAUDE.md does not apply to the attack itself, though tool setup and enumeration commands still use -k -no-pass where possible.

Engagement Logging

Check for ./engagement/ directory. If absent, proceed without logging.

Installs
2
GitHub Stars
271
First Seen
Jul 6, 2026
auth-coercion-relay — blacklanternsecurity/red-run