impacket-ntlmrelayx
Fail
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains multiple command-line examples for
ntlmrelayx.py, which is an offensive security tool from the Impacket suite. - The provided commands enable high-risk operations such as relaying authentication to SMB for shell access or to LDAP/LDAPS for Active Directory exploitation.
- Specific flags like
--delegate-accessand--add-computerare used for privilege escalation via resource-based constrained delegation or unauthorized account creation. - These techniques represent a significant security risk as they allow for the exploitation of NTLM authentication vulnerabilities to gain unauthorized control over networked systems and domains.
Recommendations
- AI detected serious security threats
Audit Metadata