
CVE-2026-62911
Proof-of-concept exploit for CVE-2026-62911: pre-auth RCE on Microsoft Exchange via NTLM relay to MRSProxy, writing an ASPX webshell for SYSTEM…

Proof-of-concept exploit for CVE-2026-62911: pre-auth RCE on Microsoft Exchange via NTLM relay to MRSProxy, writing an ASPX webshell for SYSTEM…

Zeek package for detecting PetitPotam NTLM relay attacks via EFS DCERPC over unencrypted SMB, distinguishing successful and unsuccessful exploit…

Rust-based proof-of-concept that generates Windows Library (.library-ms) files with configurable network paths to demonstrate CVE-2025-24071 NTLM…

Proof-of-concept tool that chains DNS injection, NTLM relay, and RPC-based coercion to test authentication relay paths in Windows Active Directory…

Technical Reference to multiple relay techniques

Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability

Metabase NTLM Attack

Zeek package detecting CVE-2022-30216 NTLM relay attacks against Windows Server. Raises notices for exploit attempts and successful exploitation via…

Proof-of-concept exploit for CVE-2025-24071, leveraging a crafted ZIP file to trigger SMB authentication relay and capture NTLM hashes via Impacket.

SMB Red Team Lab— NTLM Relay via LLMNR Poisoning, CVE-2007-2447, NTLMv2 Hash Cracking & NT AUTHORITY\SYSTEM on Windows 10

Detects NTLM authentication status by checking LmCompatibilityLevel registry value to assess exposure to CVE-2024-43451 and mitigate credential relay…