
A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.

This repository contains a list of many methods to coerce a windows machine to authenticate to an attacker-controlled machine.
All of these methods are callable by a standard user in the domain to force the machine account of the target Windows machine (usually a domain controller) to authenticate to an arbitrary target. The root cause of this "vulnerability/feature" in each of these methods is that Windows machines automatically authenticate to other machines when trying to access UNC paths (like \\192.168.2.1\SYSVOL\file.txt).
There are currently 30 working functions in 13 protocols.
[MS-COMA]: Component Object Model Plus (COM+) Remote Administration Protocol
[MS-DFSNM]: Distributed File System (DFS) Namespace Management Protocol
[MS-DHCPM]: Microsoft Dynamic Host Configuration Protocol (DHCP) Server Management Protocol
[MS-DNSP]: Domain Name Service (DNS) Server Management Protocol
[MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol