Skip to main content

coerce

The coerce command performs authentication coercion attacks — forcing a remote machine to authenticate back to an attacker-controlled listener using various Windows RPC protocols. This is used to capture Net-NTLMv2 hashes or relay authentication to other services (e.g., LDAP, SMB, ADCS web enrollment).

Usage


Common Flags

These flags are shared across all coercion methods:

Relay Flags

When --relay <host> is set, R4t starts a built-in relay server alongside the coercion attack and forwards captured authentication to the specified target. These flags are available on every method subcommand.

ADCS Relay Options

These flags apply when using --adcs (or when no relay type is specified, since ADCS is the default).

Shadow Credentials Relay Options


Subcommands

coerce petitpotam

Coerce authentication via MS-EFSRPC (Encrypting File System Remote Protocol). This is the most widely applicable coercion method.
R4t tries each of these named pipes in sequence:
  1. lsarpc
  2. efsr
  3. samr
  4. lsass
  5. netlogon
Use --incremental (default) to prompt before each pipe, allowing you to stop if authentication is captured.

coerce dfscoerce

Coerce authentication via MS-DFSNM (Distributed File System Namespace Management Protocol).

coerce mseven

Coerce authentication via MS-EVEN6 (Event Log Remoting Protocol Version 6).

coerce shadowcoerce

Coerce authentication via MS-FSRVP (File Server Remote VSS Protocol). Commonly referred to as ShadowCoerce.

coerce printerbug

Coerce authentication via MS-RPRN (Print System Remote Protocol). This is the original “PrinterBug” / SpoolSample method.

coerce interactive

A split-panel interactive TUI that runs a listener on one side and coercion on the other simultaneously, giving real-time feedback on captured authentications.

TUI Controls


How Coercion Works

Authentication coercion exploits Windows RPC protocols that make outbound network calls using the machine account’s credentials. When you trigger one of these calls with a listener IP as the destination, the target machine authenticates to your listener.
The captured authentication can be:
  • Cracked offline (Net-NTLMv2 → password)
  • Relayed to another service (LDAP, SMB, ADCS web enrollment)

Common Coercion Workflows

Capture and Crack

Relay to LDAP (Privilege Escalation via RBCD)

Relay to ADCS Web Enrollment (ESC8)

R4t has a built-in relay for ADCS — no external ntlmrelayx needed. --template is required.

Coercible Host Discovery

Before coercing, identify which hosts are susceptible:

Coercible Hosts Database

Hosts identified as potentially coercible are stored in the coercables table: