If you’re anything like me and/or an offensive security professional, you’re probably very, very familiar with NTLM relaying attacks against Active Directory environments. NTLM relay attacks are anything but novel; pentesters and hackers alike have been forcing blue teams and sysadmins all around the world for decades to pull their hair out as they attempt to mitigate this class of issue. This blog will not explain what this issue is – if you want more information, a quick Google search for “ntlm relaying” will yield numerous excellent blog posts explaining the core issue.