Kali Linux

Coercer : A Python Script To Automatically Coerce A Windows Server To Authenticate On An Arbitrary Machine

Coercer is a python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 9 methods.

Features

  • Automatically detects open SMB pipes on the remote machine.
  • Calls one by one all the vulnerable RPC functions to coerce the server to authenticate on an arbitrary machine.
  • Analyze mode with --analyze, which only lists the vulnerable protocols and functions listening, without performing a coerced authentication.
  • Perform coerce attack on a list of targets from a file with --targets-file
  • Coerce to a WebDAV target with --webdav-host and --webdav-port

Installation

You can now install it from pypi (latest version is ) with this command:

sudo python3 -m pip install coercer

Usage

$ ./Coercer.py -h
_ / / _ ___ _ / / / _ \/ _ \/ / / _ \/ /
/ // // / / / / // / / v1.6 _/_/___// __/___// by @podalirius
usage: Coercer.py [-h] [-u USERNAME] [-p PASSWORD] [-d DOMAIN] [–hashes [LMHASH]:NTHASH] [–no-pass] [-v] [-a] [-k] [–dc-ip ip address] [-l LISTENER] [-wh WEBDAV_HOST] [-wp WEBDAV_PORT]
(-t TARGET | -f TARGETS_FILE) [–target-ip ip address]
Automatic windows authentication coercer over various RPC calls.
options:
-h, –help show this help message and exit
-u USERNAME, –username USERNAME
Username to authenticate to the endpoint.
-p PASSWORD, –password PASSWORD
Password to authenticate to the endpoint. (if omitted, it will be asked unless -no-pass is specified)
-d DOMAIN, –domain DOMAIN
Windows domain name to authenticate to the endpoint.
–hashes [LMHASH]:NTHASH
NT/LM hashes (LM hash can be empty)
–no-pass Don’t ask for password (useful for -k)
-v, –verbose Verbose mode (default: False)
-a, –analyze Analyze mode (default: Attack mode)
-k, –kerberos Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ones specified in the
command line
–dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
-t TARGET, –target TARGET
IP address or hostname of the target machine
-f TARGETS_FILE, –targets-file TARGETS_FILE
IP address or hostname of the target machine
–target-ip ip address
IP Address of the target machine. If omitted it will use whatever was specified as target. This is useful when target is the NetBIOS name or Kerberos name and you cannot resolve it
-l LISTENER, –listener LISTENER
IP address or hostname of the listener machine
-wh WEBDAV_HOST, –webdav-host WEBDAV_HOST
WebDAV IP of the server to authenticate to.
-wp WEBDAV_PORT, –webdav-port WEBDAV_PORT
WebDAV port of the server to authenticate to.

Coerced WebDAV authentication demonstration

If you want to trigger an HTTP authentication, you can use WebDAV with --webdav-host and the netdbios name of your attacking machine!

Example output

In attack mode (without --analyze option) you get the following output:

After all the RPC calls, you get plenty of authentications in Responder:

R K

Recent Posts

Best OSINT Tools for Journalists 2026: Verify Sources, Images and Claims

Journalists use OSINT to verify public information before publishing. In 2026, misinformation, AI-generated images, fake…

9 hours ago

Install Docker on Ubuntu 20.04: Complete Step-by-Step Guide

Docker is an open-source platform that lets you package and run applications inside containers. Each container…

19 hours ago

Install PostgreSQL on Ubuntu: Database Setup and Admin Guide

PostgreSQL (often called Postgres) is an open-source relational database system. It supports advanced features like JSON…

20 hours ago

Install Xrdp Remote Desktop on Ubuntu: Setup and Connect

Xrdp is an open-source server that lets you connect to your Ubuntu machine from another computer…

20 hours ago

Tomcat 9 on Ubuntu 20.04: Install, Configure, and Start

Apache Tomcat is an open-source web server and Java servlet container. It is one of the…

21 hours ago

Automatic Updates on Ubuntu: Set Up unattended-upgrades

Keeping your Ubuntu system updated is one of the best ways to protect it. Security…

22 hours ago