Added an image and expanded on the functionality of the SOCKS-focused NTLM relay tool.
SOCKSRelayd
SOCKS-focused NTLM relay with persistent session packages and a long-lived SessionBank that owns authenticated TCP connections.
Stock ntlmrelayx -socks keeps live relays and NTLM spoof material only in
process memory. Quit the tool and everything is gone — even though keepalives
would have held those SMB sessions all day. This tool splits that state:
| Piece | Where it lives | Survives shell quit? |
|---|---|---|
| Live TCP + SMB SessionId | Background SessionBank (keepalives) | Yes, until shutdown / --stop-bank |
NTLM spoof packages (CHALLENGE_MESSAGE, hashes) |
--session-dir on disk |
Yes |
| Fake SOCKS listener | Owned by the bank daemon | Survives shell detach |
Install
pipx install git+https://github.com/mverschu/SOCKSRelayd
# Or from a local clone:
pipx install /path/to/SOCKSRelayd
Upgrade:
pipx install git+https://github.com/mverschu/SOCKSRelayd --force
The socksrelayd command is installed.
Hard limit
NTLM Type 3 messages are challenge-bound. Packages on disk cannot recreate a SOCKS relay after the target TCP session is dead (network drop, server timeout, bank process killed). In that case you still keep an inventory and any captured NetNTLM hashes; you need a new victim auth (or credentials) for a live session again.
Quick start
# Starts a background bank daemon (listeners + SOCKS + keepalives), then a shell.
# Ctrl+C / exit only detaches — the bank keeps running.
socksrelayd -t smb://10.10.10.50
socksrelayd> socks # live sessions
socksrelayd> packages # on-disk NTLM packages
socksrelayd> socks stop # drop SOCKS only — bank keeps TCP
socksrelayd> socks start # reload packages, bind SOCKS again
socksrelayd> exit # detach; daemon still alive
Re-attach later (no new listeners):
socksrelayd --attach-bank
Stop the bank when you are done:
socksrelayd> shutdown
# or from another terminal:
socksrelayd --stop-bank
Use sessions like stock ntlmrelayx:
proxychains smbclient.py -no-pass 'DOMAIN/user@10.10.10.50'
Modes
| Mode | Behavior |
|---|---|
| (default) | Fork bank daemon to background, attach shell; Ctrl+C detaches |
--attach-bank |
Shell only against an existing daemon |
--stop-bank |
Tell the daemon to exit |
--bank-daemon |
Foreground daemon, no shell (for supervisord / tmux) |
--foreground |
Old all-in-one process; Ctrl+C stops bank + shell |
IPC socket default: ~/.socksrelayd/bank.sock (--ipc-path to override).
Daemon log: ./relay-sessions/bank-daemon.log.
Session directory layout
relay-sessions/
index.jsonl # append-only metadata (id, target, user, status, …)
packages/<id>.json # serialized sessionData (CHALLENGE_MESSAGE, JOHN_OUTPUT, …)
bank-daemon.log # stdout/stderr from the background bank
Useful flags
| Flag | Meaning |
|---|---|
-t / -tf |
Relay target(s) |
--session-dir |
Package + index directory (default ./relay-sessions) |
--keepalive |
Keepalive interval seconds (default 30) |
-socks-port / -socks-address |
SOCKS bind |
--http-server |
Also enable HTTP relay listener (SMB is default) |
--no-smb-server |
Disable SMB listener |
-no-socks |
Persist packages / bank without SOCKS frontend |
--foreground |
Single process (Ctrl+C kills bank) |