B3AR 5a47a55305 Enhance README with image and tool functionality details
Added an image and expanded on the functionality of the SOCKS-focused NTLM relay tool.
2026-08-03 16:58:38 +02:00
2026-08-03 16:56:16 +02:00
2026-08-03 16:56:16 +02:00
2026-08-03 16:56:16 +02:00

SOCKSRelayd

SOCKS-focused NTLM relay with persistent session packages and a long-lived SessionBank that owns authenticated TCP connections.

image

Stock ntlmrelayx -socks keeps live relays and NTLM spoof material only in process memory. Quit the tool and everything is gone — even though keepalives would have held those SMB sessions all day. This tool splits that state:

Piece Where it lives Survives shell quit?
Live TCP + SMB SessionId Background SessionBank (keepalives) Yes, until shutdown / --stop-bank
NTLM spoof packages (CHALLENGE_MESSAGE, hashes) --session-dir on disk Yes
Fake SOCKS listener Owned by the bank daemon Survives shell detach

Install

pipx install git+https://github.com/mverschu/SOCKSRelayd

# Or from a local clone:
pipx install /path/to/SOCKSRelayd

Upgrade:

pipx install git+https://github.com/mverschu/SOCKSRelayd --force

The socksrelayd command is installed.

Hard limit

NTLM Type 3 messages are challenge-bound. Packages on disk cannot recreate a SOCKS relay after the target TCP session is dead (network drop, server timeout, bank process killed). In that case you still keep an inventory and any captured NetNTLM hashes; you need a new victim auth (or credentials) for a live session again.

Quick start

# Starts a background bank daemon (listeners + SOCKS + keepalives), then a shell.
# Ctrl+C / exit only detaches — the bank keeps running.
socksrelayd -t smb://10.10.10.50

socksrelayd> socks          # live sessions
socksrelayd> packages       # on-disk NTLM packages
socksrelayd> socks stop     # drop SOCKS only — bank keeps TCP
socksrelayd> socks start    # reload packages, bind SOCKS again
socksrelayd> exit           # detach; daemon still alive

Re-attach later (no new listeners):

socksrelayd --attach-bank

Stop the bank when you are done:

socksrelayd> shutdown
# or from another terminal:
socksrelayd --stop-bank

Use sessions like stock ntlmrelayx:

proxychains smbclient.py -no-pass 'DOMAIN/user@10.10.10.50'

Modes

Mode Behavior
(default) Fork bank daemon to background, attach shell; Ctrl+C detaches
--attach-bank Shell only against an existing daemon
--stop-bank Tell the daemon to exit
--bank-daemon Foreground daemon, no shell (for supervisord / tmux)
--foreground Old all-in-one process; Ctrl+C stops bank + shell

IPC socket default: ~/.socksrelayd/bank.sock (--ipc-path to override). Daemon log: ./relay-sessions/bank-daemon.log.

Session directory layout

relay-sessions/
  index.jsonl           # append-only metadata (id, target, user, status, …)
  packages/<id>.json    # serialized sessionData (CHALLENGE_MESSAGE, JOHN_OUTPUT, …)
  bank-daemon.log       # stdout/stderr from the background bank

Useful flags

Flag Meaning
-t / -tf Relay target(s)
--session-dir Package + index directory (default ./relay-sessions)
--keepalive Keepalive interval seconds (default 30)
-socks-port / -socks-address SOCKS bind
--http-server Also enable HTTP relay listener (SMB is default)
--no-smb-server Disable SMB listener
-no-socks Persist packages / bank without SOCKS frontend
--foreground Single process (Ctrl+C kills bank)
S
Description
Automated archival mirror of github.com/mverschu/SOCKSRelayd
Readme
47 KiB
Languages
Python 100%