PetitPotam is a proof-of-concept tool/technique released in July 2021 that coerces Windows systems to authenticate to arbitrary or attacker-controlled endpoints by abusing Microsoft’s Encrypting File System Remote Protocol (EFSRPC), including EfsRpcOpenFileRaw and related methods. The content associates PetitPotam with CVE-2021-36942 and describes it as a classic NTLM relay attack technique that can be used against Windows domain controllers and other Windows servers. It is particularly dangerous in environments using Active Directory Certificate Services (AD CS) where NTLM relay protections are not enabled. Multiple sources in the content state that, when combined with AD CS NTLM relay attack paths documented by SpecterOps, PetitPotam can allow an unauthenticated attacker to escalate privileges to full domain administrator under the right conditions. The content references Microsoft, CISA, and Splunk coverage of PetitPotam, as well as detection content for suspicious Kerberos TGT requests related to PetitPotam. Targeted systems are Windows hosts, especially AD CS servers, domain controllers, and other Windows servers that permit NTLM authentication without protections such as Extended Protection for Authentication (EPA) and HTTPS/Require SSL on relevant AD CS web services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This vulnerability was assigned CVE-2026-24294 and was patched in March 2026 Patch Tuesday. It works by default on Windows Server 2025 but not on Windows 11 24H2 because SMB signing is enforced.
In July 2021, a security researcher released PetitPotam, a tool that allows attackers to coerce Windows systems into authenticating to arbitrary endpoints.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Security researchers, including Unit 42, have documented the use of coercion tools such as PetitPotam (CVE-2021-36942) in actual attacks.
PetitPotam Suspicious Kerberos TGT Request ... OS Credential Dumping
PetitPotam est utilisé pour forcer le compte machine du serveur WSUS ( WSUS1$ ) à s’authentifier vers la machine de l’attaquant via MS-EFSRPC.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PetitPotam is an exploit that abuses MS-EFSRPC to coerce Windows hosts to authenticate to other machines, enabling NTLM relay attacks that can lead to domain compromise.
PetitPotam is referenced in the context of suspicious Kerberos TGT requests and credential-access-related activity.
PetitPotam is a proof-of-concept exploit tool that abuses a flaw in Windows Active Directory Certificate Services to relay NTLM authentication and gain administrative privileges.
A tool exploiting the Microsoft EFSRPC protocol issue (CVE-2021-36942) to coerce Windows systems into authenticating to arbitrary endpoints, enabling NTLM relay and potential privilege escalation to domain administrator in certain AD CS attack chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.