Exchange your privileges for Domain Admin privs by abusing Exchange
Branch: master
Clone or download
Type Name Latest commit message Commit time
Failed to load latest commit information.
.gitignore Initial release Jan 21, 2019
LICENSE Initial commit Jan 21, 2019 Initial release Jan 21, 2019 Initial release Jan 21, 2019 Remove _SP3 dialect, which doesnt exist. Also add message if server r… Feb 11, 2019


POC tools accompanying the blog Abusing Exchange: One API call away from Domain Admin.


These tools require impacket. You can install it from pip with pip install impacket, but it is recommended to use the latest version from GitHub.

This tool simply logs in on Exchange Web Services to subscribe to push notifications. This will make Exchange connect back to you and authenticate as system.

Attack module that can be used with to perform the attack without credentials. To get it working:

  • Modify the attacker URL in to point to the attacker's server where ntlmrelayx will run
  • Clone impacket from GitHub git clone
  • Copy this file into the /impacket/impacket/examples/ntlmrelayx/attacks/ directory.
  • cd impacket
  • Install the modified version of impacket with pip install . --upgrade or pip install -e .