PrivExchange – Exchange Your Privileges For Domain Admin Privs By Abusing Exchange



These tools require impacket. You can install it from pip with pip install impacket, but it is highly recommended to use the latest version from GitHub.

This tool ( will simply login on Exchange Web Services to subscribe to push notifications. That means it will make Exchange connect back to you as well and authenticate as the system.

The attack module (i.e. that can be used with to perform the attack without credentials. To get it working:

  • Make alteration to the attacker’s URL in to point to the attacker’s server where ntlmrelayx will run
  • Clone impacket from GitHub git clone
  • Copy this file into the /impacket/impacket/examples/ntlmrelayx/attacks/ directory.
  • cd impacket
  • Install the modified version of impacket with pip install . –upgrade or pip install -e .

Leave a Reply

Leave a Reply