Practical guide to NTLM Relaying in 2017 (A.K.A getting a foothold in under 5 minutes) // under Active Directory This blog post is mainly aimed to be a very 'cut & dry' practical guide to help clear up any confusion regarding NTLM relaying. Talking to pentesters I've noticed that there seems to be a lot of general confusion regarding what you can do with those pesky hashes you get with Responder.